LeakNet ransomware uses ClickFix and deploys Deno In-Memory Loader via hacked sites

The ransomware campaign known as LeakNet employed ClickFix social engineering tactics delivered through compromised websites as its initial access method. The use of ClickFix, which allows users to be tricked into manually running malicious commands to address non-existent errors, is a departure from relying on traditional methods of gaining initial access, such as stealing credentials […]
AI is everywhere, but CISOs are still protecting it with yesterday’s skills and tools, study finds

hacker newsMarch 17, 2026Artificial Intelligence/Security Leadership According to Penera’s AI and Adversarial Testing Benchmark Report 2026, the majority of security leaders struggle to defend their AI systems with tools and skills that are not suited to the task. This report, based on a survey of 300 U.S. CISOs and senior security leaders, examines how organizations […]
Konni introduced EndRAT through spear phishing and used KakaoTalk to spread malware

Ravi LakshmananMarch 17, 2026Threat Intelligence/Endpoint Security North Korean attackers have been observed sending phishing attacks to compromise targets, gain access to victims’ KakaoTalk desktop applications, and distribute malicious payloads to specific contacts. South Korean threat intelligence firm Genians attributes this activity to a hacker group called Konni. “Initial access was achieved through a spear-phishing email […]
CISA reports that Wing FTP vulnerability that leaks server paths is being actively exploited

Ravi LakshmananMarch 17, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw affecting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This vulnerability, CVE-2025-47813 (CVSS score: 4.3), is an information disclosure vulnerability that allows the installation path of an application to […]
GlassWorm attack uses stolen GitHub tokens to force-push malware to Python repositories

Ravi LakshmananMarch 16, 2026Malware/Cryptocurrency The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages stolen GitHub tokens to inject malware into hundreds of Python repositories. “This attack targets Python projects including Django apps, ML research code, Streamlit dashboards, and PyPI packages by adding obfuscated code to files such as setup.py, main.py, […]
Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More

Ravie LakshmananMar 16, 2026Cybersecurity / Hacking Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too […]
Why security verification becomes agentic

If you’re running security in a fairly complex organization, your validation stack will likely look like this: In one corner is a BAS tool. It could be another penetration testing effort or an automated penetration testing product. Vulnerability scanners provide information to attack surface management platforms located elsewhere. Each tool provides a portion of the […]
ClickFix campaign spreads MacSync macOS Infostealer via fake AI tool installer

Three different ClickFix campaigns were found to serve as delivery vectors for the deployment of a macOS information stealer called MacSync. Sophos researchers Jagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko, and Matt Wixey said, “Unlike traditional exploit-based attacks, this technique relies entirely on user interaction (usually in the form of copying and executing commands), making it […]
DRILLAPP backdoor targets Ukraine, exploits Microsoft Edge debugging for stealth espionage

Ukrainian organizations have emerged as targets of a new campaign likely orchestrated by Russian-linked threat actors, according to a report from S2 Grupo’s LAB52 threat intelligence team. This campaign, observed in February 2026, is assessed as a duplicate of a previous campaign launched by Laundry Bear (also known as UAC-0190 or Void Blizzard) targeting the […]
Android 17 blocks non-accessible apps from accessibility APIs to prevent malware abuse

Ravi LakshmananMarch 16, 2026Mobile security/data protection Google is testing a new security feature as part of Android Advanced Protected Mode (AAPM) that prevents certain types of apps from using accessibility services APIs. This change is included in Android 17 Beta 2 and was first reported by Android Authority last week. AAPM was introduced by Google […]