ROI issues in attack surface management

Attack Surface Management (ASM) tools promise to reduce risk. What they provide is usually more information. As security teams deploy ASM, their asset inventory increases, alerts start flowing, and dashboards fill up. There are visible activities and measurable outcomes. But when leaders ask a simple question, “Will this reduce incidents?” the answer is often unclear. […]

Cybercriminals exploit Google Cloud email capabilities in multi-step phishing campaign

January 2, 2026Ravi LakshmananCloud security/email security Cybersecurity researchers have detailed a phishing campaign in which attackers exploited Google Cloud’s application integration services to distribute emails that masqueraded as legitimate messages generated by Google. According to Check Point, this activity leverages the trust associated with Google Cloud infrastructure to send messages from a legitimate email address […]

GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories

Jan 01, 2026Ravie LakshmananCybersecurity / Hacking News The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defenders anything, it’s that threat actors don’t pause for holidays or resolutions. They just evolve faster. This week’s round-up shows how […]

RondoDox botnet exploits critical flaw in React2Shell to hijack IoT devices and web servers

January 1, 2026Ravi LakshmananNetwork security/vulnerabilities Cybersecurity researchers have revealed details of an ongoing nine-month campaign targeting Internet of Things (IoT) devices and web applications to enroll them in a botnet known as RondoDox. As of December 2025, CloudSEK has observed activity leveraging the recently revealed flaw in React2Shell (CVE-2025-55182, CVSS score: 10.0) as an initial […]

How to browse faster and get more done with Adapt Browser

As web browsers evolve into general-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow down browsing sessions and cause unnecessary friction, especially for users who rely on the browser as their primary work environment. This article explains how a lightweight, task-focused browser like Adapt Browser can help […]

Trust Wallet Chrome Extension Hack Loses $8.5 Million in Shai-Hulud Supply Chain Attack

December 31, 2026Ravi LakshmananSoftware security/data breach Trust Wallet revealed on Tuesday that a second supply chain Shai Huld (also known as Sha1 Huld) outbreak in November 2025 was likely responsible for the hacking of its Google Chrome extension, ultimately resulting in approximately $8.5 million in assets being stolen. “This attack exposed the secrets of our […]

DarkSpectre browser extension campaign exposed affecting 8.8 million users worldwide

The threat actors behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, were behind a third attack campaign, codenamed DarkSpectre, that allegedly affected 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. This activity has been attributed to a Chinese threat actor and is being tracked by Koi Security under the name DarkSpectre. […]

IBM warns of critical API Connect bug that allows remote authentication bypass

December 31, 2026Ravi LakshmananAPI security/vulnerabilities IBM has detailed a critical security flaw in API Connect that could allow attackers to gain remote access to applications. This vulnerability is tracked as CVE-2025-13915 and is rated 9.8 out of a maximum of 10.0 in the CVSS scoring system. This is described as an authentication bypass flaw. “IBM […]

Researchers discover modified Shai-Hulud worm test payload on npm registry

December 31, 2026Ravi LakshmananCybersecurity/Malware Cybersecurity researchers have revealed details of what appears to be a new strain of Shai Huld on the npm registry, with some changes since the previous wave observed last month. The npm package that embeds the new Shai Hulud strain is ‘@vietmoney/react-big-calendar’ and was uploaded to npm by a user named […]

US Treasury lifts sanctions on three people involved in Intellexa and Predator spyware

December 31, 2026Ravi LakshmananSpyware/Mobile Security The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals associated with the Intellexa Consortium, the holding company for the commercial spyware known as “Predator,” from its list of Specially Designated Nationals. The names of the individuals are: Merom Harpas Andrea Nicola Constantino Hermes Gambazzi […]