Researchers discover pre-Stuxnet ‘fast16’ malware targeting engineering software

Cybersecurity researchers have discovered new Lua-based malware that was created several years before the infamous Stuxnet worm, which was aimed at disrupting Iran’s nuclear program by sabotaging uranium enrichment centrifuges. A previously undocumented cyber sabotage framework dates back to 2005 and primarily targeted high-precision calculation software to falsify results, according to a new report published […]

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

Ravi LakshmananApril 25, 2026Network security/infrastructure security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below – CVE-2024-57726 (CVSS Score: 9.9) – A […]

FIRESTARTER backdoor hits federal Cisco Firepower devices, survives security patch

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that Cisco Firepower devices at an unnamed federal civilian agency running Adaptive Security Appliance (ASA) software were compromised by malware known as FIRESTARTER in September 2025. According to CISA and the UK National Cyber ​​Security Center (NCSC), FIRESTARTER has been assessed as a backdoor designed […]

NASA employees fall for Chinese phishing scam targeting US defense software

Ravi LakshmananApril 24, 2026Espionage/National Security; NASA’s Office of Inspector General (OIG) has revealed how Chinese nationals posed as U.S. researchers as part of a spear-phishing campaign to obtain sensitive information from space agencies, government agencies, universities, and private companies in violation of export control laws. “For years, NASA employees and research collaborators believed they were […]

Continuous observability as a decision engine

The AI ​​agent authority gap – from non-governance to delegation As we discussed in a previous article, AI agents are exposing structural gaps in enterprise security, but the problem is often viewed very narrowly. The problem is not simply that agents are new subjects. That means agents are delegated actors. They do not emerge with […]

26 FakeWallet apps targeting crypto seed phrases found in Apple App Store

Cybersecurity researchers have discovered a series of malicious apps in the Apple App Store that impersonate popular cryptocurrency wallets and attempt to steal recovery phrases and private keys since at least the fall of 2025. “When launched, these apps redirect users to a browser page that resembles the App Store and distribute Trojanized versions of […]

Tropic Trooper deploys AdaptixC2 using Trojanized SumatraPDF and GitHub

Ravi LakshmananApril 24, 2026Malware/Threat Intelligence Chinese-speaking individuals have been targeted in a new campaign that uses a trojanized version of the SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the exploitation of Microsoft Visual Studio Code (VS Code) tunnels for remote access. Zscaler ThreatLabz, which discovered the campaign last month, says […]

LMDeploy CVE-2026-33626 flaw exploited within 13 hours of publication

A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, unpacking, and serving LLMs, has become exploitable in the wild less than 13 hours after its disclosure. This vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), is related to server-side request forgery (SSRF) vulnerabilities and can be exploited to access sensitive data. “LMDeploy’s vision language […]

UNC6692 Deploying SNOW malware by impersonating IT helpdesk via Microsoft Teams

A previously undocumented cluster of threat activity known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy custom malware suites on compromised hosts. “Like many other intrusions in recent years, UNC6692 relied heavily on impersonating IT help desk employees to persuade victims to accept Microsoft Teams chat invitations from accounts […]

Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

According to new findings from JFrog and Socket, the Bitwarden CLI was compromised as part of a newly discovered and ongoing Checkmarx supply chain campaign. “The version of the affected package appears to be @bitwarden/cli@2026.4.0, and the malicious code was exposed in the file ‘bw1.js’ included in the package contents,” the application security company said. […]