APT28 deploys PRISMEX malware in campaign targeting Ukraine and NATO allies

Ravi LakshmananApril 8, 2026Vulnerability / Cloud Security The Russian threat actor known as APT28 (also known as Forest Blizzard and Pawn Storm) is said to be involved in a new spear-phishing campaign targeting Ukraine and its allies, introducing a previously undocumented malware suite codenamed PRISMEX. “PRISMEX combines advanced steganography, Component Object Model (COM) hijacking, and […]
Reduce your IAM attack surface through the Identity Visibility and Intelligence Platform (IVIP)

The fragmented state of modern enterprise identity Enterprise IAM is nearing breaking point. As organizations grow, identities become increasingly fragmented across thousands of applications, distributed teams, machine identities, and autonomous systems. The result is identity dark matter. This is identity activity that is outside the visibility of centralized IAM and out of the reach of […]
Anthropic’s Claude Mythos discovers thousands of zero-day flaws across major systems

Ravi LakshmananApril 8, 2026Artificial intelligence/secure coding Artificial intelligence (AI) company Anthropic has announced a new cybersecurity initiative called Project Glasswing that uses a preview version of its new frontier model, Claude Mythos, to find and address security vulnerabilities. This model is used by Anthropic and smaller organizations such as Amazon Web Services, Apple, Broadcom, Cisco, […]
Korean hackers spread 1,700 malicious packages on npm, PyPI, Go, and Rust

A persistent North Korea-related campaign known as Contagious Interview has spread its tentacles by publishing malicious packages targeting the Go, Rust, and PHP ecosystems. “The threat actor’s package was designed to impersonate a legitimate developer tool.” […]”While silently acting as a malware loader, it extends Contagious Interview’s established strategy to coordinated supply chain operations across […]
Iran-linked hackers disrupt U.S. critical infrastructure by targeting PLCs exposed on the Internet

Iran-linked cyber attackers are targeting internet-connected operational technology (OT) devices across critical U.S. infrastructure, including programmable logic controllers (PLCs), cybersecurity and intelligence agencies warned Tuesday. “These attacks resulted in PLC degradation, display data manipulation, and in some cases business disruption and financial loss,” the Federal Bureau of Investigation (FBI) said in a post on X. […]
Russian state-affiliated APT28 exploits SOHO routers in global DNS hijacking campaign

The Russian-linked threat actor known as APT28 (also known as Forest Blizzard) is said to be involved in a new campaign to infiltrate and modify less secure MikroTik and TP-Link routers to take control of malicious infrastructure as part of a cyberespionage campaign since at least May 2025. This large-scale exploitation campaign, codenamed FrostArmada by […]
Docker CVE-2026-34040 allows attackers to bypass authentication and gain host access

Ravi LakshmananApril 7, 2026Vulnerabilities / DevSecOps A high-severity security vulnerability has been disclosed in Docker Engine that could allow an attacker to bypass the authentication plugin (AuthZ) under certain circumstances. This vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), results from an incomplete remediation of CVE-2024-41110, the highest severity vulnerability in the same component that was […]
Over 1,000 exposed ComfyUI instances targeted by cryptomining botnet campaign

We have observed an active campaign targeting internet-exposed instances running ComfyUI, a popular and stable distribution platform, to participate in cryptocurrency mining and proxy botnets. “A dedicated Python scanner continuously sweeps across key cloud IP ranges looking for vulnerable targets and automatically installs malicious nodes via ComfyUI-Manager if exploitable nodes are not already present,” Censys […]
[Webinar] How to close the identity gap in 2026 before AI exploits enterprise risks

hacker newsApril 7, 2026SaaS Security / Enterprise Security The rapidly evolving threat landscape of 2026 has revealed a frustrating paradox for CISOs and security leaders. The bottom line is that even as identity programs mature, the risks are actually increasing. Hundreds of applications within a typical enterprise remain disconnected from central identity systems, according to […]
The hidden cost of repeated credential incidents

When we talk about credential security, the focus is usually on preventing breaches. This makes sense, as IBM’s 2025 Cost of Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is enough to justify most security investments, but this headline number obscures a more persistent problem […]