Flaw in OpenClaw AI agent could allow rapid injection and data leakage

Ravi LakshmananMarch 14, 2026Artificial intelligence/endpoint security The China National Computer Network Emergency Response Technology Team (CNCERT) has issued a warning about security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open source, self-hosted autonomous artificial intelligence (AI) agent. In a post shared on WeChat, CNCERT noted that the platform’s “inherently weak default […]

GlassWorm supply chain attack exploits 72 open VSX extensions to target developers

Cybersecurity researchers have warned of a new iteration of the GlassWorm campaign, claiming that it has “significantly expanded” its method of spread through the Open VSX registry. “Rather than requiring loaders to be directly embedded in every malicious list, threat actors are now exploiting extensionPack and extensionDependency to turn extensions that initially appear standalone into […]

Chinese hackers target Southeast Asian militaries with AppleChris and MemFun malware

The suspected China-based cyber espionage operation has targeted military organizations in Southeast Asia as part of a state-sponsored campaign dating back to at least 2020. Palo Alto Networks Unit 42 is tracking threat activity under the designation CL-STA-1087. CL refers to clusters and STA stands for state-backed motives. Security researchers Lior Rochberger and Yoav Zema […]

Meta to end Instagram’s end-to-end encrypted chat support starting May 2026

Ravi LakshmananMarch 13, 2026Encryption/data protection Meta announced plans to discontinue support for end-to-end encryption (E2EE) in Instagram chats after May 8, 2026. “If you have chats that are affected by this change, you will receive instructions on how to download the media and messages you want to keep,” the social media giant said in its […]

Interpol destroys 45,000 malicious IPs and arrests 94 people in global cybercrime investigation

Ravi LakshmananMarch 13, 2026Ransomware/Cybercrime Interpol announced on Friday that it would remove 45,000 malicious IP addresses and servers used in connection with phishing, malware and ransomware campaigns as part of the agency’s ongoing efforts to dismantle criminal networks, thwart new threats and protect victims from fraud. This effort is part of an international law enforcement […]

Storm-2561 spreads Trojan VPN clients and steals credentials via SEO poisoning

Ravi LakshmananMarch 13, 2026VPN Security/Malware Microsoft has revealed details of a credential theft campaign using fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. “This campaign deploys a digitally signed Trojan horse that redirects users searching for legitimate enterprise software to a malicious ZIP file on an attacker-controlled website and […]

Investigating new clickfix variants

Disclaimer: This report was produced by the Threat Research Center to increase cybersecurity awareness and support strengthening defensive capabilities. This is based on independent research and observations of the current threat landscape available at the time of publication. This content is for informational and preparatory purposes only. Read more blogs on threat intelligence and adversary […]

Google fixes two active Chrome zero-days affecting Skia and V8

Ravi LakshmananMarch 13, 2026Browser security/vulnerabilities Google on Thursday released security updates for its Chrome web browser that address two high-severity vulnerabilities that have been reported to be exploited in the wild. Here is the list of vulnerabilities: CVE-2026-3909 (CVSS Score: 8.8) – An out-of-bounds write vulnerability in the Skia 2D graphics library allows remote attackers […]

9 CrackArmor flaws in Linux AppArmor allow route escalation and bypass container isolation

Ravi LakshmananMarch 13, 2026Linux / Vulnerabilities Cybersecurity researchers have uncovered multiple security vulnerabilities within the AppArmor module of the Linux kernel. These vulnerabilities can be exploited by unprivileged users to bypass kernel protections and escalate to root, compromising container isolation guarantees. The Qualys Threat Research Unit (TRU) has collectively codenamed these nine confusing sub-vulnerabilities CrackArmor. […]

Authorities disrupt SocksEscort proxy botnet exploiting 369,000 IPs in 163 countries

A court-sanctioned international law enforcement operation has dismantled a criminal agency service called SocksEscort that botnetized thousands of home routers around the world to commit large-scale fraud. “SocksEscort infected homes and small businesses’ internet routers with malware,” the U.S. Department of Justice (DoJ) said in a statement. “The malware allowed SocksEscort to direct internet traffic […]