How to browse faster and get more done with Adapt Browser

As web browsers evolve into general-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow down browsing sessions and cause unnecessary friction, especially for users who rely on the browser as their primary work environment. This article explains how a lightweight, task-focused browser like Adapt Browser can help […]

Trust Wallet Chrome Extension Hack Loses $8.5 Million in Shai-Hulud Supply Chain Attack

December 31, 2026Ravi LakshmananSoftware security/data breach Trust Wallet revealed on Tuesday that a second supply chain Shai Huld (also known as Sha1 Huld) outbreak in November 2025 was likely responsible for the hacking of its Google Chrome extension, ultimately resulting in approximately $8.5 million in assets being stolen. “This attack exposed the secrets of our […]

DarkSpectre browser extension campaign exposed affecting 8.8 million users worldwide

The threat actors behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, were behind a third attack campaign, codenamed DarkSpectre, that allegedly affected 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. This activity has been attributed to a Chinese threat actor and is being tracked by Koi Security under the name DarkSpectre. […]

IBM warns of critical API Connect bug that allows remote authentication bypass

December 31, 2026Ravi LakshmananAPI security/vulnerabilities IBM has detailed a critical security flaw in API Connect that could allow attackers to gain remote access to applications. This vulnerability is tracked as CVE-2025-13915 and is rated 9.8 out of a maximum of 10.0 in the CVSS scoring system. This is described as an authentication bypass flaw. “IBM […]

Researchers discover modified Shai-Hulud worm test payload on npm registry

December 31, 2026Ravi LakshmananCybersecurity/Malware Cybersecurity researchers have revealed details of what appears to be a new strain of Shai Huld on the npm registry, with some changes since the previous wave observed last month. The npm package that embeds the new Shai Hulud strain is ‘@vietmoney/react-big-calendar’ and was uploaded to npm by a user named […]

US Treasury lifts sanctions on three people involved in Intellexa and Predator spyware

December 31, 2026Ravi LakshmananSpyware/Mobile Security The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals associated with the Intellexa Consortium, the holding company for the commercial spyware known as “Predator,” from its list of Specially Designated Nationals. The names of the individuals are: Merom Harpas Andrea Nicola Constantino Hermes Gambazzi […]

CSA issues warning about critical remote code execution bug in SmarterMail

December 30, 2026Ravi LakshmananVulnerabilities / Email Security The Cyber ​​Security Authority of Singapore (CSA) has issued a bulletin warning of a maximum severity security flaw in the SmarterTools SmarterMail email software that could be exploited to lead to remote code execution. This vulnerability is tracked as CVE-2025-52691 and has a CVSS score of 10.0. This […]

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

The threat actor known as Silver Fox has shifted its focus to India, using income tax-themed decoys in phishing campaigns to distribute a modular remote access Trojan called ValleyRAT (also known as Winos 4.0). “This sophisticated attack utilizes a complex kill chain that includes DLL hijacking and a modular Valley RAT to ensure persistence,” CloudSEK […]

How to integrate AI into modern SOC workflows

Artificial intelligence (AI) is rapidly being introduced into security operations, but many practitioners still struggle to turn early experiments into consistent operational value. This is because SOCs are implementing AI without a deliberate approach to operational integration. Some teams treat this as a shortcut for broken processes. Some people try to apply machine learning to […]

Mustang Panda uses signed kernel-mode rootkit to load TONESHELL backdoor

December 30, 2026Ravi LakshmananMalware/Cyber ​​Espionage A Chinese hacker group known as Mustang Panda utilized a previously undocumented kernel-mode rootkit driver to deliver a new variant of a backdoor called TONESHELL in a cyberattack detected targeting unspecified organizations in Asia in mid-2025. The findings, published by Kaspersky Lab, observed new backdoor variants in cyberespionage operations by […]