Casbaneiro Phishing targets Latin America and Europe using dynamic PDF lures

Ravi LakshmananApril 1, 2026Malware / Windows Security The multi-pronged phishing campaign targets Spanish-speaking users within organizations in Latin America and Europe, delivering Windows banking Trojans like Casbaneiro (also known as Metamorfo) via another piece of malware called Horabot. This activity is believed to be the work of Brazilian cybercrime threat actors tracked as Augmented Marauder […]

New Chrome zero-day CVE-2026-5281 in active exploitation – patch released

Ravi LakshmananApril 1, 2026Vulnerabilities / Browser security Google on Thursday released security updates for its Chrome web browser that address 21 vulnerabilities, including a zero-day flaw that the company says is being exploited in the wild. High severity vulnerability CVE-2026-5281 (CVSS score: N/A) involves a use-after-free bug in Dawn, an open source and cross-platform implementation […]

3 Reasons Why Attackers Will Use Trusted Tools Against You (And Why You Don’t See It Coming)

For years, cybersecurity has followed the familiar model of blocking malware and thwarting attacks. Now, attackers are moving on to their next attack. Threat actors now use malware less frequently in favor of what is already present in the environment. This includes abusing trusted tools, native binaries, and legitimate administrative utilities to move laterally, escalate […]

Google attributes Axios npm supply chain attack to North Korean group UNC1069

Ravi LakshmananApril 1, 2026Threat Intelligence/Software Security Google has officially attributed a supply chain breach of the popular Axios npm package to a cluster of financially motivated North Korean threat operations tracked as UNC1069. “We believe this attack was the work of a suspected North Korean threat actor, which we track as UNC1069,” John Hultquist, principal […]

Claude code source leaked via npm packaging error, confirmed by Anthropic

Ravi LakshmananApril 1, 2026Data Breach/Artificial Intelligence Anthropic on Tuesday admitted that the internal code of its popular artificial intelligence (AI) coding assistant, Claude Code, was accidentally released due to human error. “No sensitive customer data or credentials were involved or exposed,” an Anthropic spokesperson said in a statement shared with CNBC News. “This is a […]

Salesforce announces AI-powered makeover of Slack with 30 new features

Cloud software giant Salesforce is restructuring its business around AI, and at a small gathering in San Francisco on Tuesday, CEO Marc Benioff and his team announced the latest result of that effort: an updated version of Slack with a host of new AI features. Chief among them is the serious growth of Slackbot, an […]

Robotaxi companies refuse to say how often their AVs require remote support.

In February, Sen. Ed Markey (D-MA) sent a letter with a list of questions to seven U.S. companies working on self-driving car technology. He specifically wanted to know how much these companies’ vehicles, run by Aurora, May Mobility, Motional, Nuro, Tesla, Waymo, and Zoox, relied on input from remote staff. They all declined to speak, […]

Yupp closes after raising $33 million from Chris Dixon of a16z cryptocurrency

Sometimes a seemingly good idea, big funding from a big-name venture capital firm, and a well-connected angel investor aren’t enough. Co-founders Pankaj Gupta and Gilad Mishne announced on Tuesday that Yap would be winding down, less than a year after launching. Yupp provided a crowdsourced AI model selection service. This allowed consumers to test and […]