Hidden passenger? How to route Taboola logged in banking sessions to Temu?

hacker newsApril 16, 2026Data privacy/compliance Bank has approved Taboola pixel. This pixel silently redirected logged-in users to the Temu tracking endpoint. This happened without the bank’s knowledge, user consent, and without a single security control registering a breach. For technical details, please see our Security Intelligence Brief. Download now → Blind spot of “first hop […]
Abuse of Obsidian plugin leads to PHANTOMPULSE RAT in targeted financial and cryptocurrency attacks

Ravi LakshmananApril 16, 2026Application security/threat intelligence A “novel” social engineering campaign that leverages the cross-platform note-taking application Obsidian as an initial access vector to distribute a previously undocumented Windows remote access Trojan called PHANTOMPULSE has been observed in attacks targeting individuals in the financial and cryptocurrency sectors. The campaign, named REF6598 by Elastic Security Labs, […]
UAC-0247 Data theft malware campaign targets clinics and government in Ukraine

Ravi LakshmananApril 16, 2026Malware/Threat Intelligence Ukraine’s Computer Emergency Response Team (CERT-UA) has revealed details of a new campaign targeting government and municipal healthcare institutions, primarily clinics and emergency hospitals, distributing malware that can steal sensitive data from Chromium-based web browsers and WhatsApp. This activity was observed between March and April 2026 and is believed to […]
n8n webhook has been exploited since October 2025 to deliver malware via phishing emails

Ravi LakshmananApril 15, 2026Threat Intelligence/Cloud Security Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads and fingerprint devices by sending automated emails. “By leveraging trusted infrastructure, these attackers are bypassing traditional security filters and turning productivity tools into delivery vehicles […]
Actively exploited nginx-ui flaw (CVE-2026-33032) allows complete takeover of Nginx servers

Ravi LakshmananApril 15, 2026Web security/vulnerabilities A recently disclosed critical security flaw affecting nginx-ui, an open source web-based Nginx management tool, is being exploited in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that allows an attacker to take control of the Nginx service. Codenamed MCPwn by Pluto Security. […]
April Patch Tuesday fixes critical flaws for SAP, Adobe, Microsoft, Fortinet, and more

Ravi LakshmananApril 15, 2026Vulnerability/Data Breach A number of critical vulnerabilities affecting products from Adobe, Fortinet, Microsoft, and SAP are highlighted in April’s Patch Tuesday releases. Topping the list is a SQL injection vulnerability affecting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9), which could lead to the execution of arbitrary […]
What you need for public verification of your architecture

Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across the industry, executives are embracing its broad potential, and boards, investors, and executives are already pushing organizations to implement it across operations and security functions. Pentera’s AI Security and Exposure Report 2026 reflects that momentum. All CISOs surveyed reported that AI […]
Microsoft issues patches for SharePoint zero-day and 168 other new vulnerabilities

Microsoft on Tuesday released an update that addresses a record 169 security flaws across its product portfolio, including one vulnerability that is being exploited in the wild. Of these 169 vulnerabilities, 157 were rated as important, eight were rated as critical, three were rated as medium, and one was rated as low severity. 93 of […]
OpenAI announces GPT-5.4-Cyber with expanded access for security teams

Rabi LakshmananApril 15, 2026Vulnerability/Secure Coding OpenAI on Tuesday unveiled its latest flagship model, GPT-5.4-Cyber, a variant of GPT‑5.4 specifically optimized for defensive cybersecurity use cases, just days after rival Anthropic unveiled its own Frontier model, Mythos. “The progressive use of AI will accelerate defenders, those responsible for keeping systems, data, and users safe, so they […]
New flaw in PHP Composer allows arbitrary command execution – patch released

Ravi LakshmananApril 14, 2026Vulnerabilities / DevSecOps Two high-severity security vulnerabilities have been disclosed in Composer, a PHP package manager, that could allow arbitrary command execution if successfully exploited. The vulnerability is described as a command injection flaw affecting the Perforce VCS (version control software) driver. Details of the two defects are below. CVE-2026-40176 (CVSS Score: […]