Critical flaw in n8n could allow remote code execution and disclosure of stored credentials

Ravi LakshmananMarch 11, 2026 Vulnerabilities/Application Security Cybersecurity researchers have detailed two security flaws that have been patched in the n8n workflow automation platform. This includes two critical bugs that could lead to the execution of arbitrary commands. The vulnerabilities are listed below – CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to remote code […]

Meta disables 150,000 accounts linked to Southeast Asia fraud center in global crackdown

Ravi LakshmananMarch 11, 2026Cybercrime/Artificial Intelligence Meta announced on Wednesday that it has disabled more than 150,000 accounts associated with fraud centers in Southeast Asia as part of a coordinated effort with authorities in Thailand, the United States, the United Kingdom, Canada, South Korea, Japan, Singapore, the Philippines, Australia, New Zealand, and Indonesia. The company said […]

Dozens of vendors patch security flaws across enterprise software and network devices

Ravi LakshmananMarch 11, 2026Vulnerabilities / Enterprise Security SAP has released a security update that addresses two critical security flaws that can be exploited to execute arbitrary code on affected systems. The vulnerabilities in question are listed below – CVE-2019-17571 (CVSS score: 9.8) – Code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS […]

What boards must demand in the age of automated AI abuse

“You knew and you could have acted, so why didn’t you act?” This is the question you don’t want to be asked. And in the aftermath of an incident, leaders are faced with an increasing number of questions to answer. For years, many executives and boards have treated large vulnerability backlogs as an unpleasant but […]

Microsoft patches 84 flaws (including 2 public zero-days) in March Patch Tuesday

Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two listed as publicly known. Of these, 8 are rated as “critical” and 76 are rated as “important.” Forty-six of the patched vulnerabilities are related to privilege escalation, followed by remote code execution (18), information disclosure (10), […]

UNC6426 Exploit nx npm supply chain attack to gain AWS administrator access within 72 hours

Ravi LakshmananMarch 11, 2026DevSecOps / AI Security The attacker, known as UNC6426, leveraged keys stolen after last year’s nx npm package supply chain breach to fully compromise victims’ cloud environments within 72 hours. The attack began with the theft of a developer’s GitHub token, which the threat actor used to gain unauthorized access to the […]

5 malicious Rust crates and AI bots exploit CI/CD pipelines to steal developer secrets

Cybersecurity researchers have discovered five malicious Rust crates that send .env file data to threat actors under the guise of time-related utilities. The Rust packages published on crates.io are: chrono_anchor dnp3times time_calibrator time_calibrators time-sync These crates impersonated timeapi.io on a per-socket basis and were published between late February and early March 2026. It has been […]

FortiGate devices are exploited to infiltrate the network and steal service account credentials

Ravi LakshmananMarch 10, 2026Network security/vulnerabilities Cybersecurity researchers are warning of a new campaign in which attackers are exploiting FortiGate next-generation firewall (NGFW) appliances as entry points to penetrate victim networks. This activity involves exploiting recently disclosed security vulnerabilities or weak credentials to extract configuration files containing service account credentials and network topology information, SentinelOne said […]

KadNap malware infects over 14,000 edge devices, powering stealth proxy botnet

Cybersecurity researchers have discovered a new malware called KadNap that primarily targets Asus routers and forces them to join a botnet that proxies malicious traffic. According to Lumen’s Black Lotus Labs team, the malware was first detected in August 2025 and has spread to more than 14,000 infected devices, with more than 60% of victims […]

New ‘LeakyLooker’ flaw in Google Looker Studio could allow cross-tenant SQL queries

Ravi LakshmananMarch 10, 2026Database security/vulnerabilities Cybersecurity researchers have revealed nine cross-tenant vulnerabilities in Google Looker Studio. This vulnerability could allow an attacker to execute arbitrary SQL queries against a victim’s database, potentially exposing sensitive data within an organization’s Google Cloud environment. Tenable collectively refers to these shortcomings as LeakyLooker. There is no evidence that this […]