Trojanized gaming tool spreads Java-based RAT via browsers and chat platforms

Ravi LakshmananFebruary 27, 2026Endpoint security/Windows security Threat actors lure unsuspecting users into running Trojanized gaming utilities. This utility is distributed via browsers and chat platforms and delivers a remote access trojan (RAT). “A malicious downloader staged a portable Java runtime and executed a malicious Java archive (JAR) file named jd-gui.jar,” the Microsoft Threat Intelligence team […]

Meta files lawsuit against advertisers in Brazil, China, and Vietnam over celebrity baiting fraud

Ravi LakshmananFebruary 27, 2026Online fraud/digital advertising Meta announced Thursday that it will take legal action to combat fraud on its platform by filing lawsuits against what it calls fraudulent advertisers based in Brazil, China and Vietnam. As part of the effort, the advertiser’s payment method was suspended, associated accounts were disabled, and the domain name […]

Aeternum C2 botnet stores encrypted commands on Polygon blockchain to avoid deletion

Cybersecurity researchers have revealed details of a new botnet loader called Aeternum C2. This botnet loader uses blockchain-based command and control (C2) infrastructure to make it more resilient to takedown efforts. “Rather than relying on traditional servers or domains for command and control, Aeternum stores instructions on the public Polygon blockchain,” Qrator Labs said in […]

UAT-10027 Dohdoor backdoor targets US education and healthcare

Ravi LakshmananFebruary 26, 2026Malware/Threat Intelligence The previously undocumented cluster of threat activity is believed to stem from an ongoing malicious campaign targeting the education and healthcare sectors in the United States since at least December 2025. This campaign is tracked by Cisco Talos as UAT-10027. The ultimate goal of the attack is to deliver a […]

Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories

Ravie LakshmananFeb 26, 2026Cybersecurity / Hacking News Nothing here looks dramatic at first glance. That’s the point. Many of this week’s threats begin with something ordinary, like an ad, a meeting invite, or a software update. Behind the scenes, the tactics are sharper. Access happens faster. Control is established sooner. Cleanup becomes harder. Here is […]

Expert Recommendation: Get ready for PQC today February 26, 2026 Encryption/Data Protection Overview: Steal today, break in 10 years Digital evolution is unstoppable, and although the pace varies, sooner or later things tend to stick. Of course, that also applies to adversaries. The rise of ransomware and cyber extortion has created funding for a complex and highly specialized criminal ecosystem. The cloud era has made nearly limitless storage capacity commonly available. Therefore, there is literally nothing stopping criminals from stealing and trading large amounts of data, encrypted or not. The patient’s adversary is "Harvest now, decrypt later" (HNDL) Strategy. They secretly accumulate encrypted data with the intention of later decrypting it using quantum computers. Data that requires long-term security, such as trade secrets or sensitive designs, will inevitably have a longer lifetime than current encryption, making them more vulnerable. Therefore, it is important for organizations to begin planning their transition to PQC.

Expert Recommendation: Get ready for PQC today February 26, 2026 Encryption/Data Protection Overview: Steal today, break in 10 years Digital evolution is unstoppable, and although the pace varies, sooner or later things tend to stick. Of course, that also applies to adversaries. The rise of ransomware and cyber extortion has created funding for a complex […]

Microsoft warns developers about fake Next.js job repository distributing in-memory malware

A “coordinated developer-targeted campaign” uses malicious repositories disguised as legitimate Next.js projects and technical assessments to trick victims into running the projects and establish permanent access to compromised machines. “This activity is consistent with a broader group of threats that use job-themed decoys to blend into developers’ daily workflows and increase the likelihood of code […]

Malicious StripeApi NuGet package imitated official library and stole API tokens

Ravi LakshmananFebruary 26, 2026Malware/Software Security Cybersecurity researchers have revealed details of a new malicious package discovered in the NuGet Gallery that targets the financial sector by impersonating a library from financial services company Stripe. The package, codenamed StripeApi.Net, attempts to impersonate Stripe.net, the official Stripe library that has been downloaded over 75 million times. This […]

Cisco SD-WAN zero-day CVE-2026-20127 has been exploited for administrator access since 2023

Ravi LakshmananFebruary 26, 2026Vulnerability/Network Security Newly disclosed maximum severity security flaws in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage) have been exploited in the wild as part of malicious activity dating back to 2023. This vulnerability, tracked as CVE-2026-20127 (CVSS score: 10.0), allows an unauthenticated, remote attacker to bypass authentication […]

Google suspends UNC2814 GRIDTIDE campaign after 53 breaches in 42 countries

Ravi LakshmananFebruary 25, 2026Cyber ​​espionage / network security Google said Wednesday that it worked with industry partners to disrupt the infrastructure of a suspected China-aligned cyber espionage group tracked as UNC2814, which infiltrated at least 53 organizations in 42 countries. “This prolific and elusive threat actor has a long history of targeting international governments and […]