New GPUBreach attack enables full CPU privilege escalation via GDDR6 bitflip

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that can be exploited to escalate privileges and, in some cases, take complete control of the host. The efforts are codenamed GPUBreach, GDDRHammer, and GeForge. GPUBreach goes a step further than GPUHammer by demonstrating for the first time that RowHammer bitflips […]
China-linked Storm-1175 exploits zero-day to rapidly deploy Medusa ransomware

Ravi LakshmananApril 7, 2026Vulnerability/Threat Intelligence China-based threat actors known for deploying Medusa ransomware are said to be involved in weaponizing a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and compromise vulnerable internet-connected systems. The Microsoft Threat Intelligence team said, “Due to the attackers’ high operational tempo and proficiency in identifying exposed perimeter […]
Flowise AI Agent Builder under active CVSS 10.0 RCE exploitation. Over 12,000 instances exposed

Ravi LakshmananApril 7, 2026Artificial intelligence/vulnerabilities Threat actors are exploiting maximum-severity security flaws in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that may allow remote code execution. In an advisory released in September 2025, Flowise states, “The […]
Iran-linked password dissemination campaign targets more than 300 Israeli Microsoft 365 organizations

As conflict continues in the Middle East, Iranian-linked attackers are suspected to be behind a password dissemination campaign targeting Microsoft 365 environments in Israel and the United Arab Emirates. According to Check Point, this activity is assessed as ongoing and carried out in three separate attack waves that occurred on March 3, 2026, March 13, […]
North Korea-linked hackers use GitHub as C2 in multi-stage attack targeting South Korea

Ravi LakshmananApril 6, 2026Malware/Threat Intelligence Threat actors believed to be affiliated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as a command and control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. According to Fortinet FortiGuard Labs, the attack chain includes an obfuscated Windows shortcut (LNK) file that […]
How SOCs solve critical risks in three steps

The attack surface no longer exists on a single operating system, nor are the campaigns targeting it. In enterprise environments, attackers move Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform. For security leaders, this creates a costly operational gap. This […]
Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More

Ravie LakshmananApr 06, 2026Cybersecurity / Hacking This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster […]
How LiteLLM turned developer machines into attackers’ credential vaults

The most active enterprise infrastructure within a company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents. In March 2026, TeamPCP threat actors proved how valuable developer machines can be. A supply chain attack against LiteLLM, a popular […]
Qilin and Warlock ransomware uses vulnerable drivers to disable over 300 EDR tools

Ravi LakshmananApril 6, 2026Ransomware/Endpoint Security According to Cisco Talos and Trend Micro research, threat actors associated with Qilin and Warlock ransomware operations have been observed using Bring Your Own Vulnerability Driver (BYOVD) techniques to silence security tools running on compromised hosts. The Qilin attack analyzed by Talos deployed a malicious DLL named ‘msimg32.dll’ that started […]
BKA identifies REvil leader behind 130 ransomware attacks in Germany

Ravi LakshmananApril 6, 2026Cybercrime/Financial Crime The German Federal Criminal Police (also known as BKA or Bundeskcriminalamt) has revealed the identity of the main threat actor associated with the now-defunct REvil (also known as Sodinokibi) ransomware-as-a-service (RaaS) operation. The actor, who goes by the alias UNKN, acts as a representative for the group and promoted ransomware […]