Chrome extension turns malicious after ownership transfer, allowing code injection and data theft

Two Google Chrome extensions have become malicious after an apparent ownership transfer incident, providing attackers with the means to push malware downstream to customers, inject arbitrary code, and collect sensitive data. The extensions in question were both originally associated with a developer named “akshayanuonline@gmail.com” (BuildMelon) and are listed below. QuickLens – Google Lens search screen […]

CISO Executive Toolkit (Free Download)

What’s included? Get the five most widely used CISO resources in one place. Each asset is designed to solve real-world, recurring leadership challenges such as budgeting, team design, tool selection, best practice alignment, and board communication. Think of it as a ready-to-use toolkit that you can refer to all year long. CISO Budget Benchmarking SurveyUnderstand […]

Web server exploit and MimiKatz used in attacks targeting critical infrastructure in Asia

Ravi LakshmananMarch 9, 2026Threat Intelligence/Web Security High-value organizations in South Asia, Southeast Asia, and East Asia have been targeted by Chinese threat actors as part of a long-running campaign. This activity targets the aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors and has been attributed to a previously undocumented threat group known as […]

OpenAI Codex Security scans 1.2 million commits and finds 10,561 high-severity issues

Rabi LakshmananMarch 7, 2026DevSecOps / Artificial Intelligence OpenAI on Friday began deploying Codex Security, an artificial intelligence (AI)-powered security agent designed to discover, verify, and suggest fixes for vulnerabilities. This feature is available as a research preview to ChatGPT Pro, Enterprise, Business, and Edu customers via Codex Web and will be available for free next […]

Anthropic discovers 22 vulnerabilities in Firefox using Claude Opus 4.6 AI model

Rabi LakshmananMarch 7, 2026Browser security / artificial intelligence Anthropic announced Friday that it has discovered 22 new security vulnerabilities in its Firefox web browser as part of a security partnership with Mozilla. Of these, 14 were classified as severe, 7 were classified as moderate, and 1 was rated as low severity. This issue was resolved […]

Transparent Tribe uses AI to mass produce malware implants in campaign targeting India

Rabi LakshmananMarch 6, 2026Threat Intelligence/Cyber ​​Espionage Pakistan-aligned threat actors known as Transparent Tribe have become the latest hacking group to utilize artificial intelligence (AI)-powered coding tools to attack targets with various implants. According to new findings from Bitdefender, the campaign is designed to generate “a large number of mediocre implants” developed using lesser-known programming languages […]

Multi-stage VOID#GEIST malware that delivers XWorm, AsyncRAT, and Xeno RAT

Cybersecurity researchers have detailed a multi-stage malware campaign that uses batch scripts as a conduit to deliver various encrypted remote access Trojan (RAT) payloads for XWorm, AsyncRAT, and Xeno RAT. This stealth attack chain has been codenamed VOID#GEIST by Securonix Threat Research. At a high level, the obfuscated batch script is used to deploy a […]

MSP guide to scaling cybersecurity with AI-powered risk management

hacker newsMarch 6, 2026Artificial Intelligence/Enterprise Security Scaling cybersecurity services as an MSP or MSSP requires technical expertise and a business model that delivers measurable value at scale. Risk-based cybersecurity is the foundation of that model. Done right, it builds customer trust, increases upsell opportunities, and drives recurring revenue. But delivering this consistently and efficiently requires […]

Iran-linked Muddy Water hackers target US networks with new Dindoor backdoor

A new investigation by Broadcom’s Symantec and Carbon Black Threat Hunters team has uncovered evidence of an Iranian hacker group infiltrating the networks of multiple U.S. companies, including banks, airports, nonprofit organizations and the Israeli arm of a software company. This activity is believed to be the work of a state-sponsored hacking group called MuddyWater […]

China-linked hackers use TernDoor, PeerTime, and BruteEntry in communications attacks in South America

Ravi LakshmananMarch 6, 2026Cyber ​​espionage/threat intelligence China-linked advanced persistent threat (APT) attackers have been targeting critical communications infrastructure in South America since 2024, targeting Windows and Linux systems and edge devices with three different implants. This activity is being tracked by Cisco Talos as UAT-9244 and is described as being closely related to another cluster […]