The importance of behavioral analysis in cyber attacks using AI

hacker newsMarch 20, 2026Artificial intelligence/data protection Artificial intelligence (AI) is changing the way individuals and organizations conduct many activities, including the way cybercriminals conduct phishing attacks and iterate malware. Cybercriminals are now using AI to generate personalized phishing emails, deepfakes, and malware to evade traditional detection by impersonating normal user activity and bypassing traditional security […]
Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover

Ravi LakshmananMarch 20, 2026Web security/vulnerabilities Sansec warns that Magento’s REST API has a critical security flaw that could allow an unauthenticated attacker to upload arbitrary executable files and perform code execution or account takeover. This vulnerability was codenamed PolyShell by Sansec due to the fact that the attack relies on disguising malicious code as an […]
Department of Justice thwarts IoT botnet of 3 million devices behind record 31.4 Tbps global DDoS attack

The U.S. Department of Justice (DoJ) announced Thursday that it has disrupted command and control (C2) infrastructure used by several Internet of Things (IoT) botnets, including AISURU, Kimwolf, JackSkid, and Mossad, as part of a court-authorized law enforcement operation. In this effort, authorities in Canada and Germany are also targeting the operators behind these botnets, […]
Apple warns that older iPhones are vulnerable to Coruna and DarkSword exploit kit attacks

Ravi LakshmananMarch 20, 2026Mobile security/malware Apple is reminding users still running older versions of iOS to update their iPhones to protect against web-based attacks carried out through powerful exploit kits such as Coruna and DarkSword. These attacks leverage malicious web content to target older versions of iOS, triggering infection chains that lead to the theft […]
Speagle malware hijacks Cobra DocGuard and steals data via compromised servers

Ravi LakshmananMarch 19, 2026Cyber espionage/threat intelligence Cybersecurity researchers have reported a new malware called Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to covertly collect sensitive information from infected computers and send it to a Cobra DocGuard server that has been compromised by an attacker, masking […]
54 EDR killers use BYOVD to exploit 34 signed vulnerability drivers to disable security

A new analysis of endpoint detection and response (EDR) killers reveals that 54 of them leverage a technique known as bring-your-own-vulnerable-driver (BYOVD), for a total of 34 vulnerable drivers. EDR killer programs are common in ransomware intrusions because they provide a way for affiliates to neutralize security software before deploying file-encrypting malware. This is done […]
FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

Ravie LakshmananMar 19, 2026Cybersecurity / Hacking News ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that shouldn’t work anymore but still do. Some of it looks simple, almost sloppy, until you see how […]
New Perseus Android banking malware monitors Notes app and extracts sensitive data

Ravi LakshmananMarch 19, 2026Malware/Mobile Security Cybersecurity researchers have uncovered a new Android malware family called Perseus that is actively distributed for device takeover (DTO) and financial fraud. Perseus builds on the foundations of Cerberus and Phoenix while evolving into a “more flexible and capable platform” for compromising Android devices through dropper apps distributed via phishing […]
How Ceros gives security teams visibility and control over their code

Security teams have spent years building identity and access controls for human users and service accounts. However, a new category of actors has quietly infiltrated most enterprise environments and operates completely outside of their control. Anthropic’s AI coding agent, Claude Code, is now running at scale across engineering organizations. It reads files, executes shell commands, […]
DarkSword iOS exploit kit uses 6 flaws, 3 zero-days to take over entire device

A new exploit kit for Apple iOS devices designed to steal sensitive data has been exploited by multiple attackers since at least November 2025, according to a report from Google Threat Intelligence Group (GTIG), iVerify, and Lookout. According to GTIG, multiple commercial surveillance vendors and suspected state-sponsored attackers utilized the full-chain exploit kit, codenamed DarkSword, […]