DeepLoad malware uses ClickFix and WMI persistence to steal browser credentials

Ravi LakshmananMarch 30, 2026Threat Intelligence/Browser Security The new campaign utilizes ClickFix social engineering tactics as a method to distribute a previously undocumented malware loader called DeepLoad. “While likely using AI-assisted obfuscation and process injection to evade static scans, credential theft begins quickly, capturing passwords and sessions even if the primary loader is blocked,” ReliaQuest researchers […]

Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More

Ravie LakshmananMar 30, 2026Cybersecurity / Hacking Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There’s a bit of everything this […]

3 SOC Process Fixes to Unlock Tier 1 Productivity

Is it the threat itself or the processes surrounding the threat that are actually slowing down Tier 1? For many SOCs, the biggest delays are not caused by threats alone. These result from fragmented workflows, manual triage steps, and limited visibility early in the investigation. Correcting these process gaps will help Tier 1s move faster, […]

Secrecy Sprawl in 2026: 9 Points for CISOs

The proliferation of sensitive information continues, accelerating faster than most security teams expected in 2025. GitGuardian’s State of Secrets Sprawl 2026 report analyzed billions of commits across public GitHub and uncovered 29 million new hard-coded secrets in 2025 alone. This is a 34% increase over the previous year and the largest single-year increase ever. This […]

Russian CTRL toolkit delivered via malicious LNK file hijacks RDP via FRP tunnel

Ravi LakshmananMarch 30, 2026Malware/Network Security Cybersecurity researchers have discovered a Russian-originated remote access toolkit distributed via malicious Windows Shortcuts (LNK) files disguised as private key folders. According to Censys, the CTRL toolkit is custom-built using .NET and includes a variety of executables that facilitate credential phishing, keylogging, Remote Desktop Protocol (RDP) hijacking, and reverse tunneling […]

Three China-linked clusters target Southeast Asian governments in 2025 cyberattacks

Ravi LakshmananMarch 30, 2026Threat Intelligence/Network Intrusion Three China-aligned threat activity clusters targeted government agencies in Southeast Asia as part of a “complex and well-funded operation.” This campaign introduced various malware families including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL RAT, PoshRAT, TrackBak Stealer, RawCookie, Hypnosis Loader, and […]

Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

Ravi LakshmananMarch 28, 2026Vulnerability/Network Security According to Defused Cyber ​​and watchTowr, a critical security flaw affecting Citrix NetScaler ADC and NetScaler Gateway was recently uncovered and active reconnaissance activity has been witnessed. Vulnerability CVE-2026-3055 (CVSS score: 9.3) refers to a memory over-read caused by insufficient input validation, which could be exploited by an attacker to […]

CISA adds CVE-2025-53521 to KEV after active F5 BIG-IP APM exploit

Ravi LakshmananMarch 28, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting the F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3), which could allow an attacker […]

TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign

Ravi LakshmananMarch 28, 2026Mobile Security / Email Security Proofpoint has revealed details of a targeted email campaign in which Russian-linked attackers leveraged the recently revealed DarkSword exploit kit to target iOS devices. We have high confidence that this activity is the work of a Russian state-sponsored threat group known as TA446, and is also tracked […]