FBI investigating malware hidden in games hosted on Steam

The FBI announced Friday that it is investigating a hacker suspected of releasing several malware-laced video games on the popular PC game store Steam. In an announcement looking for possible infected victims, the FBI listed BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova as games suspected of being developed by the same cybercriminals over the […]

Storm-2561 spreads Trojan VPN clients and steals credentials via SEO poisoning

Ravi LakshmananMarch 13, 2026VPN Security/Malware Microsoft has revealed details of a credential theft campaign using fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. “This campaign deploys a digitally signed Trojan horse that redirects users searching for legitimate enterprise software to a malicious ZIP file on an attacker-controlled website and […]

Investigating new clickfix variants

Disclaimer: This report was produced by the Threat Research Center to increase cybersecurity awareness and support strengthening defensive capabilities. This is based on independent research and observations of the current threat landscape available at the time of publication. This content is for informational and preparatory purposes only. Read more blogs on threat intelligence and adversary […]

Motion robotaxis join Uber app in Las Vegas, two years after major reset

Uber has added self-driving cars from other companies to its growing robotaxi network. Hyundai’s self-driving version of Motional, the Ioniq 5, is now available for transportation to five areas of the city. Currently, there is a safety monitor inside the vehicle. Starting Friday, vehicles will pick up and drop off at the Westgate adjacent to […]

Google fixes two active Chrome zero-days affecting Skia and V8

Ravi LakshmananMarch 13, 2026Browser security/vulnerabilities Google on Thursday released security updates for its Chrome web browser that address two high-severity vulnerabilities that have been reported to be exploited in the wild. Here is the list of vulnerabilities: CVE-2026-3909 (CVSS Score: 8.8) – An out-of-bounds write vulnerability in the Skia 2D graphics library allows remote attackers […]

9 CrackArmor flaws in Linux AppArmor allow route escalation and bypass container isolation

Ravi LakshmananMarch 13, 2026Linux / Vulnerabilities Cybersecurity researchers have uncovered multiple security vulnerabilities within the AppArmor module of the Linux kernel. These vulnerabilities can be exploited by unprivileged users to bypass kernel protections and escalate to root, compromising container isolation guarantees. The Qualys Threat Research Unit (TRU) has collectively codenamed these nine confusing sub-vulnerabilities CrackArmor. […]

Authorities disrupt SocksEscort proxy botnet exploiting 369,000 IPs in 163 countries

A court-sanctioned international law enforcement operation has dismantled a criminal agency service called SocksEscort that botnetized thousands of home routers around the world to commit large-scale fraud. “SocksEscort infected homes and small businesses’ internet routers with malware,” the U.S. Department of Justice (DoJ) said in a statement. “The malware allowed SocksEscort to direct internet traffic […]

Truecaller allows you to hang up with scammers on behalf of your family

Caller identification platform Truecaller recently released a new feature that allows one person to become a family group admin, receive alerts about fraudulent calls received by other members, and end calls on behalf of a family member if they suspect they have been scammed. The company, which has more than 450 million users, first launched […]

Veeam patches 7 critical backup and replication flaws that could allow remote code execution

Ravi LakshmananMarch 13, 2026Vulnerabilities / Enterprise Security Veeam has released a security update that addresses multiple critical vulnerabilities in its backup and replication software that could allow remote code execution if successfully exploited. The vulnerabilities are: CVE-2026-21666 (CVSS score: 9.9) – Vulnerability that allows authenticated domain users to execute remote code on backup servers. CVE-2026-21667 […]