Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover

Ravi LakshmananMarch 20, 2026Web security/vulnerabilities Sansec warns that Magento’s REST API has a critical security flaw that could allow an unauthenticated attacker to upload arbitrary executable files and perform code execution or account takeover. This vulnerability was codenamed PolyShell by Sansec due to the fact that the attack relies on disguising malicious code as an […]

Apple warns that older iPhones are vulnerable to Coruna and DarkSword exploit kit attacks

Ravi LakshmananMarch 20, 2026Mobile security/malware Apple is reminding users still running older versions of iOS to update their iPhones to protect against web-based attacks carried out through powerful exploit kits such as Coruna and DarkSword. These attacks leverage malicious web content to target older versions of iOS, triggering infection chains that lead to the theft […]

Speagle malware hijacks Cobra DocGuard and steals data via compromised servers

Ravi LakshmananMarch 19, 2026Cyber ​​espionage/threat intelligence Cybersecurity researchers have reported a new malware called Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to covertly collect sensitive information from infected computers and send it to a Cobra DocGuard server that has been compromised by an attacker, masking […]

Cloudflare CEO says online bot traffic will exceed human traffic by 2027

Bots are taking over the web, according to Cloudflare CEO Matthew Prince. In an interview at the SXSW conference in Austin this week, he said that the speed at which artificial intelligence is growing will result in AI bot traffic exceeding human traffic online by 2027. Prince explained that bots’ web usage is increasing with […]

Blue Sky announces $100 million Series B after CEO change

Social network Bluesky is gearing up for big changes with today’s news that it has raised $100 million in Series B funding. The round, led by Bain Capital Crypto, was completed in April 2025 and was previously undisclosed. Other companies participating in this round include Anthos Capital, Bloomberg Beta, and Knight Foundation, in addition to […]

54 EDR killers use BYOVD to exploit 34 signed vulnerability drivers to disable security

A new analysis of endpoint detection and response (EDR) killers reveals that 54 of them leverage a technique known as bring-your-own-vulnerable-driver (BYOVD), for a total of 34 vulnerable drivers. EDR killer programs are common in ransomware intrusions because they provide a way for affiliates to neutralize security software before deploying file-encrypting malware. This is done […]