When cross-app permissions lead to risks

On January 31, 2026, researchers revealed that Moltbook, a social network built for AI agents, left its database widely available, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part was in the private messages. Some of these conversations held clear-text third-party credentials, including OpenAI API keys, […]
Microsoft patches critical CVE-2026-40372 privilege escalation bug in ASP.NET Core

Ravi LakshmananApril 22, 2026Vulnerabilities/Encryption Microsoft has released an out-of-band update to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges. This vulnerability is tracked as CVE-2026-40372 and has a CVSS score of 9.1 out of 10.0. Severity is rated as Important. An anonymous researcher is credited with discovering and […]
New LOTUSLITE variant of Mustang Panda targets Indian banks and Korean policy world

Ravi LakshmananApril 22, 2026Cyber espionage/malware Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE distributed via themes related to the Indian banking sector. “The backdoor communicates with a dynamic DNS-based command and control server via HTTPS and supports remote shell access, file manipulation, and session management, indicating a continued set of […]
Cohere AI Terrarium sandbox flaw allows root code execution and container escape

Ravi LakshmananApril 22, 2026Vulnerabilities / Container Security A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could allow arbitrary code execution. This vulnerability is tracked as CVE-2026-5752 and is rated 9.3 on the CVSS scoring system. “A sandbox escape vulnerability in Terrarium could allow arbitrary code execution with root privileges […]
SystemBC C2 Server Reveals Over 1,570 Victims of Operation The Gentlemen Ransomware

Threat actors associated with The Gentlemen ransomware-as-a-service (RaaS) operations have been observed attempting to deploy a known proxy malware called SystemBC. A command and control (C2 or C&C) server linked to SystemBC uncovered a botnet with more than 1,570 victims, according to new research published by Check Point. “SystemBC establishes a SOCKS5 network tunnel within […]
22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters

Ravi LakshmananApril 21, 2026Network security/vulnerabilities Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex. These vulnerabilities could be exploited to hijack a susceptible device and alter data exchanged by the device. Forescout Research Vedere Labs has identified approximately 20,000 serial-to-Ethernet converters with the vulnerabilities, collectively codenamed BRIDGE:BREAK, […]
Ransomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack

Ravi LakshmananApril 21, 2026Insider Threat/Cybercrime A third person hired as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, worked with the operators of BlackCat ransomware starting in April 2023 to help the electronic crime syndicate extract larger amounts of ransom money. […]
5 places mature SOCs keep their MTTR fast and other SOCs are wasting their time

Security teams often present MTTR as an internal KPI. Management has a different view. Every hour that a threat exists in your environment can result in data breaches, service interruptions, regulatory exposure, and brand damage. The root cause of slow MTTR is rarely a “lack of analysts.” It’s almost always the same structural problem: threat […]
How attackers get in through your front door via identity-based attacks

The cybersecurity industry has spent the last few years tracking advanced threats such as zero-days, supply chain breaches, and AI-powered exploits. However, the most reliable entry point for attackers remains the same. That’s credential theft. Identity-based attacks remain the primary initial access vector for breaches today. Attackers obtain valid credentials through stuffing credentials from previously […]
NGate campaign targets Brazil, trojanizes HandyPay to steal NFC data and PINs

Ravi LakshmananApril 21, 2026Mobile security/artificial intelligence Cybersecurity researchers have discovered a new version of an Android malware family called NGate. This version was found to be exploiting a legitimate application called HandyPay instead of NFCGate. “The attackers obtained an app used to relay NFC data and patched it with malicious code that appears to be […]