149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

Cybersecurity researchers have warned of a surge in retaliatory hacktivist activity in the wake of the joint US-Israeli military operations against Iran, codenamed Epic Fury and Roaring Lion. “The hacktivist threat in the Middle East is highly skewed, with two groups, Keymous+ and DieNet, leading nearly 70% of all attack activity from February 28 to […]
Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

Google announced that it has identified a “new and powerful” exploit kit called Coruna (also known as CryptoWaters) targeting Apple iPhone models running iOS versions 13.0 through 17.2.1. According to the Google Threat Intelligence Group (GTIG), the exploit kit included five complete iOS exploit chains and a total of 23 exploits. It has no effect […]
New RFP template for AI usage control and AI governance

hacker newsMarch 4, 2026Artificial Intelligence / SaaS Security As AI becomes the central engine of enterprise productivity, security leaders are finally getting the green light and budget to secure it. But a quiet crisis is brewing in the boardroom. Many organizations know they need “AI governance” but don’t know what they actually want. The CISO’s […]
Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

Ravi LakshmananMarch 4, 2026Threat Intelligence/Application Security Cybersecurity researchers have flagged a malicious Packagist PHP package masquerading as a Laravel utility that acts as a vector for a cross-platform remote access trojan (RAT) that works on Windows, macOS, and Linux systems. The names of the packages are listed below – nhattuanbl/lara-helper (download 37) nhattuanbl/simple-queue (download 29) […]
APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

Ravi LakshmananMarch 4, 2026Malware / Windows Security Cybersecurity researchers have revealed details of an advanced persistent threat (APT) group called Silver Dragon that has been linked to cyberattacks targeting organizations in Europe and Southeast Asia since at least mid-2024. “Silver Dragon gains initial access by exploiting public internet servers and delivering phishing emails containing malicious […]
CISA adds actively exploited VMware Aria operational flaw CVE-2026-22719 to KEV catalog

Ravi LakshmananMarch 4, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw affecting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog as being actively exploited in the wild. High severity vulnerability CVE-2026-22719 (CVSS score: 8.1) is described as a case of […]
Fake tech support spam deploys customized Havoc C2 across organization

Threat hunters are cautioned as part of a new campaign in which malicious actors pose as fake IT support and offer the Havoc command and control (C2) framework as a precursor to data theft and ransomware attacks. The intrusion, which Huntress identified last month across five partner organizations, involved the attacker using email spam as […]
The 3 Steps CISOs Must Follow

Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1 analysts sit at the front line of detection, and yet they are also the most vulnerable to the cognitive and organizational pressures that quietly erode […]
Open Source CyberStrikeAI Deploys AI-Driven FortiGate Attacks in 55 Countries

Ravi LakshmananMarch 3, 2026Vulnerability / Artificial Intelligence The attackers behind the recently revealed artificial intelligence (AI)-assisted campaign targeting Fortinet’s FortiGate appliances leveraged an open-source AI-native security testing platform called CyberStrikeAI to carry out the attack. This new discovery is attributed to Team Cymru, whose use was detected after analyzing the IP address (‘212.11.64’).[.]250″) was used […]
AI Agents: The Next Wave of Identity Dark Matter

The rise of MCP in the enterprise Model Context Protocol (MCP) is rapidly becoming a practical way to move LLM from “chat” to real work. By providing structured access to applications, APIs, and data, MCP enables prompt-driven AI agents that can retrieve information, take actions, and automate end-to-end business workflows across the enterprise. This is […]