Webinar guide to audit modern agent workflows

hacker newsMarch 10, 2026Artificial intelligence/threat detection Artificial intelligence (AI) is no longer just a tool with which we interact. It’s a tool that does something for us. These are called AI agents. You can also send emails, move data, manage software, and more. But there’s a problem. While these agents speed things up, they also […]

A guide to reducing your attack surface

You cannot control when the next critical vulnerability will occur. You can control how much of your environment is exposed when it is published. The problem is that most teams are exposed to the internet more than they realize. Intruder’s head of security takes a deep dive into why this happens and how teams can […]

APT28 uses BEARDSHELL and COVENANT malware to spy on Ukrainian military

Ravi LakshmananMarch 10, 2026Cyber ​​espionage/threat intelligence A Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants called BEARDSHELL and COVENANT to facilitate long-term surveillance of Ukrainian military personnel. In a new report shared with The Hacker News, ESET said the two malware families have been in use since April […]

Threat actors mass scan Salesforce Experience Cloud via modified AuraInspector tool

Ravi LakshmananMarch 10, 2026Cloud security/API security Salesforce has warned of increased activity by threat actors aiming to exploit misconfigurations in publicly accessible Experience Cloud sites using a customized version of an open source tool called AuraInspector. According to the company, this activity involves exploiting customers’ overly permissive Experience Cloud guest user settings to access sensitive […]

CISA, SolarWinds, Ivanti, Workspace One vulnerabilities reported as being actively exploited

Ravi LakshmananMarch 10, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerability list is as follows: CVE-2021-22054 (CVSS Score: 7.5) – A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One […]

Malicious npm package disguised as OpenClaw installer deploys RAT and steals macOS credentials

Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package named ‘@openclaw-ai/openclawai’ was uploaded to the registry on March 3, 2026 by a user named ‘openclaw-ai’. It has been downloaded 178 times so far. This […]

Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

Ravie LakshmananMar 09, 2026Cybersecurity / Hacking Another week in cybersecurity. Another week of “you’ve got to be kidding me.” Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday morning. That’s kind of just how it goes now. The good news? There were some […]

Can the security platform finally be delivered to the mid-market?

hacker newsMarch 9, 2026Endpoint security/security operations Mid-market organizations are constantly striving to achieve the same level of security as enterprise organizations. As awareness of supply chain attacks increases, customers and business partners are defining the security levels that must be met. What if you could easily prove that you meet these stringent security levels to […]

OpenClaw Security Crisis: Detecting AI Agent Risks

You’ve probably heard of OpenClaw. This open source AI agent quickly became one of the fastest growing repositories in GitHub’s history, gaining over 135,000 stars within a few weeks. However, this led to the first major AI agent security crisis of 2026. Reco helps you identify whether an AI agent is present in your environment. […]