Infy ​​hackers resume operations with new C2 servers after Iran internet blackout ends

Rabi LakshmananFebruary 5, 2026Malware/Cyber ​​Espionage The elusive Iranian threat group known as Infy (also known as Prince of Persia) has evolved its tactics as part of an effort to cover its tracks even as it prepares new command and control (C2) infrastructure to coincide with the end of a widespread regime-imposed internet blackout earlier in […]

n8n critical flaw CVE-2026-25049 allows execution of system commands via malicious workflows

Rabi LakshmananFebruary 5, 2026Workflow automation/vulnerabilities A critical new security vulnerability has been disclosed in the n8n workflow automation platform that could be successfully exploited to execute arbitrary system commands. This flaw, tracked as CVE-2026-25049 (CVSS score: 9.4), is due to improper sanitization that bypasses safety measures put in place to address CVE-2025-68613 (CVSS score: 9.9), […]

Malicious NGINX configuration enables massive web traffic hijacking campaign

Rabi LakshmananFebruary 5, 2026Web security/vulnerabilities Cybersecurity researchers have detailed an active web traffic hijacking campaign that targets NGINX installations and administrative panels such as Baota (BT) in an attempt to route them through attackers’ infrastructure. Datadog Security Labs said it has observed threat actors associated with recent React2Shell (CVE-2025-55182, CVSS score: 10.0) exploits using malicious […]

Microsoft develops scanner to detect backdoors in open weight large-scale language models

Rabi LakshmananFebruary 4, 2026Artificial intelligence/software security Microsoft announced Wednesday that it has developed a lightweight scanner that can detect backdoors in open weight large-scale language models (LLMs) and improve overall reliability for artificial intelligence (AI) systems. According to the tech giant’s AI security team, the scanner leverages three observable signals that can be used to […]

DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

Rabi LakshmananFebruary 4, 2026Malware/Endpoint Security Threat hunters have revealed details of a new stealth malware campaign called DEAD#VAX. The campaign combines “disciplined techniques and sophisticated exploitation of legitimate system functionality” to bypass traditional detection mechanisms and deploy a remote access Trojan (RAT) known as AsyncRAT. “This attack leverages IPFS-hosted VHD files, extreme script obfuscation, runtime […]

China-linked Amaranth-Dragon exploits WinRAR flaws for espionage

China-linked threat actors are believed to be involved in new cyber espionage operations targeting governments and law enforcement agencies across Southeast Asia throughout 2025. Check Point Research is tracking a previously undocumented cluster of activity under the name “Amaranth-Dragon,” which it says shares a connection with the APT 41 ecosystem. Target countries include Cambodia, Thailand, […]

Orchid Security brings continuous identity observability to enterprise applications

hacker newsFebruary 4, 2026Identity Security/Security Operations An innovative approach to discovering, analyzing, and managing identity usage that goes beyond traditional IAM controls. Challenge: Identity exists outside the identity stack Identity and access management tools were built to manage users and directories. Modern businesses run on applications. Over time, identity logic has moved into application code, […]

How early decisions shape incident response investigations

Many incident response failures are not due to a lack of tools, intelligence, or technical skills. They result from what happens immediately after detection, when pressure is high and information is incomplete. We’ve seen IR teams recover from advanced intrusions with limited telemetry. I’ve also seen teams lose control of investigations they could have handled. […]

Microsoft warns that Python Infostears is targeting macOS via fake ads and installers

Ravi LakshmananFebruary 4, 2026Malvertising/information thieves Microsoft warned that information theft attacks are “rapidly expanding” beyond Windows to target Apple’s macOS environment by leveraging cross-platform languages ​​such as Python and abusing trusted platforms for large-scale distribution. The tech giant’s Defender Security Research team said it has observed information stealer campaigns targeting macOS since late 2025 using […]

Eclipse Foundation requires pre-publication security checks for open VSX extensions

Ravi LakshmananFebruary 4, 2026Supply chain security/secure coding The Eclipse Foundation, which manages the Open VSX Registry, announced plans to conduct security checks before Microsoft Visual Studio Code (VS Code) extensions are published to open source repositories to combat supply chain threats. This move marks a shift from a reactive to a proactive approach to ensuring […]