MuddyWater uses Microsoft Teams to steal credentials in false flag ransomware attack

An Iranian state-backed hacking group known as MuddyWater (also known as Mango Sandstorm, Seedworm, and Static Kitten) is believed to have been responsible for the ransomware attack, dubbed a “false flag operation.” This attack, observed by Rapid7 in early 2026, was found to utilize social engineering techniques via Microsoft Teams to initiate the infection sequence. […]
The Hacker News launches “Cybersecurity Stars Awards 2026” — now accepting applications

hacker newsMay 6, 2026Security Leadership/Industry Recognition For nearly 20 years, we at Hacker News have been primarily reporting horror stories about cyberspace: massive hacks, broken systems, and new threats. But behind every headline there’s a quieter, better story. This is the story of leaders who make tough decisions under pressure, teams who build smarter defenses, […]
The AI agent is already within the perimeter. Do you know what they do?

Analysts recently confirmed what identity security teams have been quietly worrying about. That means AI agents are being deployed faster than companies can manage. Gartner states in its first Market Guide for Guardian Agents that “enterprise adoption of AI agents is accelerating and outpacing the maturity of governance policy management.” Business leaders can request access […]
Google’s Android app receives public certification to thwart supply chain attacks

Ravi LakshmananMay 6, 2026Android / data security Google announced binary transparency enhancements for Android as a way to protect its ecosystem from supply chain attacks. Google’s product and security teams said, “This new public ledger ensures that the Google apps on devices are exactly what we intended them to be built and distributed.” This effort […]
CloudZ RAT exploits Windows Phone links to steal credentials and OTPs

Ravi LakshmananMay 6, 2026Endpoint security/threat intelligence Cybersecurity researchers have detailed an intrusion that involved the use of the CloudZ remote access tool (RAT) and an earlier undocumented plugin called Pheno to facilitate credential theft. “Based on the functionality of the CloudZ RAT and Pheno plugin, it was intended to steal victims’ credentials and potentially one-time […]
Palo Alto PAN-OS vulnerability exploited to allow remote code execution

Ravi LakshmananMay 6, 2026Vulnerability/Network Security Palo Alto Networks has issued an advisory warning that a critical buffer overflow vulnerability in PAN-OS software is being exploited in the wild. This vulnerability is tracked as CVE-2026-0300 and is described as a case of unauthenticated remote code execution. If the User Identity Authentication Portal is configured to allow […]
Critical flaw in Apache HTTP/2 (CVE-2026-23918) allows DoS and potential RCE

Ravi LakshmananMay 5, 2026Vulnerabilities / Server Security The Apache Software Foundation (ASF) has released security updates that address several security vulnerabilities in its HTTP server, including a serious vulnerability that could lead to remote code execution (RCE). The vulnerability is tracked as CVE-2026-23918 (CVSS score: 8.8) and is described as a case of “double free […]
DAEMON Tools supply chain attack compromises official installer with malware

Ravi LakshmananMay 5, 2026Endpoint security/software security Kaspersky Lab findings reveal a new supply chain attack targeting the DAEMON Tools software, whose installer was compromised and delivered a malicious payload. “These installers are distributed from the official DAEMON Tools website and are signed with digital certificates owned by the DAEMON Tools developers,” said Kaspersky researchers Igor […]
China-linked UAT-8302 uses regionally shared APT malware to target governments

Ravi LakshmananMay 5, 2026Network security/endpoint security Attacks by advanced persistent threat (APT) groups aligned with China are believed to target government agencies in South America from at least late 2024 onwards, and in southeastern Europe by 2025. This activity is being tracked by Cisco Talos as UAT-8302, and post-exploitation activity includes the deployment of a […]
Backdoor attackers know, but most security teams haven’t shut them down yet

All the AI tools, workflow automation, and productivity apps that employees have connected to Google and Microsoft this year have left something behind. It’s a persistent OAuth token with no expiration date, no automatic cleanup, and, in most organizations, no one to monitor it. Boundary controls don’t know about it. MFA doesn’t stop that. And […]