Veeam patches 7 critical backup and replication flaws that could allow remote code execution

Ravi LakshmananMarch 13, 2026Vulnerabilities / Enterprise Security Veeam has released a security update that addresses multiple critical vulnerabilities in its backup and replication software that could allow remote code execution if successfully exploited. The vulnerabilities are: CVE-2026-21666 (CVSS score: 9.9) – Vulnerability that allows authenticated domain users to execute remote code on backup servers. CVE-2026-21667 […]
Rust-based VENON malware targets 33 Brazilian banks with credential-stealing overlay

Ravi LakshmananMarch 12, 2026Malware/Cybercrime Cybersecurity researchers have revealed details of a new banking malware written in Rust that targets users in Brazil. This is significantly different from other known Delphi-based malware families associated with the Latin American cybercrime ecosystem. The malware is designed to infect Windows systems and was first discovered last month, codenamed VENON […]
Hive0163 uses AI-assisted Slopoly malware for persistent access in ransomware attacks

Ravi LakshmananMarch 12, 2026Artificial intelligence/malware Cybersecurity researchers have revealed details of a suspected artificial intelligence (AI)-generated malware codenamed “Slopoly” used by a financially motivated attacker named Hive0163. “Although AI-generated malware like Slopoly is still relatively under the radar, it shows how easily threat actors can weaponize AI and develop new malware frameworks in a fraction […]
How to Scale Phishing Detection in Your SOC: 3 Steps for CISOs

Phishing has quietly turned into one of the hardest enterprise threats to expose early. Instead of crude lures and obvious payloads, modern campaigns rely on trusted infrastructure, legitimate-looking authentication flows, and encrypted traffic that conceals malicious behavior from traditional detection layers. For CISOs, the priority is now clear: scale phishing detection in a way that […]
OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & More

Ravie LakshmananMar 12, 2026Cybersecurity / Hacking News Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner than we’d […]
Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

The most dangerous phishing campaigns aren’t just designed to fool employees. Many are designed to exhaust the analysts investigating them. When a phishing investigation takes 12 hours instead of five minutes, the outcome can shift from a contained incident to a breach. For years, the cybersecurity industry has focused on the front door of phishing […]
Apple issues security update for older iOS devices targeted by Coruna WebKit exploit

Ravi LakshmananMarch 12, 2026Vulnerabilities/Malware Apple on Wednesday backported a fix to an older version of iOS, iPadOS, and macOS Sonoma after a security flaw was discovered to be used as part of the Coruna exploit kit. The vulnerability, tracked as CVE-2023-43010, is related to an unspecified vulnerability in WebKit that could lead to memory corruption […]
Six Android malware families target Pix payments, banking apps, and crypto wallets

Cybersecurity researchers have discovered six new Android malware families with the ability to steal data from compromised devices and commit financial fraud. Android malware ranges from traditional banking Trojans such as PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT to full-fledged remote administration tools such as SUXRAT. According to Zimperium, PixRevolution targets Brazil’s Pix instant […]
CISA reports active exploitation of n8n RCE bug as 24,700 instances remain exposed

Ravi LakshmananMarch 12, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting n8n to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. This vulnerability is tracked as CVE-2025-68613 (CVSS score: 9.9) and involves an expression injection case that could lead […]
Researchers trick Perplexity’s Comet AI browser into phishing scam in under 4 minutes

Ravi LakshmananMarch 11, 2026Artificial intelligence/browser security Agent web browsers that leverage artificial intelligence (AI) capabilities to autonomously perform actions across multiple websites on your behalf can be trained and tricked into falling prey to phishing and fraud traps. The core of the attack exploits the tendency of AI browsers to infer their behavior and use […]