My Day Getting My Hands Dirty with an NDR System

My objectiveThe role of NDR in SOC workflowsStarting up the NDR systemHow AI complements the human responseWhat else did I try out?What could I see with NDR that I wouldn’t otherwise?Am I ready to be a network security analyst now? My objective As someone relatively inexperienced with network threat hunting, I wanted to get some […]

Microsoft discovers ‘AI summary’ prompts to drive chatbot recommendations

Ravi LakshmananFebruary 17, 2026Enterprise security/artificial intelligence A new study from Microsoft reveals that legitimate businesses are leveraging artificial intelligence (AI) chatbots via the “Summarize with AI” button. This button is increasingly being placed on websites in a way that reflects traditional search engine poisoning (AI). This new AI hijacking technique has been codenamed “AI Recommendation […]

Apple tests end-to-end encrypted RCS messaging in iOS 26.4 developer beta

Ravi LakshmananFebruary 17, 2026Encryption/Mobile Security Apple on Monday released a new developer beta for iOS and iPadOS that supports end-to-end encryption (E2EE) on Rich Communications Services (RCS) messages. This feature is currently available for testing in iOS and iPadOS 26.4 beta and will be available to customers in future updates to iOS, iPadOS, macOS, and […]

Infostealer steals OpenClaw AI agent configuration files and gateway tokens

Ravi LakshmananFebruary 16, 2026Artificial Intelligence/Threat Intelligence Cybersecurity researchers have revealed that they have detected instances of successful infiltration of information-stealing infections from victims’ OpenClaw (formerly known as Clawdbot and Moltbot) configuration environments. “This discovery marks an important milestone in the evolution of information thieves’ behavior, from stealing browser credentials to harvesting the ‘soul’ and identity […]

Investigation reveals 25 password recovery attacks on leading cloud password managers

Ravi LakshmananFebruary 16, 2026Vulnerabilities/Encryption New research has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditions. Researchers Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, and Kenneth G. Paterson said, “The severity of attacks ranges from integrity violations to complete compromise of all vaults within an […]

Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware

Ravie LakshmananFeb 16, 2026 This week’s recap shows how small gaps are turning into big entry points. Not always through new exploits, often through tools, add-ons, cloud setups, or workflows that people already trust and rarely question. Another signal: attackers are mixing old and new methods. Legacy botnet tactics, modern cloud abuse, AI assistance, and […]

How Lithuania is preparing for AI-powered cyber fraud

Presentation of the KTU Consortium’s mission ‘A secure and inclusive digital society’ at the Innovation Agency’s event ‘Innovation Breakfast: How mission-driven science and innovation programs address societal challenges’. Technology is rapidly evolving and reshaping economies, governance, and daily life. But as innovation accelerates, so too does digital risk. Technological change is no longer an abstraction, […]

New ZeroDayRAT mobile spyware enables real-time surveillance and data theft

Cybersecurity researchers have revealed details of a new mobile spyware platform called ZeroDayRAT that is being promoted on Telegram as a way to obtain sensitive data and facilitate real-time surveillance on Android and iOS devices. “Developers operate dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a […]

New Chrome Zero-Day (CVE-2026-2441) is under active attack — patch released

Ravi LakshmananFebruary 16, 2026Zero-day/Browser Security Google on Friday released security updates for its Chrome browser to address security flaws it says are being exploited in the wild. This high-severity vulnerability is tracked as CVE-2026-2441 (CVSS score: 8.8) and is described as a use-after-free bug in CSS. Security researcher Shaheen Fazim is credited with discovering and […]

Microsoft exposes DNS-based ClickFix attack using Nslookup to stage malware

Microsoft has revealed details of a new version of its ClickFix social engineering tactic in which attackers trick unsuspecting users into running a command that performs a Domain Name System (DNS) lookup to retrieve the next stage payload. Specifically, this attack uses the “nslookup” (short for nameserver lookup) command to[ファイル名を指定して実行]It relies on performing custom DNS […]