Infinity Stealer targets macOS via fake Cloudflare CAPTCHA, using Nuitka; first such campaign per Malwarebytes. Researchers at Malwarebytes spotted a new macOS infostealer, named Infinity Stealer, using a Python payload compiled with Nuitka. It spreads via ClickFix, tricking users with fake Cloudflare CAPTCHA pages. “A fake verification page instructs the visitor to open Terminal, paste…
Category: AI
AI, Europe, Exploits, Global Security News, Government & Policy, malware, Network Security, Russia
Russia-linked APT TA446 uses DarkSword exploit to target iPhone users in phishing wave
Russia-linked TA446 is using the DarkSword iOS exploit kit in targeted phishing campaigns to compromise iPhone users. Russia-linked APT group TA446 (aka SEABORGIUM, ColdRiver, Callisto, and Star Blizzard) is using the DarkSword exploit kit in targeted spear-phishing campaigns against iOS devices. The attacks rely on malicious emails to compromise iPhones, highlighting a growing threat from…
AI, Cybersecurity, Global Security News
The Art of Natural Writing: Turning AI Text into Human-Like Content
In this post, I will talk about the art of natural writing and discuss turning AI text into human-like content. Artificial intelligence has changed the way we create content, making it faster and more efficient than ever. However, one major challenge remains: AI-generated text often lacks the warmth and natural tone of human writing. This…
AI, Global Security News
SystemRescue 13 updates its kernel to Linux 6.18 LTS, adds new recovery tools
Bootable Linux recovery environments occupy a specific niche in the systems administration and incident response toolkit. SystemRescue, an Arch-based live distribution built for repairing unbootable systems and recovering data from damaged drives, has shipped version 13.00 with a new long-term supported kernel, updated storage tools, and several additions to its command-line toolset. Kernel and storage…
AI, china, Global Security News, Government & Policy, malware
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a “complex and well-resourced operation.” The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL
AI, Data Breaches, Europe, Global Security News
European Commission confirms data breach after Europa.eu hack
The European Commission has confirmed a data breach after its Europa.eu web platform was hacked in a cyberattack claimed by the ShinyHunters extortion gang. […]
AI, Global Security News, Risk Management
Why risk alone doesn’t get you to yes
I have been in security rooms for years, from military operations centers to corporate boardrooms. In all those years I can tell you that the hardest mission that most security leaders will face is not identifying a threat, but getting someone to act on it. We’re trained to see exposure before they are identified by…
AI, Global Security News
ShipSec Studio brings open-source workflow orchestration to security operations
Security teams have long relied on a mix of shell scripts, cron jobs, and loosely connected tools to chain reconnaissance and vulnerability scanning work together. ShipSec Studio, an open-source security workflow automation platform from ShipSec AI, aims to replace that arrangement with a dedicated orchestration layer built specifically for security operations. What the platform does…
AI, Global Security News
Breaking out: Can AI agents escape their sandboxes?
Container sandboxes are part of routine AI agent testing and deployment. Agents use them to run code, edit files, and interact with system resources without direct access to the host. The SandboxEscapeBench benchmark, developed by researchers at the University of Oxford and the AI Security Institute, evaluates whether an agent with shell access can escape…
AI, Cybersecurity, Data Breaches, Global Security News, Government & Policy
Don’t count on government guidance after a smart home breach
People are filling their homes with internet-connected cameras, speakers, locks, and routers. When one of those devices is compromised, the next steps are often unclear. Researchers reviewing government cybersecurity advice in 11 countries found that most guidance focuses on prevention, leaving households with limited support after a breach. The analysis covers Australia, Austria, Canada, Finland,…
AI, Global Security News
The Sudden Fall of OpenAI’s Most Hyped Product Since ChatGPT
Sam Altman hoped Sora would turn OpenAI into a creative pioneer. Instead, it looks like an expensive strategic miscalculation.
AI, Global Security News
DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
A lot of the information seen on DShield honeypots [1] is repeated bot traffic, especially when looking at the Cowrie [2] telnet and SSH sessions. However, how long a session lasts, how many commands are run per session and what the last commands run before a session disconnects can vary. Some of this information could help…
AI, Global Security News
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM
Moving beyond their LiteLLM campaign, TeamPCP weaponizes the Telnyx Python SDK with stealthy WAV‑based payloads to steal credentials across Linux, macOS, and Windows.
AI, Global Security News
Incident responders, s’il vous plait: Invites lead to odd malware events
A phishing campaign targeting multiple organizations led to RMM installations – but not much else (yet). A threat actor experimenting, or an access-as-a-service attack underway? Categories: Threat Research Tags: STAC6405, infostealer, RMM, Phishing
AI, Global Security News
iTWire TV: NiCE Bets Big on Australia as Agentic AI Rewires the Contact Centre
GUEST INTERVIEW: NiCE’s new ANZ boss says the days of pressing zero and repeating “operator” are numbered, and a US$955 million acquisition is the reason why.
AI, Data Breaches, Global Security News
FBI confirms hack of Director Patel’s personal email inbox
The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents. […]
AI, Global Security News
NiCE Bets Big on Australia as Agentic AI Rewires the Contact Centre
GUEST INTERVIEW: NiCE’s new ANZ boss says the days of pressing zero and repeating “operator” are numbered, and a US$955 million acquisition is the reason why.
AI, Apps, Data Breaches, Endpoint, Exploits, Global Security News, malware, Network Security
Hackers Didn’t Hack the FBI Network — They Did Something Smarter
A threat operation attributed to actors aligned with Iran’s Ministry of Intelligence and Security (MOIS) has compromised the personal email account of FBI Director Kash Patel, exposing historical communications and personal data in a campaign that blends espionage, disruption, and information operations. The activity is being conducted under the “Handala Hack Team” persona, which serves…
AI, Global Security News
Real-time Analytics News for the Week Ending March 28
In this week’s real-time analytics news: Oracle announced new agentic AI features for Oracle AI Database. The post Real-time Analytics News for the Week Ending March 28 appeared first on RTInsights.
AI, Global Security News
The Cricut Explore 5 brings faster, smarter cutting
Cricut, the masters of cutting machines to make your art and craft dreams come to life, recently released the new Cricut Explore 5. It’s the latest evolution in Cricut’s mid-range cutting machine lineup, aimed at hobbyists and small creators who want speed, precision and ease of use without stepping up to the more expensive Maker series.…
AI, Global Security News
Silicon Valley Has Stopped Talking Politics—Except for This Google Executive
AI pioneer Jeff Dean is a rare tech leader who has been publicly criticizing actions by the Trump administration.
AI, Global Security News
AVEVA pushes ‘data to dollars’ message as AI reshapes oil, gas, and LNG operations
Industrial software firm AVEVA is doubling down on its “data to dollars” strategy, arguing that better data governance and AI-driven operational models can simultaneously boost production, cut costs, and reduce emissions across oil, gas and LNG operations.
AI, Global Security News
Acromove partners with Wavelink to bring cost-effective portable edge-cloud and 5G to ANZ, powering AI and critical infrastructure
Acromove, a deep-tech company specialising in portable edge-cloud infrastructure and private 5G, today announced it has appointed Wavelink as its distributor across Australia and New Zealand (ANZ). The partnership will bring Acromove’s portable edge-cloud units to the channel, enabling organisations to run AI inference and mission-critical workloads closer to the point of action. Many of the…
AI, Global Security News
Agent Computers: the PC era, amplified
For 40 years, the personal computer has been the most important tool in human hands. You sat down, opened your apps, and got to work. You wrote, built, designed, analyzed, edited, explored, and created. The machine worked for you. It was personal. It was powerful. It extended individual capabilities in a way nothing else had.…
AI, Global Security News
Baidam Appoints Anita Sheridan-Roddick As Chief Revenue Officer To Champion Growth
COMPANY ANNOUNCEMENT: Hot on the heels of being named CEO of Baidam, Australia’s leading First Nations information technology provider, Beau Hodge has appointed Anita Sheridan-Roddick (formerly National Sales Director) as Chief Revenue Officer (CRO).
AI, Global Security News, Risk Management
Decoding AI Coding “Personalities” Critical to Managing Development Risk
GUEST OPINION: As generative AI cements its place in enterprise software development, a familiar discipline is taking on new urgency: risk management.
AI, Cybersecurity, Exploits, Global Security News, Network Security
Urgent Alert: NetScaler bug CVE-2026-3055 probed by attackers could leak sensitive data
Attackers are actively probing a critical Citrix NetScaler flaw (CVE-2026-3055) that can leak sensitive data via a memory overread issue. A critical vulnerability, tracked as CVE-2026-3055 (CVSS score of 9.3), in Citrix NetScaler ADC and Gateway is already being actively probed by attackers. This week, Citrix issued security updates for two NetScaler vulnerabilities, including the critical memory…
AI, Global Security News
Meta the Defendant
Plus, Apple’s autocorrect fix, Sora’s untimely demise, Nvidia’s iron grip on the AI industry and the 10-year feud shaping AI’s future.
AI, Exploits, Global Security News, Government & Policy, malware, Network Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 90
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape New Malware Targets Users of Cobra DocGuard Software Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets Trivy Supply Chain Attack Expands to Compromised Docker Images VoidStealer: Debugging Chrome to Steal…
AI, Compliance, Global Security News
SAP Concur showcases new AI, integrated travel and expense enhancements, and global partnerships at SAP Concur Fusion 2026
COMPANY NEWS: SAP Concur is accelerating the future of travel and expense management with a new wave of AI-powered innovations, expanded global partnerships, and enhanced capabilities unveiled at SAP Concur Fusion 2026. The announcements highlight SAP’s focus on automating workflows, strengthening compliance, and improving employee experiences.
AI, Global Security News
Everyone Hates iPhone Autocorrect. An Update Fixes One of the Biggest Problems.
Here’s what iOS 26.4 does to improve your typing, plus some tips to help you reclaim your keyboard.
AI, Apps, china, Cybersecurity, Data Breaches, Europe, Exploits, Global Security News, Government & Policy, malware, Network Security, Risk Management, Russia
Security Affairs newsletter Round 569 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. ShinyHunters claims the hack of the European Commission Iran-linked group Handala hacked FBI Director Kash Patel’s…
AI, Global Security News, Network Security
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packages
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: NIST updates its DNS security guidance for the first time in over a decade DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more…
AI, Exploits, Global Security News, Risk Management
Apple issues urgent lock screen warnings for unpatched iPhones and iPads
Apple is alerting users of outdated iPhones and iPads via lock screen warnings about active web-based exploits, urging immediate software updates. Apple is sending lock screen alerts to users running outdated iOS and iPadOS versions, warning of active web-based attacks targeting their devices. The notifications urge users to install critical updates to stay protected, highlighting…
AI, Cybersecurity, Global Security News, Government & Policy
From Paper to Digital: The Benefits of Making Taxes Digital (MTD)
In this post, I will talk about the benefits of making taxes digital (MTD). A lot of things have expanded from being solely on physical paper to being in digital format. Books are an example. Now, the income tax process in the UK, for certain individuals and businesses. With Making Tax Digital (MTD), the government is…
AI, Data Breaches, Europe, Global Security News
ShinyHunters Claims 350GB Data Breach at European Commission
ShinyHunters claims it breached European Commission systems, leaking 350GB of data. Officials are investigating, with no independent verification yet.
AI, Global Security News
The People Who Are Using AI at Home to Free Up Their Time
Using AI agents to compare insurance plans and order groceries means more free time for riding bikes and playing the guitar.
AI, Cybersecurity, Data Breaches, Europe, Global Security News
ShinyHunters claims the hack of the European Commission
The European Commission has allegedly been breached by ShinyHunters, with reported data dumps including content from mail servers. The European Commission has allegedly been breached by ShinyHunters, with reported data dumps including content from mail servers and internal communications systems. The cybercrime group added the Commission to its Tor data leak site, claiming the theft…
AI, Data Breaches, Global Security News
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation (FBI), and leaked a cache of photos and other documents to the internet. Handala Hack Team, which carried out the breach, said on its website that Patel “will now find…
AI, Cloud Security, Compliance, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, Risk Management
TeamPCP Supply Chain Campaign: Update 003 – Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
This is the third update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 002 covered developments through March 27, including the Telnyx PyPI compromise and Vect ransomware partnership. This update covers developments from March 27-28, 2026. HIGH: First 48-Hour Window Without a New Supply…
AI, Global Security News
Why the real bottleneck in enterprise AI isn’t GPUs – it’s data
For the past two years, the conversation around enterprise AI has been dominated by GPUs: who has them; who can buy them; who is waiting months for them. But a new wave of announcements at NVIDIA’s recent annual AI conference suggests something more subtle is happening inside enterprise data centres. While the GPU shortage grabbed…
AI, Global Security News
6Q4:How AI Is Moving from Promise to Practice
A look beyond the artificial intelligence hype: What will it take for real value to start showing up as companies implement AI? The post 6Q4:How AI Is Moving from Promise to Practice appeared first on RTInsights.
AI, Data Breaches, Europe, Global Security News, Government & Policy, malware, Risk Management
Iran-linked group Handala hacked FBI Director Kash Patel’s personal email account
Iran-linked group Handala claims it hacked FBI Director Kash Patel’s personal email, leaking files. The FBI says no government data was exposed. Iran-linked hacking group Handala claims it breached FBI Director Kash Patel’s personal Gmail account and shared alleged data, including photos and files. The FBI confirmed it is aware of the incident and has…
AI, Exploits, Global Security News
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
A recently disclosed critical security flaw impacting Citrix NetScaler ADC and NetScaler Gateway is witnessing active reconnaissance activity, according to Defused Cyber and watchTowr. The vulnerability, CVE-2026-3055 (CVSS score: 9.3), refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
U.S. CISA adds a flaw in F5 BIG-IP AMP to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in F5 BIG-IP AMP to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in F5 BIG-IP AMP, tracked as CVE-2025-53521 (CVSS ver. 3.1 score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability in BIG-IP APM allows…
AI, Cybersecurity, Exploits, Global Security News, Russia
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community…
AI, Data Breaches, Global Security News
Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail
Iran-linked Handala hackers breached FBI Chief Kash Patel’s Gmail, leaking photos and documents. Officials say no classified data was exposed.
AI, Global Security News
The Decadelong Feud Shaping the Future of AI
Unhealed personal wounds and past power struggles between the leaders of OpenAI and Anthropic are defining how the world now encounters the technology.
AI, Global Security News
The Playbook That Elon Musk Relies On to Make His Wild Ideas Work
Musk’s five-step algorithm gets Tesla and SpaceX employees to achieve stretch goals and innovate, and it’s sure to come in handy in his push to build the world’s largest AI chip factory.
AI, Apps, Compliance, Data Breaches, Endpoint, Exploits, Global Security News, malware, Risk Management
A critical Windows security fix puts legacy hardware on borrowed time
Microsoft is finally blocking a long-since retired program that it said led to “abuse and credential theft,” yet remained widely trusted for years. Beginning in April, Redmond will remove trust for kernel drivers that haven’t been vetted through its Windows Hardware Compatibility Program (WHCP). The company is specifically targeting kernel drivers signed by the now…
AI, Data Breaches, Global Security News
ShinyHunters Walk Away from BreachForums, Leak 300,000-User Database
ShinyHunters leaves BreachForums, leaks data of 300,000 users, warns all active domains are fake, and threatens more leaks from forum backups.
AI, Apps, Cybersecurity, Exploits, Global Security News, Government & Policy, malware, Network Security, Risk Management
RSAC 2026: No easy fixes for expanding AI attack surface, but a coordinated response is emerging
SAN FRANCISCO — Forty-four thousand cybersecurity practitioners converged on Moscone Center this week with an urgent question: how do you secure a network when everything — the technology, the threats, the tools — is changing faster than anyone can govern it? Related: Feds pull back on collaboration Microsoft’s Vasu Jakkal set the scale on day…
AI, Cybersecurity, Data Breaches, Europe, Global Security News, Network Security
The European Commission confirmed a cyberattack affecting part of its cloud systems
The European Commission confirmed a cyberattack affecting part of its cloud systems, now contained, with no impact on internal networks. On March 24, the European Commission detected a cyberattack affecting the cloud infrastructure hosting its Europa.eu websites. The incident was quickly contained, with mitigation measures applied and no disruption to website availability. Early findings suggest…
AI, Apps, Cybersecurity, Data Breaches, Global Security News, malware, Network Security, Risk Management
LiteLLM Supply Chain Attack Exposes Credentials Across AI Ecosystems
A widely used AI development library was compromised in a recent supply chain attack, potentially exposing a large number of systems to risk. Malicious LiteLLM packages on PyPI were backdoored to quietly steal credentials, tokens, and sensitive infrastructure data from both development and production environments. “The LiteLLM compromise shows just how quickly supply chain attacks…
AI, Apps, Cloud Security, Cybersecurity, Data Breaches, Europe, Global Security News, Risk Management
European Commission data stolen in a cyberattack on the infrastructure hosting its web sites
The European Commission is continuing to investigate the theft of data from its cloud infrastructure earlier this week. On Thursday, the Commission revealed there had been an attack on its Europa.eu platform, offering few details, then, on Friday, security news site Bleeping Computer reported that the attack had involved the compromise of an account or…
AI, APAC, Apps, Compliance, Global Security News, Network Security
Nutanix Debuts New Agentic AI Solution
Nutanix, a hybrid multicloud computing company, recently launched a new agentic AI solution to help customers boost agentic AI adoption for business transformation. Nutanix brings AI factory enablement stack to market The full software stack, Nutanix Agentic AI, is designed to help infrastructure and platform teams build and operate AI factories, while providing shared access…
AI, Cybersecurity, Global Security News, Network Security, Risk Management
RSAC 2026: Sonar Shares Why Code Security Must Shift Before CI
At RSAC 2026, I sat down with Jeremy Katz, VP of Code Security at Sonar, and one theme came through clearly: the way we secure code has to change — fast. As development shifts toward AI-assisted and agent-driven workflows, traditional checkpoints in CI/CD are no longer enough to catch risk early. Katz pointed out that…
AI, Data Breaches, Global Security News, Government & Policy, Network Security, Risk Management
Iranian hackers, Handala, claim to compromise FBI Director Kash Patel’s personal data
Iranian hackers claimed Friday to have compromised the personal data of FBI Director Kash Patel, and the bureau confirmed that it knew of the targeting of Patel’s personal email. The government-connected hacking group, Handala, previously claimed credit for hacking medical device maker Stryker, a boast that threat researchers considered credible. “All personal and confidential email…
AI, Global Security News
Optimizing Order Sourcing for Markdown Avoidance Through the Agentic Shift
AI agents are transforming Order Management Systems (OMS) from a static rules-based engine to a dynamic intelligence-based strategist. The post Optimizing Order Sourcing for Markdown Avoidance Through the Agentic Shift appeared first on RTInsights.
AI, Apps, Global Security News, privacy
Lloyds Bank reveals how IT bug exposed transaction data
Lloyds Banking Group has identified the glitch that led to some of its customers being able to see details of other customers’ transactions on March 12. It revealed the information in a letter to the UK Parliament’s Treasury Committee, setting out the details of the incident and how it has been handled. The issue arose…
AI, APAC, Apps, Compliance, Cybersecurity, Endpoint, Exploits, Global Security News, Government & Policy, Network Security, Risk Management, Russia
Security leaders say the next two years are going to be ‘insane’
SAN FRANCISCO — Every RSA Conference has its buzzwords. Cloud. Ransomware. Zero trust. Plastered across the 87-acre Moscone Center complex on every booth, banner and bar. This year was AI, with vendors pitching AI-powered solutions to every security problem imaginable. But 2026 stood out for a different reason: Industry leaders spent the conference warning about…
AI, Global Security News, Risk Management
AI threatens jobs that can be ‘unbundled’
There have been plenty of warnings about job losses due to AI, particularly in the world of IT and in the reduction of entry-level positions. Doom mongers’ claims that AI is going to eradicate all our jobs look to be exaggerated but there is little room for complacency as there are some roles most definitely…
AI, Global Security News
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
TeamPCP, the threat actor behind the supply chain attack targeting Trivy, KICS, and litellm, has now compromised the telnyx Python package by pushing two malicious versions to steal sensitive data. The two versions, 4.87.1 and 4.87.2, published to the Python Package Index (PyPI) repository on March 27, 2026, concealed their credential harvesting capabilities within a…
AI, Global Security News, malware
Fake VS Code alerts on GitHub spread malware to developers
A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section of various projects, to trick users into downloading malware. […]
AI, Compliance, Global Security News, Risk Management
Delve Compliance Scandal Exposes AI Vendor Risk Gaps
Allegations against AI compliance startup Delve are raising urgent questions about how enterprises vet vendors in the race to adopt automation. As scrutiny grows, the controversy underscores a broader issue: many AI tools marketed as “enterprise-ready” may lack the safeguards, validation, and transparency buyers assume are in place. Compliance platform Delve faces allegations of fabricated…
AI, Apps, Global Security News
One-third of help-desk tickets stop work, says study
Nearly one-third of all help-desk tickets handled by large organizations are work-stoppers, according to a study from help-desk automation company Fixify, which also found Tuesday to be the busiest day of the week for help desks. “Monday gets the reputation, but Tuesday gets the tickets,” it the study said. Around one in eight of the…
AI, Global Security News
New Wave of AiTM Phishing Targets TikTok for Business
Push Security has uncovered a new AiTM phishing campaign targeting TikTok for Business accounts using Google and TikTok themed login pages
AI, Global Security News
The Quest to Revive a Frozen Brain
Plus, one journalist is going all in on AI and crypto-backed mortgages are entering the mainstream.
AI, Global Security News
BianLian Ransomware Spreads via Fake Invoice SVG Images in New Attacks
Researchers at WatchGuard have identified a new phishing campaign targeting companies in Venezuela. Using malicious SVG image files…
AI, Global Security News, malware
New AITM phishing wave hijacks TikTok Business accounts
A new AITM phishing campaign targets TikTok Business accounts to hijack them for malvertising, continuing tactics seen in earlier Google-themed scams. Push Security researchers uncovered a new wave of AITM phishing pages targeting TikTok for Business accounts, aiming to hijack them for malvertising. The campaign includes TikTok and Google-themed fake pages, showing links to previous…
AI, Global Security News, malware
TeamPCP Targets Telnyx Package in Latest PyPI Software Supply Chain Attack
Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
CISA and BSI warn orgs of critical PTC Windchill and FlexPLM flaw
CISA warns of a critical flaw in PTC Windchill and FlexPLM (CVE-2026-4681), with no patch yet and potential for imminent exploitation. CISA issued an advisory about a critical vulnerability, tracked as CVE-2026-4681 (CVSS score of 10.0), in PTC’s Windchill and FlexPLM software. At this time, no patches are available, and no active attacks have been…
AI, Exploits, Global Security News, Russia
Wartime Usage of Compromised IP Cameras Highlight Their Danger
The list of countries exploiting internet-connected cameras to give them eye’s inside their adversaries’ borders continues to expand, with Russia, Iran, Israel, Ukraine, and the United States all using the tactic. What should companies look out for?
AI, Apps, Compliance, Data Breaches, Exploits, Global Security News, malware, Network Security, Risk Management
TeamPCP Supply Chain Campaign: Update 002 – Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
This is the second update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 001 covered developments through March 26. This update covers developments from March 26-27, 2026. CRITICAL: Telnyx Python SDK Compromised on PyPI — New WAV Steganography TTP TeamPCP compromised the telnyx Python SDK (670,000+…
AI, Apps, Cloud Security, Global Security News, Network Security, Risk Management
RSAC 2026: How Zscaler Is Securing the AI Ecosystem
At RSAC 2026, I sat down with Adam Geller, Chief Product Officer at Zscaler, to talk about one of the biggest challenges facing security teams right now: how to secure AI without slowing it down. What struck me was how differently Zscaler is approaching the problem compared to many others in the space. Rethinking AI…
AI, Global Security News, Risk Management
Agentic GRC: Teams Get the Tech. The Mindset Shift Is What’s Missing.
Agentic GRC automates workflows, forcing teams to rethink their role beyond operations. Anecdotes explains why the biggest challenge is shifting from execution to risk leadership. […]
AI, Apps, Compliance, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, Risk Management, Russia
Critical Vulnerabilities, Insider Threats, and AI-Driven Cybercrime Define the Week
Major Threats & Vulnerabilities Zero-Day and Critical CVE Exploits Oracle’s emergency patch for CVE-2026-21992 addressed a critical remote code execution flaw in Identity Manager and Web Services Manager with a CVSS score of 9.8. The vulnerability could allow unauthenticated attackers to fully compromise systems. Administrators are urged to patch immediately despite no known active exploitation.…
AI, Cybersecurity, Global Security News
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX’s pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry. “The pipeline had a single boolean return value that meant both ‘no scanners are…
AI, Global Security News, malware
TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware
TeamPCP continues is supply chain compromise rampage, with telnyx on PyPI being the latest maliciously modified package. What happened? Telnyx is a widely used software development kit (SDK) for the Telnyx AI Voice Agent service. According to Endor Labs researchers, attackers backdoored the legitimate SDK code and published versions 4.87.1 and 4.87.2 of the package…
AI, Data Breaches, Europe, Global Security News
European Commission investigating breach after Amazon cloud hack
The European Commission, the European Union’s main executive body, is investigating a security breach after a threat actor gained access to its Amazon cloud infrastructure. […]
AI, Apps, Cybersecurity, Endpoint, Exploits, Global Security News
Attackers exploit critical Langflow RCE within hours as CISA sounds alarm
Attackers have exploited a critical Langflow RCE within hours of disclosure, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to formally flag it for urgent remediation. The flaw, which allows running arbitrary code on vulnerable Langflow instances without >credentials, was weaponized within 20 hours of the open-source AI-pipeline tool disclosing it. According to a Sysdig report,…
AI, Global Security News, malware
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. “TikTok has been historically…
AI, Compliance, Cybersecurity, Global Security News, Government & Policy, Risk Management
AI regulations are already out of date — IT leaders need to think ahead
Most AI regulations passed in the last few years are already irrelevant, but enterprises should think ahead with rudimentary governance plans for quicker compliance, said legal experts in two panel discussions at Nvidia’s GTC trade show last week. Current AI regulations target frontier models, high-risk models, and transparency. They typically focus on LLMs and the…
AI, Global Security News
Cyberangriff auf die Linke
Die Hackergruppe “Qilin” steht möglicherweise hinter dem Angriff. Studio-M – shutterstock.com Die Linke ist nach eigenen Angaben Opfer einer schweren Cyberattacke geworden und vermutet dahinter russischsprachige Hacker. Man habe am Donnerstag sofort reagiert und Teile der IT-Infrastruktur vom Netz genommen, teilte Bundesgeschäftsführer Janis Ehling mit. «Nach derzeitigen Erkenntnissen zielen die Täter darauf ab, sensible Daten…
AI, Cybersecurity, Exploits, Global Security News, Network Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner. Their addition to the catalog…
AI, Global Security News
Anti-piracy coalition takes down AnimePlay app with 5 million users
The Alliance for Creativity and Entertainment (ACE) announced the shutdown of AnimePlay, a major anime streaming platform with over 5 million users. […]
AI, Global Security News, Risk Management
RSAC 2026 wrap-up – Week in security with Tony Anscombe
This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with
AI, Apps, Compliance, Global Security News, Government & Policy, Risk Management
Anthropic wins reprieve against US DoD ban, buying time for contractors to assess AI supply chains
The Pentagon’s attempt to brand Anthropic a supply chain risk was “likely both contrary to law and arbitrary and capricious,” a US federal judge wrote in a ruling halting a ban on use of Anthropic’s products in defense contracts. In granting Anthropic a preliminary injunction against the ban, US District Judge Rita Lin of the…
AI, Data Breaches, Exploits, Global Security News
Ajax data breach exposed season tickets, supporter bans open to tampering
AFC Ajax, the Dutch football club from Amsterdam, disclosed that an unknown hacker gained access to parts of its IT systems and obtained the email addresses of a few hundred people. The hack exploited vulnerabilities in Ajax’s app and website, including exposed APIs and shared access keys. The club stated that names, email addresses, and…
AI, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Aquasecurity Trivy flaw, tracked as CVE-2026-33634 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. On March 19, 2026, attackers used compromised credentials to release a malicious…
AI, Global Security News, Russia
Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware
A pro-Ukrainian group called Bearlyfy has been attributed to more than 70 cyber attacks targeting Russian companies since it first surfaced in the threat landscape in January 2025, with recent attacks leveraging a custom Windows ransomware strain codenamed GenieLocker. “Bearlyfy (also known as Labubu) operates as a dual-purpose group aimed at inflicting maximum damage upon…
AI, Compliance, Global Security News, Risk Management
8 steps CISOs can take to empower their teams
Many leaders know empowered teams deliver better results, but not all leaders understand how to get there. It all starts with knowing what empowerment truly means. Put simply: Empowerment is the absence of micromanagement. Empowerment provides the foundation for people to develop autonomy; to take action, responsibility, and accountability; and to have the room necessary…
AI, Apps, china, Global Security News
The ‘AI slop’ backlash kills Sora
OpenAI just killed Sora. That’s an amazing development. When the company rolled out the video-creation site, and later the app, reviewers called it a trailblazer because it combined video creations with sound effects, spoken dialog, and the ability for users to generate a specific character using a reference image and reuse them in multiple videos…
AI, Global Security News, malware, privacy, Risk Management
Don’t sleep on this powerful new Chrome security booster
When it comes to staying safe online, the teensiest shred of common sense goes an impressively long way. That’s absolutely true on Android, as I’ve been preaching for more years than I can even remember at this point — and it’s true on the web, too, especially when you’re working within the desktop browser you…
AI, Apps, Cybersecurity, Exploits, Global Security News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Cybersecurity researchers have disclosed three security vulnerabilities impacting LangChain and LangGraph that, if successfully exploited, could expose filesystem data, environment secrets, and conversation history. Both LangChain and LangGraph are open-source frameworks that are used to build applications powered by Large Language Models (LLMs). LangGraph is built on the foundations of
AI, Global Security News
A cunning predator: How Silver Fox preys on Japanese firms this tax season
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them
AI, Apps, china, Exploits, Global Security News, Government & Policy, malware, Network Security
China-linked Red Menshen APT deploys stealthy BPFDoor implants in telecom networks
China-linked Red Menshen APT group used stealthy BPFDoor implants in telecom networks to spy on government targets. Rapid7 Labs uncovered a China-linked threat group known as Red Menshen has been running a long-term espionage campaign by infiltrating telecom networks, mainly in the Middle East and Asia. Active since at least 2021, the group uses highly…
AI, Global Security News, Risk Management
AI frenzy feeds credential chaos, secrets spread through code, tools, and infrastructure
Code keeps moving through pipelines, and credentials continue to surface alongside it. GitGuardian’s State of Secrets Sprawl 2026 puts the count at 28.65 million new hardcoded secrets in public GitHub commits in 2025, extending a multi-year rise in exposed access keys, tokens, and passwords. Public and internal repositories that contain at least one secret (Source:…
AI, Apps, Compliance, Cybersecurity, Europe, Global Security News, privacy, Risk Management
European Parliament delays implementation of parts of the EU AI Act
The European Parliament’s Thursday vote to delay parts of the EU AI Act adds more uncertainty to the already chaotic AI compliance universe. But analysts say that CIOs must proceed as though the compliance rules are in effect. In a statement, Parliament said that its members decided to “delay the application of certain rules on…
AI, Compliance, Global Security News, Network Security
Google: The quantum apocalypse is coming sooner than we thought
Google isn’t just responsible for the encryption of a big chunk of the communications on the internet. It is also building its own quantum computers, so it’s well placed to evaluate how close the technology is to fruition. Until now, the company has been aligned with the NIST timeline, which specifies 2030 for deprecating quantum-unsafe…
