Starkiller phishing suite uses AitM reverse proxy to bypass multi-factor authentication

Cybersecurity researchers have revealed details of a new phishing suite called Starkiller that bypasses multi-factor authentication (MFA) protections by proxying legitimate login pages. It is promoted as a cybercrime platform by a threat group calling itself Jinkusu, and customers are given access to a dashboard where they can select brands to impersonate and enter the […]
Microsoft warns that OAuth redirect abuse can deliver malware to government targets

Ravi LakshmananMarch 3, 2026Phishing/Malware Microsoft on Monday warned of phishing campaigns that utilize phishing emails and OAuth URL redirection mechanisms to bypass traditional phishing defenses implemented in email and browsers. The company says the campaign targets government and public sector organizations, and the ultimate goal is to redirect victims to attacker-controlled infrastructure without stealing their […]
Google confirms CVE-2026-21385 in Qualcomm Android component has been exploited

Ravi LakshmananMarch 3, 2026Vulnerabilities / Mobile Security Google on Monday revealed that a high-severity security flaw affecting an open-source Qualcomm component used in Android devices was exploited. The vulnerability in question is CVE-2026-21385 (CVSS score: 7.8), which is a buffer overread in the graphics component. “Adding user-specified data without checking available buffer space will corrupt […]
SloppyLemming uses dual malware chain to target Pakistan and Bangladesh governments

Ravi LakshmananMarch 3, 2026Malware/phishing The threat activity cluster known as SloppyLemming is believed to be the result of new attacks targeting government agencies and critical infrastructure operators in Pakistan and Bangladesh. According to Arctic Wolf, this activity occurred between January 2025 and January 2026. This activity involves the use of two different attack chains delivering […]
New Chrome vulnerability allows malicious extension to escalate privileges via Gemini panel

Ravi LakshmananMarch 2, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have detailed a patched security flaw in Google Chrome that could allow an attacker to escalate privileges and access local files on the system. This vulnerability is tracked as CVE-2026-0628 (CVSS score: 8.8) and is described as a case of insufficient policy enforcement of the WebView […]
Google develops Merkle tree certificate to enable quantum-proof HTTPS in Chrome

Ravi LakshmananMarch 2, 2026Encryption/Browser Security Google has announced a new program in its Chrome browser that ensures HTTPS certificates are secure against future risks posed by quantum computers. “To ensure ecosystem scalability and efficiency, Chrome has no immediate plans to add traditional X.509 certificates, including post-quantum cryptography, to the Chrome root store,” the Chrome Secure […]
SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

Ravie LakshmananMar 02, 2026Cybersecurity / Hacking This week is not about one big event. It shows where things are moving. Network systems, cloud setups, AI tools, and common apps are all being pushed in different ways. Small gaps in access control, exposed keys, and normal features are being used as entry points. The pattern becomes […]
How to protect your SaaS from bot attacks using SafeLine WAF

Most SaaS teams remember the day their user traffic started to increase rapidly. Few people notice the day bots start targeting them. On paper, everything looks good: more signups, more sessions, more API calls. But in reality, something doesn’t feel right. Signups are increasing, but users aren’t activating. Server costs increase faster than revenue. Logs […]
APT28 is related to CVE-2026-21513 MSHTML 0-Day exploited before February 2026 Patch Tuesday

Ravi LakshmananMarch 2, 2026Vulnerability/Threat Intelligence New findings from Akamai reveal that a recently disclosed security flaw patched by Microsoft may have been exploited by a Russian-linked state-sponsored threat actor known as APT28. The vulnerability in question is CVE-2026-21513 (CVSS score: 8.8), a high-severity security feature bypass affecting the MSHTML framework. “A failure in the MSHTML […]
North Korean hackers publish 26 npm packages that hide cross-platform RAT Pastebin C2

Ravi LakshmananMarch 2, 2026Supply chain attacks/malware Cybersecurity researchers have revealed a new iteration of the ongoing Contagion Interview campaign. In this campaign, North Korean threat actors published a set of 26 malicious packages to the npm registry. Although these packages pose as developer tools, they contain the ability to use seemingly innocuous Pastebin content as […]