Claude Opus 4.6 discovers over 500 high-severity flaws across major open source libraries

Rabi LakshmananFebruary 6, 2026Artificial intelligence/vulnerabilities Artificial intelligence (AI) company Anthropic has revealed that its latest large-scale language model (LLM), Claude Opus 4.6, has discovered more than 500 previously unknown high-severity security flaws in open source libraries such as Ghostscript, OpenSC, and CGIF. Claude Opus 4.6, released Thursday, includes enhancements to coding skills such as code […]
AISURU/Kimwolf botnet launches record 31.4 Tbps DDoS attack

Rabi LakshmananFebruary 5, 2026Botnet/Network Security The distributed denial of service (DDoS) botnet known as AISURU/Kimwolf is believed to be responsible for the record-setting attack, which lasted just 35 seconds at a peak of 31.4 terabits per second (Tbps). Cloudflare, which automatically detected and mitigated this activity, said it was part of a growing volume of […]
Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories

Ravie LakshmananFeb 05, 2026Cybersecurity / Hacking News This week didn’t produce one big headline. It produced many small signals — the kind that quietly shape what attacks will look like next. Researchers tracked intrusions that start in ordinary places: developer workflows, remote tools, cloud access, identity paths, and even routine user actions. Nothing looked dramatic […]
Buyer’s Guide to AI Usage Control

Today’s “AI Everywhere” reality is woven into daily workflows across the enterprise, embedded in a world of SaaS platforms, browsers, copilots, extensions, and shadow tools that are rapidly expanding faster than security teams can track them. However, most organizations still rely on traditional controls that operate far from where the AI interactions actually occur. As […]
Infy hackers resume operations with new C2 servers after Iran internet blackout ends

Rabi LakshmananFebruary 5, 2026Malware/Cyber Espionage The elusive Iranian threat group known as Infy (also known as Prince of Persia) has evolved its tactics as part of an effort to cover its tracks even as it prepares new command and control (C2) infrastructure to coincide with the end of a widespread regime-imposed internet blackout earlier in […]
n8n critical flaw CVE-2026-25049 allows execution of system commands via malicious workflows

Rabi LakshmananFebruary 5, 2026Workflow automation/vulnerabilities A critical new security vulnerability has been disclosed in the n8n workflow automation platform that could be successfully exploited to execute arbitrary system commands. This flaw, tracked as CVE-2026-25049 (CVSS score: 9.4), is due to improper sanitization that bypasses safety measures put in place to address CVE-2025-68613 (CVSS score: 9.9), […]
Malicious NGINX configuration enables massive web traffic hijacking campaign

Rabi LakshmananFebruary 5, 2026Web security/vulnerabilities Cybersecurity researchers have detailed an active web traffic hijacking campaign that targets NGINX installations and administrative panels such as Baota (BT) in an attempt to route them through attackers’ infrastructure. Datadog Security Labs said it has observed threat actors associated with recent React2Shell (CVE-2025-55182, CVSS score: 10.0) exploits using malicious […]
Microsoft develops scanner to detect backdoors in open weight large-scale language models

Rabi LakshmananFebruary 4, 2026Artificial intelligence/software security Microsoft announced Wednesday that it has developed a lightweight scanner that can detect backdoors in open weight large-scale language models (LLMs) and improve overall reliability for artificial intelligence (AI) systems. According to the tech giant’s AI security team, the scanner leverages three observable signals that can be used to […]
DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

Rabi LakshmananFebruary 4, 2026Malware/Endpoint Security Threat hunters have revealed details of a new stealth malware campaign called DEAD#VAX. The campaign combines “disciplined techniques and sophisticated exploitation of legitimate system functionality” to bypass traditional detection mechanisms and deploy a remote access Trojan (RAT) known as AsyncRAT. “This attack leverages IPFS-hosted VHD files, extreme script obfuscation, runtime […]
China-linked Amaranth-Dragon exploits WinRAR flaws for espionage

China-linked threat actors are believed to be involved in new cyber espionage operations targeting governments and law enforcement agencies across Southeast Asia throughout 2025. Check Point Research is tracking a previously undocumented cluster of activity under the name “Amaranth-Dragon,” which it says shares a connection with the APT 41 ecosystem. Target countries include Cambodia, Thailand, […]