Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover

Ravi LakshmananMarch 20, 2026Web security/vulnerabilities Sansec warns that Magento’s REST API has a critical security flaw that could allow an unauthenticated attacker to upload arbitrary executable files and perform code execution or account takeover. This vulnerability was codenamed PolyShell by Sansec due to the fact that the attack relies on disguising malicious code as an […]
Department of Justice thwarts IoT botnet of 3 million devices behind record 31.4 Tbps global DDoS attack

The U.S. Department of Justice (DoJ) announced Thursday that it has disrupted command and control (C2) infrastructure used by several Internet of Things (IoT) botnets, including AISURU, Kimwolf, JackSkid, and Mossad, as part of a court-authorized law enforcement operation. In this effort, authorities in Canada and Germany are also targeting the operators behind these botnets, […]
Apple warns that older iPhones are vulnerable to Coruna and DarkSword exploit kit attacks

Ravi LakshmananMarch 20, 2026Mobile security/malware Apple is reminding users still running older versions of iOS to update their iPhones to protect against web-based attacks carried out through powerful exploit kits such as Coruna and DarkSword. These attacks leverage malicious web content to target older versions of iOS, triggering infection chains that lead to the theft […]
A humanoid robot that went on a rampage at a California restaurant had to be stopped by employees as it danced around.

When we think of the existential threats posed by new technologies, we usually think of things like the recent negotiations between Anthropic and the Department of Defense over how AI can be used in the military. It’s frightening to think – how long will it take for nuclear weapons to be detonated without human intervention? […]
Speagle malware hijacks Cobra DocGuard and steals data via compromised servers

Ravi LakshmananMarch 19, 2026Cyber espionage/threat intelligence Cybersecurity researchers have reported a new malware called Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to covertly collect sensitive information from infected computers and send it to a Cobra DocGuard server that has been compromised by an attacker, masking […]
Cloudflare CEO says online bot traffic will exceed human traffic by 2027

Bots are taking over the web, according to Cloudflare CEO Matthew Prince. In an interview at the SXSW conference in Austin this week, he said that the speed at which artificial intelligence is growing will result in AI bot traffic exceeding human traffic online by 2027. Prince explained that bots’ web usage is increasing with […]
Blue Sky announces $100 million Series B after CEO change

Social network Bluesky is gearing up for big changes with today’s news that it has raised $100 million in Series B funding. The round, led by Bain Capital Crypto, was completed in April 2025 and was previously undisclosed. Other companies participating in this round include Anthos Capital, Bloomberg Beta, and Knight Foundation, in addition to […]
54 EDR killers use BYOVD to exploit 34 signed vulnerability drivers to disable security

A new analysis of endpoint detection and response (EDR) killers reveals that 54 of them leverage a technique known as bring-your-own-vulnerable-driver (BYOVD), for a total of 34 vulnerable drivers. EDR killer programs are common in ransomware intrusions because they provide a way for affiliates to neutralize security software before deploying file-encrypting malware. This is done […]
Meta deploys new AI content enforcement system while reducing dependence on third-party vendors

Meta announced Thursday that it will begin deploying a more advanced AI system to handle content enforcement as it plans to cut back on third-party vendors. Tasks related to content enforcement include capturing and removing content related to terrorism, child exploitation, drugs, fraud, and fraud. The company says that once these more advanced AI systems […]
1,800-year-old nails found in three burial sites in Roman necropolis, may have been used to ‘protect’ both the living and the dead

A close-up of the skeleton shows a nail placed above the chest (just to the left of the spine). (Image source: Rome Special Inspectorate) Small iron nails placed in the chests of three skeletons preserve rare details about ancient Roman burial customs. 1,800 years ago, someone tried to protect the living from the dead. Diletta […]