Risk & Resilience

Software Developer Accidentally Gains Control Of Thousands Of DJI Robot Vacuums Exposing Security Vulnerability

A software developer accidentally accessed and controlled about 7,000 DJI Romo robot vacuums worldwide while trying to connect his own device to a PlayStation controller, exposing serious security vulnerabilities in smart home devices.

UAT-10027 Campaign Targets U.S. Education And Healthcare Sectors Using Dohdoor Backdoor

Cisco Talos tracks UAT-10027, a malicious campaign targeting U.S. education and healthcare sectors with Dohdoor backdoor using DNS over HTTPS for stealthy command-and-control.

Google Disrupts UNC2814 GRIDTIDE Campaign Targeting 53 Organizations Across 42 Countries

Google, in collaboration with industry partners, has disrupted the infrastructure of UNC2814, a suspected China-linked cyber espionage group using GRIDTIDE malware to target 53 organizations across 42 countries, supporting affected organizations and cutting off malicious access.

Lazarus Group Deploys Medusa Ransomware In Middle East And U.S. Healthcare Attacks

North Korea linked Lazarus Group has been observed using Medusa ransomware in attacks targeting a Middle Eastern entity and a U.S. healthcare organization, signaling a tactical shift toward ransomware as a service operations.

Wormable XMRig Campaign Exploits BYOVD And Time-Based Logic Bomb To Target Systems

Cybersecurity researchers uncover a wormable XMRig cryptojacking campaign using pirated software, BYOVD exploits, and time-based logic bombs to maximize mining and propagate across systems.

Microsoft 365 Copilot Bug Exposed Confidential Emails Despite DLP Policies

Microsoft confirms a bug in Microsoft 365 Copilot allowed sensitive emails with labels to be summarized in Copilot Chat, bypassing DLP controls, fixed on February 3, 2026.

Cline CLI 2.3.0 Supply Chain Attack Led To Unauthorized OpenClaw Installation On Developer Systems

A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.

Security Vulnerabilities Discovered In Live Server Code Runner And Other VS Code Extensions

Researchers disclose critical vulnerabilities in four popular Microsoft Visual Studio Code extensions that could enable file theft and remote code execution across developer environments.

Massiv Android Banking Malware Spread Through Fake IPTV Apps Warn Researchers

Researchers at ThreatFabric uncover Massiv, a new Android banking trojan spread via fake IPTV apps that enables device takeover attacks and mobile financial fraud.

Apple Tests End To End Encrypted RCS Messaging In iOS 26.4 Developer Beta

Apple introduces end to end encrypted RCS messaging in iOS 26.4 developer beta, alongside enhanced Memory Integrity Enforcement and default Stolen Device Protection features.

Microsoft Warns Of Manipulative Prompts Hidden In Summarize With AI Buttons

Microsoft researchers identify more than 50 hidden prompts embedded in Summarize with AI buttons that influence assistants to remember and recommend specific brands without user awareness.

Agentic AI Transforms Governance Risk And Compliance Beyond Task Automation

Yair Kuznitsov, CEO of Anecdotes, explains how agentic AI is reshaping Governance, Risk, and Compliance by embedding autonomous decision making into GRC workflows.

Recent articles

spot_img