Flaw in Claude code allows remote code execution and API key disclosure

Ravi LakshmananFebruary 25, 2026Artificial intelligence/vulnerabilities Cybersecurity researchers have revealed multiple security vulnerabilities in Anthropic’s Claude Code, an artificial intelligence (AI)-powered coding assistant, that could allow remote code execution and theft of API credentials. “This vulnerability exploits various configuration mechanisms, including hooks, Model Context Protocol (MCP) servers, and environment variables, to execute arbitrary shell commands and […]
SLH offers $500-$1,000 per call to recruit women for IT help desk vishing attack

Ravi LakshmananFebruary 25, 2026Social engineering/cloud security A notorious cybercrime group known as Scattered LAPSUS$ Hunters (SLH) has been observed offering financial incentives to recruit women to carry out social engineering attacks. Dataminr said in a new threat brief that it is considering hiring them for voice phishing campaigns targeting IT help desks. The group is […]
5 ways triage failure increases business risk instead of reducing it

Triage should make things easier. For many teams, the opposite is true. If a confident verdict cannot be reached early, alerts turn into repeated confirmations, back-and-forth, and “just escalate” calls. The costs don’t stop within the SOC. It manifests itself in a lack of SLAs, higher costs per case, and more room for real threats […]
A malicious NuGet package stole ASP.NET data. Malware with dropped npm packages

Ravi LakshmananFebruary 25, 2026Cybersecurity/Malware Cybersecurity researchers have discovered four malicious NuGet packages designed to target ASP.NET web application developers and steal sensitive data. The campaign, discovered by Socket, not only steals ASP.NET identity data such as user accounts, role assignments, and permission mappings, but also manipulates authorization rules to create persistent backdoors in victim applications. […]
Manual processes are putting national security at risk

Why automating sensitive data transfer is a mission-critical priority According to The CYBER360: Defending the Digital Battlespace report, more than half of national security organizations still rely on manual processes to transfer sensitive data. This should be a wake-up call to all defense and government leaders, as manual handling of sensitive data is not only […]
Defense contractor employee sentenced to prison for selling 8 zero-day products to Russian broker

Ravi LakshmananFebruary 25, 2026 Zero Day / National Security A 39-year-old Australian previously employed by US defense contractor L3Harris has been sentenced to just over seven years in prison for selling eight zero-day exploits to Russian exploit broker Operation Zero in exchange for millions of dollars. Peter Williams pleaded guilty in October 2025 to two […]
Critical Serv-U 15.5 flaw that allows root code execution in SolarWinds Patch 4

Ravi LakshmananFebruary 25, 2026Vulnerabilities / Windows Security SolarWinds has released an update that addresses four critical security flaws in its Serv-U file transfer software. Exploitation of these vulnerabilities could result in remote code execution. All vulnerabilities rated 9.1 by the CVSS scoring system are listed below. CVE-2025-40538 – Broken access control vulnerability allows an attacker […]
CISA confirms active exploitation of FileZen CVE-2026-25108 vulnerability

Ravi LakshmananFebruary 25, 2026Vulnerabilities/Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added the recently disclosed FileZen vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow authenticated […]
A flaw in RoguePilot in GitHub codespaces could allow Copilot to leak GITHUB_TOKEN

A vulnerability in the GitHub code space could be exploited by a malicious actor to take control of a repository by injecting malicious Copilot instructions into GitHub issues. This artificial intelligence (AI)-powered vulnerability has been codenamed “RoguePilot” by Orca Security. It was later patched following responsible disclosure by Microsoft. “An attacker can create hidden instructions […]
UAC-0050 Targets European financial institutions with spoofed domains and RMS malware

Ravi LakshmananFebruary 24, 2026Cyber espionage/malware Russian-aligned threat actors have been observed targeting financial institutions in Europe as part of social engineering attacks likely to facilitate intelligence gathering and financial theft, suggesting threat actors’ targeting may expand beyond Ukraine to organizations supporting the war-torn nation. This activity targeted anonymous organizations involved in regional development and reconstruction […]