MTTD looks great. No gaps after alert

Last week, Anthropic restricted its Mythos preview model following the autonomous discovery and exploitation of zero-day vulnerabilities across all major operating systems and browsers. Palo Alto Networks’ Wendy Whitmore warned that it could take weeks or months for similar features to become widespread. According to CrowdStrike’s 2026 Global Threat Report, the average breakout time for […]

North Korea’s APT37 uses Facebook social engineering to deliver RokRAT malware

Ravi LakshmananApril 13, 2026Social engineering/threat intelligence A North Korean hacker group tracked as APT37 (also known as ScarCruft) is believed to be involved in a new multi-stage social engineering campaign. In this campaign, threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a […]

Cloud Threat Retrospective 2026 | Wiz Research

Traditional vulnerabilities remain a key factor in cloud threat actor activity in 2025. In publicly documented incidents in Wiz’s cloud threat landscape, most initial accesses involved weaponized vulnerabilities, exposed secrets, and misconfigurations. However, the well-known nature of these vectors should not be misinterpreted to mean that the impact of an attacker’s actions will be limited […]

CPUID Compromise Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

Rabi LakshmananApril 12, 2026Malware/Threat Intelligence An unknown attacker has compromised CPUID (‘cpuid[.]com”), a website that hosts popular hardware monitoring tools such as CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, served a malicious executable of software and deployed a remote access Trojan called STX RAT within 24 hours. The incident lasted from approximately 15:00 UTC on April […]

Adobe patches actively exploited Acrobat Reader flaw CVE-2026-34621

Rabi LakshmananApril 12, 2026Vulnerabilities / Endpoint Security Adobe has released an emergency update to fix a critical security flaw in Acrobat Reader that is being exploited in the wild. This vulnerability has been assigned the CVE identifier CVE-2026-34621 and has a CVSS score of 9.6 out of 10.0. Successful exploitation of this flaw could allow […]

Law enforcement uses Webloc to track 500 million devices via advertising data

Hungary’s domestic intelligence agency, El Salvador’s national police, and several law enforcement agencies and police departments in the United States are believed to have used an ad-based global geolocation surveillance system called Weblock. According to a report published by Citizen Lab, the tool was developed by Israeli company Cobwebs Technologies and sold by its successor, […]

GlassWorm campaign uses Zig Dropper to infect multiple developer IDEs

Rabi LakshmananApril 10, 2026Malware/Blockchain Cybersecurity researchers have warned of further evolution of the ongoing GlassWorm campaign. It employs a new Zig dropper designed to covertly infect all integrated development environments (IDEs) on a developer’s machine. The technique was discovered in an Open VSX extension named “specstudio.code-wakatime-activity-tracker” that pretends to be WakaTime, a popular tool that […]

Browser extensions are the new AI consumption channel no one is talking about

While much of the discussion around AI security centers around protecting the consumption of “shadow” AI and GenAI, there is a wide open window that no one is guarding. It’s an AI browser extension. A new report from LayerX reveals just how deep this blind spot goes and why AI extensions may be the surface […]

Google deploys DBSC in Chrome 146 to block session theft on Windows

Ravi LakshmananApril 10, 2026Malware/Browser Security Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. Public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned for future Chrome releases. “This […]