Falsely reusing passwords: A risky and often overlooked workaround

When security teams discuss credential-related risks, they typically focus on threats like phishing, malware, and ransomware. These attack techniques continue to evolve and are gaining the attention they deserve. However, one of the most persistent and underappreciated risks to organizational security remains far more common. Reusing nearly identical passwords continues to bypass security controls and […]

Google warns of active exploitation of WinRAR vulnerability CVE-2025-8088

Ravi LakshmananJanuary 28, 2026Vulnerability/Threat Intelligence Google revealed on Tuesday that multiple threat actors, including state adversaries and financially motivated groups, are exploiting critical patched security flaws in RARLAB WinRAR to gain initial access and deploy various payloads. “Although discovered and patched in July 2025, government-sponsored and financially motivated actors associated with Russia and China continue […]

Fake Python Spellchecker package on PyPI delivers hidden remote access Trojan

Ravi LakshmananJanuary 28, 2026Supply chain security/malware Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that contain the ability to deliver a remote access trojan (RAT) while masquerading as a spell checker. The packages named Spellcheckerpy and Spellcheckpy are currently not available for download, but they were previously downloaded over […]

Unmasking new TOAD attacks hidden in legitimate infrastructure

“Living off the land” has become a preferred tactic for threat actors in many attack scenarios. This time, an existing “innocuous” component is being used as part of a phishing campaign. By leveraging the reputation of trusted services like PayPal and Zoom, attackers can bypass traditional Secure Email Gateways (SEGs) that whitelist these domains. Recently, […]

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Ravi LakshmananJanuary 28, 2026Network security/zero day Fortinet has begun releasing security updates to address critical flaws affecting FortiOS that are being exploited in the wild. The vulnerability, assigned CVE identifier CVE-2026-24858 (CVSS score: 9.4), is described as an authentication bypass related to FortiOS single sign-on (SSO). This flaw also affects FortiManager and FortiAnalyzer. The company […]

Anduril has invented a novel drone flying contest where work is the prize

Anduril founder Palmer Lackey lights up and talks a mile a minute when discussing his company’s new recruitment event, the AI ​​Grand Prix. This is a drone flying contest with a twist. Instead of humans operating the drones, the drones need to operate autonomously. Humans will be tested on their skills in writing the software […]