Fake tech support spam deploys customized Havoc C2 across organization

Threat hunters are cautioned as part of a new campaign in which malicious actors pose as fake IT support and offer the Havoc command and control (C2) framework as a precursor to data theft and ransomware attacks. The intrusion, which Huntress identified last month across five partner organizations, involved the attacker using email spam as […]

Apple unveils new MacBook Air and MacBook Pro powered by M5

Apple announced new laptops Tuesday morning, including new MacBook Air and MacBook Pro models powered by Apple’s M5 chip. The Pro models were announced alongside the brand new M5 Pro and M5 Max chips, which Apple describes as its most advanced CPU cores to date. The company says these updated M5 chips are specifically designed […]

Vanuatu’s ‘barefoot volcanologist’ stands on Mount Yasur, spewing ash and sulfur, captured in award-winning photo

A photograph of an amateur volcanologist standing barefoot on a lava field on Vanuatu’s Mount Yasur has won the portrait category in this year’s Sony World Photography Awards open competition. Fine art and documentary photographer El Leontief captured Philip, the “barefoot volcanologist,” on Tanna, a remote Pacific island about 120 miles (190 kilometers) from Efate’s […]

The 3 Steps CISOs Must Follow

Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1 analysts sit at the front line of detection, and yet they are also the most vulnerable to the cognitive and organizational pressures that quietly erode […]

Open Source CyberStrikeAI Deploys AI-Driven FortiGate Attacks in 55 Countries

Ravi LakshmananMarch 3, 2026Vulnerability / Artificial Intelligence The attackers behind the recently revealed artificial intelligence (AI)-assisted campaign targeting Fortinet’s FortiGate appliances leveraged an open-source AI-native security testing platform called CyberStrikeAI to carry out the attack. This new discovery is attributed to Team Cymru, whose use was detected after analyzing the IP address (‘212.11.64’).[.]250″) was used […]

The candidates Silicon Valley built are now the ones they are trying to destroy.

For months, there has been talk that Silicon Valley’s billionaire class is recruiting candidates to replace Congressman Ro Khanna. Early Tuesday morning, the candidate officially announced. Ethan Agarwal (pictured above), a 40-year-old tech entrepreneur with no political background, told TechCrunch on Monday night that he is running for California’s 17th Congressional District. This process could […]

AI Agents: The Next Wave of Identity Dark Matter

The rise of MCP in the enterprise Model Context Protocol (MCP) is rapidly becoming a practical way to move LLM from “chat” to real work. By providing structured access to applications, APIs, and data, MCP enables prompt-driven AI agents that can retrieve information, take actions, and automate end-to-end business workflows across the enterprise. This is […]

Starkiller phishing suite uses AitM reverse proxy to bypass multi-factor authentication

Cybersecurity researchers have revealed details of a new phishing suite called Starkiller that bypasses multi-factor authentication (MFA) protections by proxying legitimate login pages. It is promoted as a cybercrime platform by a threat group calling itself Jinkusu, and customers are given access to a dashboard where they can select brands to impersonate and enter the […]

Microsoft warns that OAuth redirect abuse can deliver malware to government targets

Ravi LakshmananMarch 3, 2026Phishing/Malware Microsoft on Monday warned of phishing campaigns that utilize phishing emails and OAuth URL redirection mechanisms to bypass traditional phishing defenses implemented in email and browsers. The company says the campaign targets government and public sector organizations, and the ultimate goal is to redirect victims to attacker-controlled infrastructure without stealing their […]