Prioritizing identities is not a backlog issue

Most ID programs still prioritize work based on volume, loudness, or “failed control checks,” similar to how IT ticket prioritization is done. This approach breaks down the moment the environment stops being mostly human and mostly onboarding. In modern enterprises, identity risk is a combination of factors such as control posture, hygiene, business context, and […]

Lazarus Group uses Medusa ransomware in Middle East and US healthcare attacks

Ravi LakshmananFebruary 24, 2026Threat Intelligence/Healthcare The North Korean-linked Lazarus Group (also known as Diamond Sleet and Pompilus) was observed using Medusa ransomware in attacks targeting anonymous organizations in the Middle East, according to a new report by Symantec and the Carbon Black Threat Hunters team. Broadcom’s threat intelligence division also announced that it has identified […]

UnsolicitedBooker targets Central Asian telecom companies with LuciDoor and MarsSnake backdoors

A cluster of threat activity known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a change from previous attacks targeting Saudi companies. According to a report published last week by Positive Technologies, the attack involved the deployment of two different backdoors, codenamed LuciDoor and MarsSnake. “The group used some unique […]

Anthropic says Chinese AI company used 16 million Claude queries to copy model

Ravi LakshmananFebruary 24, 2026Artificial Intelligence / Humanity Anthropic announced on Monday that it had identified an “industrial-scale campaign” in which three artificial intelligence (AI) companies, Deep Seek, Moonshot AI, and MiniMax, illegally extracted Claude’s abilities to improve their models. This distillation attack resulted in more than 16 million interactions with its large-scale language model (LLM) […]

APT28 uses webhook-based macro malware to target European companies

Ravi LakshmananFebruary 23, 2026Malware/Threat Intelligence A Russian-affiliated state-sponsored threat actor tracked as APT28 is believed to be involved in a new campaign targeting specific organizations in Western and Central Europe. According to S2 Grupo’s LAB52 threat intelligence team, this activity was active from September 2025 to January 2026. The code name is “Operation MacroMaze”. “This […]

Wormable XMRig campaign uses BYOVD exploit and time-based logic bombs

Cybersecurity researchers have revealed details of a new cryptojacking campaign that uses pirated software bundles as bait to deploy a custom-built XMRig miner program on compromised hosts. “Analysis of recovered droppers, persistence triggers, and mining payloads reveals sophisticated multi-stage infections that prioritize maximizing cryptocurrency mining hashrate, often destabilizing victims’ systems,” Trellix researcher Aswath A said […]

Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More

Ravie LakshmananFeb 23, 2026Cybersecurity / Hacking Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across devices, cloud services, research labs, and even […]

How exposing endpoints increases risk across your LLM infrastructure

hacker newsFebruary 23, 2026Artificial Intelligence/Zero Trust As more organizations run their own large-scale language models (LLMs), they are also introducing more internal services and application programming interfaces (APIs) to support those models. Modern security risks are increasingly introduced not from the models themselves, but from the infrastructure that serves, connects, and automates them. Each new […]

Malicious npm package collects cryptographic keys, CI secrets, and API tokens

Cybersecurity researchers have uncovered what they claim is an active “Shai-Hulud-like” supply chain worm campaign that leverages a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. Similar to previous waves of Shai-Hulud attacks, the malicious […]

MuddyWater uses GhostFetch, CHAR, HTTP_VIP to target MENA organizations

Ravi LakshmananFebruary 23, 2026Threat Intelligence/Artificial Intelligence The Iranian hacker group known as MuddyWater (also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST) targeted multiple organizations and individuals primarily based in the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. According to a report published by Group-IB, this […]