A malicious NuGet package stole ASP.NET data. Malware with dropped npm packages

Ravi LakshmananFebruary 25, 2026Cybersecurity/Malware Cybersecurity researchers have discovered four malicious NuGet packages designed to target ASP.NET web application developers and steal sensitive data. The campaign, discovered by Socket, not only steals ASP.NET identity data such as user accounts, role assignments, and permission mappings, but also manipulates authorization rules to create persistent backdoors in victim applications. […]
Manual processes are putting national security at risk

Why automating sensitive data transfer is a mission-critical priority According to The CYBER360: Defending the Digital Battlespace report, more than half of national security organizations still rely on manual processes to transfer sensitive data. This should be a wake-up call to all defense and government leaders, as manual handling of sensitive data is not only […]
Defense contractor employee sentenced to prison for selling 8 zero-day products to Russian broker

Ravi LakshmananFebruary 25, 2026 Zero Day / National Security A 39-year-old Australian previously employed by US defense contractor L3Harris has been sentenced to just over seven years in prison for selling eight zero-day exploits to Russian exploit broker Operation Zero in exchange for millions of dollars. Peter Williams pleaded guilty in October 2025 to two […]
Critical Serv-U 15.5 flaw that allows root code execution in SolarWinds Patch 4

Ravi LakshmananFebruary 25, 2026Vulnerabilities / Windows Security SolarWinds has released an update that addresses four critical security flaws in its Serv-U file transfer software. Exploitation of these vulnerabilities could result in remote code execution. All vulnerabilities rated 9.1 by the CVSS scoring system are listed below. CVE-2025-40538 – Broken access control vulnerability allows an attacker […]
CISA confirms active exploitation of FileZen CVE-2026-25108 vulnerability

Ravi LakshmananFebruary 25, 2026Vulnerabilities/Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added the recently disclosed FileZen vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow authenticated […]
A flaw in RoguePilot in GitHub codespaces could allow Copilot to leak GITHUB_TOKEN

A vulnerability in the GitHub code space could be exploited by a malicious actor to take control of a repository by injecting malicious Copilot instructions into GitHub issues. This artificial intelligence (AI)-powered vulnerability has been codenamed “RoguePilot” by Orca Security. It was later patched following responsible disclosure by Microsoft. “An attacker can create hidden instructions […]
UAC-0050 Targets European financial institutions with spoofed domains and RMS malware

Ravi LakshmananFebruary 24, 2026Cyber espionage/malware Russian-aligned threat actors have been observed targeting financial institutions in Europe as part of social engineering attacks likely to facilitate intelligence gathering and financial theft, suggesting threat actors’ targeting may expand beyond Ukraine to organizations supporting the war-torn nation. This activity targeted anonymous organizations involved in regional development and reconstruction […]
Prioritizing identities is not a backlog issue

Most ID programs still prioritize work based on volume, loudness, or “failed control checks,” similar to how IT ticket prioritization is done. This approach breaks down the moment the environment stops being mostly human and mostly onboarding. In modern enterprises, identity risk is a combination of factors such as control posture, hygiene, business context, and […]
Lazarus Group uses Medusa ransomware in Middle East and US healthcare attacks

Ravi LakshmananFebruary 24, 2026Threat Intelligence/Healthcare The North Korean-linked Lazarus Group (also known as Diamond Sleet and Pompilus) was observed using Medusa ransomware in attacks targeting anonymous organizations in the Middle East, according to a new report by Symantec and the Carbon Black Threat Hunters team. Broadcom’s threat intelligence division also announced that it has identified […]
UnsolicitedBooker targets Central Asian telecom companies with LuciDoor and MarsSnake backdoors

A cluster of threat activity known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a change from previous attacks targeting Saudi companies. According to a report published last week by Positive Technologies, the attack involved the deployment of two different backdoors, codenamed LuciDoor and MarsSnake. “The group used some unique […]