Dragonweave has landed in the Czech Republic and Taiwan

A new cyber espionage operation codenamed Operation Dragon Weave was observed targeting officials and citizens of the Czech Republic and Taiwan to deploy AdaptixC2 agents. Seqrite Labs said targets for the campaign include government, research, academia, technology, and financial services sectors. This activity distributes spear-phishing emails containing ZIP attachments and triggers an infection chain that […]

Why MSPs are moving beyond vCISO tools

Three years ago, the practical question for MSPs building a cybersecurity practice was which “vCISO platform” to purchase. The term was an apt abbreviation for work at the time, including assessments, recommendations, reports, and perhaps side-lined compliance modules. Since then, this work has become beyond description. Security Growth Platform is a more accurate name for […]

OpenAI Codex authentication token stolen in codexui-android npm supply chain attack

Cybersecurity researchers have revealed details of a new malicious supply chain campaign targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is promoted on GitHub and npm as a remote web UI for OpenAI Codex and attracts more than 29,000 downloads each week. Packages are still available for download […]

Critical flaw in WP Maps Pro can be actively exploited to create administrator accounts

Ravi LakshmananJune 1, 2026Vulnerabilities/website security; Threat actors are actively exploiting a critical security flaw affecting WP Maps Pro, a WordPress plugin with over 15,000 sales on Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, lists, and advanced location […]

5 Misconfigurations Mythos Class AI Can Spot in Your Stack

The attack surface is not unknown. It’s in the defaults that your team inherited three years ago and never checked. ‍ The uncomfortable truth about Mythos class AI as an attack tool is that it does not require sophisticated targeting. All you need is the default. ‍ At Reco, we spend a lot of time […]

Dutch authorities dismantle botnet linked to 17 million infected devices

Ravi LakshmananMay 31, 2026IoT security/network security Dutch authorities announced that they have shut down a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, and carried out malicious attacks. According to Dutch government regulations and the National Cyber ​​Security Center (NCSC), the bot network consisted of at least 17 million […]

PAN-OS GlobalProtect Authentication Bypass under Active Exploit (CVE-2026-0257)

Rabi LakshmananMay 30, 2026Vulnerability/Network Security Palo Alto Networks has warned that a medium-severity security flaw affecting PAN-OS and Prisma Access has recently been disclosed and is being exploited in the wild. This vulnerability is tracked as CVE-2026-0257 (CVSS score: 7.8) and refers to a case of authentication bypass that can be exploited by a malicious […]

ChatGPhish vulnerability turns ChatGPT web summaries into phishing surfaces

Cybersecurity researchers have revealed details of a vulnerability in OpenAI ChatGPT. This vulnerability leverages an artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger a prompt injection and open the door to phishing attacks. The technology has been codenamed ChatGPhish by Permiso Security. “The chatgpt.com response renderer trusts Markdown links and […]

Marimo CVE-2026-39987 After exploitation, attacker uses LLM agent for post-exploitation purposes

Rabi LakshmananMay 29, 2026Vulnerability / Artificial Intelligence After exploiting the publicly accessible Marimo network using recently disclosed vulnerabilities and gaining initial access, unknown attackers have been observed using large-scale language model (LLM) agents to perform post-compromise actions. “The attacker compromised a Marimo notebook with internet access via CVE-2026-39987, extracted two cloud credentials from the compromised […]

New Russian-linked GREYVIBE targets Ukraine with AI-powered cyber attack

Rabi LakshmananMay 29, 2026Cyber ​​espionage/artificial intelligence A previously undocumented threat actor known as GREYVIBE is believed to have been conducting sustained and persistent attacks targeting Ukraine and Ukrainian-affiliated entities since at least August 2025. According to WithSecure, GREYVIBE is assessed to be a Russian-speaking group widely active in the Russian time zone and whose activities […]