$285M Drift Hack Tracks 6-Month North Korean Social Engineering Operation

Drift revealed that the April 1, 2026 attack, which resulted in the theft of $285 million, was the culmination of a months-long, targeted, well-planned social engineering operation by the Democratic People’s Republic of Korea (DPRK) that began in the fall of 2025. The Solana-based decentralized exchange described the attack as a “six-month effort” and attributed […]
36 malicious npm packages exploit Redis, PostgreSQL to deploy Persistent Implant

Ravi LakshmananApril 5, 2026Malware / DevSecOps Cybersecurity researchers discovered 36 malicious packages in the npm registry disguised as Strapi CMS plugins but with different payloads to facilitate exploitation of Redis and PostgreSQL, deploy reverse shells, harvest credentials, and drop persistent implants. “Every package contains three files (package.json, index.js, postinstall.js), has no description, repository, or homepage, […]
Fortinet patch actively exploits CVE-2026-35616 in FortiClient EMS

Ravi LakshmananApril 5, 2026Vulnerabilities/API Security Fortinet has released an out-of-band patch for a critical security flaw affecting FortiClient EMS and announced that the flaw is being exploited in the wild. This vulnerability is tracked as CVE-2026-35616 (CVSS score: 9.1) and is described as a pre-authentication API access bypass leading to privilege escalation. “Improper Access Control […]
China-linked TA416 targets European governments with PlugX and OAuth-based phishing

China-aligned threat actors have been targeting European governments and diplomatic institutions since mid-2025, after two years of minimal targeting in the region. This campaign is attributed to TA416, a cluster of activity that overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, and Vertigo Panda. “This TA416 activity included multiple waves of web bug and malware […]
Microsoft releases details about cookie-controlled PHP web shell persisted via Cron on Linux servers

Ravi LakshmananApril 3, 2026Linux/Server Hardening According to findings from the Microsoft Defender Security Research Team, threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to remotely execute code. “Rather than exposing command execution through URL parameters or the request body, these web shells rely on […]
UNC1069 Axios Maintainer social engineering led to npm supply chain attack

Ravi LakshmananApril 3, 2026Threat Intelligence/Malware The administrator of the Axios npm package acknowledged that the supply chain compromise was the result of a highly targeted social engineering campaign orchestrated by North Korean threat actors, tracked as UNC1069. Administrator Jason Seman said the attackers first approached him posing as the founders of legitimate, well-known companies and […]
Why third-party risk is the biggest gap in clients’ security posture

The next major breach to hit your clients likely won’t come from behind your walls. It can be delivered through a vendor they trust, a SaaS tool contracted by their finance team, or a subcontractor that no one in IT knows about. This is a new attack surface, and most organizations are ill-prepared for it. […]
New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets

Ravi LakshmananApril 3, 2026Mobile security/threat intelligence Cybersecurity researchers have discovered a new version of SparkCat malware on the Apple App Store and Google Play Store. It has been over a year since this Trojan was discovered targeting both mobile operating systems. The malware has been found hiding inside seemingly innocuous apps like enterprise messengers and […]
Drift loses $285 million in North Korea-related durable Nonce social engineering attack

Solana-based decentralized exchange Drift has admitted that attackers exfiltrated approximately $285 million from its platform during a security incident that occurred on April 1, 2026. “Earlier today, a malicious actor gained unauthorized access to the Drift protocol through a new attack involving a persistent nonce, resulting in a rapid takeover of Drift’s Security Council administrative […]
Hackers exploit CVE-2025-55182 to compromise 766 Next.js hosts and steal credentials

Ravi LakshmananApril 2, 2026Vulnerability/Threat Intelligence We have observed large-scale credential harvesting operations exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos attributes this operation to the threat cluster we track […]