Orchid Security brings continuous identity observability to enterprise applications

hacker newsFebruary 4, 2026Identity Security/Security Operations An innovative approach to discovering, analyzing, and managing identity usage that goes beyond traditional IAM controls. Challenge: Identity exists outside the identity stack Identity and access management tools were built to manage users and directories. Modern businesses run on applications. Over time, identity logic has moved into application code, […]

How early decisions shape incident response investigations

Many incident response failures are not due to a lack of tools, intelligence, or technical skills. They result from what happens immediately after detection, when pressure is high and information is incomplete. We’ve seen IR teams recover from advanced intrusions with limited telemetry. I’ve also seen teams lose control of investigations they could have handled. […]

Microsoft warns that Python Infostears is targeting macOS via fake ads and installers

Ravi LakshmananFebruary 4, 2026Malvertising/information thieves Microsoft warned that information theft attacks are “rapidly expanding” beyond Windows to target Apple’s macOS environment by leveraging cross-platform languages ​​such as Python and abusing trusted platforms for large-scale distribution. The tech giant’s Defender Security Research team said it has observed information stealer campaigns targeting macOS since late 2025 using […]

Eclipse Foundation requires pre-publication security checks for open VSX extensions

Ravi LakshmananFebruary 4, 2026Supply chain security/secure coding The Eclipse Foundation, which manages the Open VSX Registry, announced plans to conduct security checks before Microsoft Visual Studio Code (VS Code) extensions are published to open source repositories to combat supply chain threats. This move marks a shift from a reactive to a proactive approach to ensuring […]

CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog

Ravi LakshmananFebruary 4, 2026Software security/vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw affecting SolarWinds Web Help Desk (WHD) to its Known Exploited Vulnerabilities (KEV) catalog, flagging it as being actively exploited in attacks. This vulnerability, tracked as CVE-2025-40551 (CVSS score: 9.8), is an untrusted data deserialization vulnerability […]

Docker fixes critical Ask Gordon AI flaw that allows code execution via image metadata

Ravi LakshmananFebruary 3, 2026Artificial intelligence/vulnerabilities Cybersecurity researchers have detailed a patched security flaw affecting Ask Gordon, the artificial intelligence (AI) assistant built into Docker Desktop and the Docker command-line interface (CLI). This flaw could be exploited to execute code or leak sensitive data. This critical vulnerability has been codenamed DockerDash by cybersecurity firm Noma Labs. […]

Learn what to build, buy, and automate

hacker newsFebruary 3, 2026Threat Detection / Enterprise Security Most security teams today are buried in tools. Too many dashboards. Too much noise. Not enough real progress. Every vendor promises “full coverage” and “AI-powered automation,” but inside most SOCs, teams are still overwhelmed, stretched, and unsure of which tools are truly powerful. result? Growing stacks, missing […]

Hackers exploit Metro4Shell RCE flaw in React Native CLI npm package

Ravi LakshmananFebruary 3, 2026Open source/vulnerabilities Threat actors have been observed exploiting a critical security flaw affecting Metro Development Server in the popular “@react-native-community/cli” npm package. Cybersecurity company VulnCheck announced on December 21, 2025 that it observed the first exploit of CVE-2025-11953 (also known as Metro4Shell). With a CVSS score of 9.8, this vulnerability allows an […]

When a cloud outage spreads to the Internet

It’s hard to overlook recent large-scale cloud service outages. Massive incidents affecting providers like AWS, Azure, and Cloudflare disrupted large swaths of the internet and brought down websites and services that many other systems depend on. The resulting ripple effect brought down the applications and workflows that many organizations rely on on a daily basis. […]

APT28 uses Microsoft Office CVE-2026-21509 in espionage-focused malware attack

Ravi LakshmananFebruary 3, 2026Vulnerabilities/Malware A Russian-linked state-sponsored threat actor known as APT28 (also known as UAC-0001) is believed to have exploited a newly disclosed security flaw in Microsoft Office as part of a campaign codenamed Operation Neusploit. Zscaler ThreatLabz said it observed a group of hackers exploiting the flaw in attacks targeting users in Ukraine, […]