Google disrupts IPIDEA, one of the world’s largest residential proxy networks

Google announced Wednesday that it has joined forces with other partners to disrupt IPIDEA. IPIDEA is one of the world’s largest residential proxy networks, the company says. To this end, the company said it has taken legal action to suspend dozens of domains used to control devices and proxy traffic passing through them. At the […]
Fake Moltbot AI coding assistant on VS Code marketplace drops malware

Cybersecurity researchers have flagged a new malicious Microsoft Visual Studio Code (VS Code) extension for Moltbot (formerly known as Clawdbot) on the official extension marketplace. The extension claims to be a free artificial intelligence (AI) coding assistant, but it secretly drops a malicious payload on compromised hosts. The extension was named “ClawdBot Agent – AIcoding […]
Russia’s Electrum linked to December 2025 cyber attack on Polish power grid

Ravi LakshmananJanuary 28, 2026Critical Infrastructure/Threat Intelligence A “coordinated” cyber attack targeting multiple sites across Poland’s electricity grid is believed with medium confidence to be the work of a Russian state-backed hacking group known as ELECTRUM. Operational technology (OT) cybersecurity firm Dragos said in a new intelligence brief released Tuesday that the late December 2025 activity […]
Two high-severity flaws in n8n allow authenticated remote code execution

Ravi LakshmananJanuary 28, 2026Vulnerability/Workflow Automation Cybersecurity researchers have uncovered two new security flaws in the n8n workflow automation platform, including a critical vulnerability that could allow remote code execution. The vulnerabilities discovered by the JFrog Security Research team are as follows: CVE-2026-1470 (CVSS Score: 9.9) – eval injection vulnerability that allows an authenticated user to […]
From triage to threat hunting: how AI accelerates SecOps

If you work in security operations, you’ll be familiar with the concept of an AI SOC agent. Early stories promised complete autonomy. Vendors have seized on the idea of “autonomous SOCs” and proposed a future where algorithms replace analysts. That future has not yet arrived. We have never seen mass layoffs or empty security operations […]
Critical flaw in vm2 Node.js allows sandbox escape and arbitrary code execution

Ravi LakshmananJanuary 28, 2026Vulnerabilities / Open Source A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system. This vulnerability is tracked as CVE-2026-22709 and has a CVSS score of 9.8 out of 10.0 in the […]
Mustang Panda Deploys Latest COOLCLIENT Backdoor to Government Cyberattacks

In the 2025 cyber espionage attack, Chinese-linked threat actors were observed using the latest version of a backdoor called COOLCLIENT to facilitate comprehensive data theft from infected endpoints. The activity was attributed to Mustang Panda (also known as Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon), and the intrusions were primarily targeted at government agencies […]
Falsely reusing passwords: A risky and often overlooked workaround

When security teams discuss credential-related risks, they typically focus on threats like phishing, malware, and ransomware. These attack techniques continue to evolve and are gaining the attention they deserve. However, one of the most persistent and underappreciated risks to organizational security remains far more common. Reusing nearly identical passwords continues to bypass security controls and […]
Google warns of active exploitation of WinRAR vulnerability CVE-2025-8088

Ravi LakshmananJanuary 28, 2026Vulnerability/Threat Intelligence Google revealed on Tuesday that multiple threat actors, including state adversaries and financially motivated groups, are exploiting critical patched security flaws in RARLAB WinRAR to gain initial access and deploy various payloads. “Although discovered and patched in July 2025, government-sponsored and financially motivated actors associated with Russia and China continue […]
Fake Python Spellchecker package on PyPI delivers hidden remote access Trojan

Ravi LakshmananJanuary 28, 2026Supply chain security/malware Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that contain the ability to deliver a remote access trojan (RAT) while masquerading as a spell checker. The packages named Spellcheckerpy and Spellcheckpy are currently not available for download, but they were previously downloaded over […]