Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud | Cybersecurity
Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their…
Read moreResearchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software | Cybersecurity
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran’s nuclear program by destroying uranium enrichment centrifuges. According to a…
Read moreCISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline | Cybersecurity
Ravie LakshmananApr 25, 2026Network Security / Infrastructure Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X…
Read moreFIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches | Cybersecurity
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency’s Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025…
Read moreBridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine | Cybersecurity
The AI Agent Authority Gap – From Ungoverned to Delegation As discussed in our previous article, AI agents are exposing a structural gap in enterprise security, but the problem is…
Read moreMedical data of 500,000 UK volunteers listed for sale on Alibaba | Malware
Half a million Britons signed up to help cure cancer. Their data ended up for sale on Alibaba. The UK Biobank charity informed the British government of an incident concerning…
Read moreTropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2 | Cybersecurity
Ravie LakshmananApr 24, 2026Malware / Threat Intelligence Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation…
Read moreRoblox clamps down on chats and age checks as legal pressure builds | Malware
Roblox has long faced criticism over child safety on its platform. Now it has started settling with state attorneys over the issue, and the total is climbing fast. On April…
Read moreUNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware | Cybersecurity
A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts. “As with…
Read moreHow cyberattacks on companies affect everyone | Malware
If you use the internet, you’ve likely been affected by cybercrime in some way. Even when an attack is aimed at a company, the fallout usually lands on ordinary people….
Read moreBitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign | Cybersecurity
Ravie LakshmananApr 23, 2026Supply Chain Attack / Open Source Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings…
Read moreApple fixes iOS bug that kept deleted notifications, including chat previews | Malware
Apple has released a software update that deals with an issue that could allow deleted notifications to be retrieved. Something that, in at least one reported case, was used by…
Read moreApple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case | Cybersecurity
Ravie LakshmananApr 23, 2026Vulnerability / Encryption Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on…
Read moreLazarus Group Malware Targets Crypto, Business Execs via macOS | News World
Security researchers have linked a new macOS malware campaign to the Lazarus Group, the North Korea-linked hacking operation behind some of the crypto industry’s biggest thefts. Flagged on Tuesday, the…
Read moreResearcher claims Claude Desktop installs “spyware” on macOS | Malware
Security researcher Alexander Hanff wrote an article titled Anthropic secretly installs spyware when you install Claude Desktop. Claims like that are bound to create two sides, so we searched for…
Read moreMalicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain | Cybersecurity
Ravie LakshmananApr 22, 2026Cloud Security / Software Security Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository. In an alert published today, software supply…
Read moreMalicious trading website drops malware that hands your browser to attackers | Malware
During our threat hunting, we found a campaign using the same malware loader from our previous research to deliver a different threat: Needle Stealer, data-stealing malware designed to quietly harvest…
Read moreLotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack | Cybersecurity
Ravie LakshmananApr 22, 2026Malware / Critical Infrastructure Cybersecurity researchers have discovered a previously undocumented data wiper that has been used in attacks targeting Venezuela at the end of last year…
Read moreMustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles | Cybersecurity
Ravie LakshmananApr 22, 2026Cyber Espionage / Malware Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that’s distributed via a theme related to India’s banking sector….
Read moreAndroid 17 ends all-or-nothing access to your contacts | Malware
Some of the apps on your phone want your contacts. Most don’t need them all, but have been happily slurping up the lot for years. Google has decided to do…
Read more