Malicious Chrome extension discovered to be stealing business data, email, and browsing history

Cybersecurity researchers have discovered a malicious Google Chrome extension designed to steal data related to Meta Business Suite and Facebook Business Manager. The extension, named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoieffl), is marketed as a way to collect Meta Business Suite data, remove verification pop-ups, and generate two-factor authentication (2FA) codes. This extension has 33 […]

npm updates and considerations to strengthen your supply chain

hacker newsFebruary 13, 2026Supply Chain Security/DevSecOps In December 2025, in response to the Sha1-Hulud incident, npm completed a major certification review aimed at reducing supply chain attacks. While this overhaul is a solid step forward, this change does not make npm projects immune to supply chain attacks. npm remains susceptible to malware attacks – here’s […]

Researchers observe real-world exploitation of BeyondTrust CVSS 9.9 vulnerability

According to watchTowr, threat actors have begun exploiting recently revealed critical security flaws affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products. “Overnight, we observed the first real-world exploitation of BeyondTrust across our global sensors,” Ryan Dewhurst, head of threat intelligence at watchTowr, said in a post on X. “The attacker is abusing […]

Google reports state-sponsored hackers are using Gemini AI to support reconnaissance and attacks

Ravi LakshmananFebruary 12, 2026Cyber ​​espionage/artificial intelligence Google announced Thursday that it observed a North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on targets. This is because various hacker groups continue to weaponize this tool to accelerate various stages of the cyberattack lifecycle, enable information manipulation, […]

Lazarus campaign plants malicious packages in npm and PyPI ecosystem

Cybersecurity researchers discovered a set of malicious packages across npm and Python Package Index (PyPI) repositories linked to a fake recruitment-themed campaign organized by the North Korean-linked Lazarus Group. This coordinated campaign is codenamed graphalgo, after the first package published on the npm registry. It is rated as being active since May 2025. “Developers are […]

AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories

Ravie LakshmananFeb 12, 2026Cybersecurity / Hacking News Threat activity this week shows one consistent signal — attackers are leaning harder on what already works. Instead of flashy new exploits, many operations are built around quiet misuse of trusted tools, familiar workflows, and overlooked exposures that sit in plain sight. Another shift is how access is […]

Why 84% of security programs are late

hacker newsFebruary 12, 2026Enterprise Security/Breach Prevention A new 2026 market intelligence survey of 128 enterprise security decision makers (available here) reveals a clear chasm forming between organizations. It has nothing to do with budget size or industry and everything to do with deciding on one framework. Organizations that implement Continuous Threat Exposure Management (CTEM) see […]

83% of Ivanti EPMM exploits are linked to a single IP on Bulletproof hosting infrastructure

Ravi LakshmananFebruary 12, 2026Vulnerability/Network Security A significant portion of exploitation attempts targeting newly revealed security flaws in Ivanti Endpoint Manager Mobile (EPMM) can be traced back to a single IP address on the bulletproof hosting infrastructure provided by PROSPERO. Threat intelligence firm GreyNoise announced that it recorded 417 exploit sessions from eight unique source IP […]

Fixes zero-day exploit affecting Apple, iOS, macOS, and Apple devices

Ravi LakshmananFebruary 12, 2026Zero-day/vulnerabilities Apple on Wednesday released updates to iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS to address a zero-day flaw that the company says was exploited in a sophisticated cyber attack. The vulnerability is tracked as CVE-2026-20700 (CVSS score: N/A) and is described as a memory corruption issue in dyld, Apple’s dynamic […]

First malicious Outlook add-in discovered that steals over 4,000 Microsoft credentials

Cybersecurity researchers have discovered that this is the first known malicious Microsoft Outlook add-in to be detected in the wild. In this unusual supply chain attack, detailed by Koi Security, an unknown attacker claimed a domain associated with a legitimate, now-abandoned add-in to serve up a fake Microsoft login page, stealing over 4,000 credentials in […]