Risk & Resilience

Anthropic AI Discovers 22 Security Vulnerabilities In Mozilla Firefox Using Claude Opus 4.6

Anthropic identifies 22 security vulnerabilities in Mozilla Firefox using its Claude Opus 4.6 AI model during a security collaboration with Mozilla, with most issues fixed in Firefox 148.

Transparent Tribe Uses AI To Mass Produce Malware In Campaign Targeting Government Entities

Transparent Tribe, also known as APT36, is using AI assisted coding tools to generate large volumes of malware implants targeting government organizations and diplomatic missions, according to Bitdefender research.

China Linked Hackers Target South American Telecom Infrastructure Using TernDoor PeerTime And BruteEntry

Cisco Talos reports China linked UAT-9244 APT actor using TernDoor, PeerTime, and BruteEntry implants to compromise Windows, Linux, and edge devices in South American telecom networks.

Microsoft Uncovers ClickFix Campaign Using Windows Terminal To Deploy Lumma Stealer Malware

Microsoft reports a ClickFix social engineering campaign abusing Windows Terminal to execute malicious commands and deploy Lumma Stealer targeting browser credentials.

AI Driven SOC Investigations Show Deeper Threat Detection Beyond Alert Triage

Real world investigations show how AI powered SOC platforms can conduct multi source threat analysis, helping security teams detect credential compromise and advanced phishing attacks faster.

Malicious Laravel Packages On Packagist Deploy Cross Platform Remote Access Trojan

Security researchers discovered malicious Laravel related packages on Packagist that deploy a cross platform remote access trojan affecting Windows, macOS, and Linux systems.

Europol Led Operation Dismantles Tycoon 2FA Phishing Service Linked To 64,000 Attacks

Europol and cybersecurity partners dismantled Tycoon 2FA, a phishing as a service toolkit tied to more than 64,000 attacks and nearly 100,000 affected organizations worldwide.

Google Confirms CVE 2026 21385 In Qualcomm Android Component Under Active Exploitation

Google confirms active exploitation of CVE 2026 21385, a high severity Qualcomm graphics component flaw, as part of Android March 2026 security updates addressing 129 vulnerabilities.

China Linked Amaranth Dragon Exploits WinRAR Flaw In Southeast Asia Espionage Campaigns

China linked Amaranth Dragon exploited a WinRAR vulnerability in targeted espionage campaigns across Southeast Asia, with overlaps tied to APT41 and parallel PlugX operations by Mustang Panda.

Malicious Go Crypto Module Steals Passwords And Deploys Rekoobe Backdoor On Linux Systems

Researchers uncover a malicious Go module impersonating golang.org/x/crypto that steals terminal passwords, installs SSH persistence, and deploys the Rekoobe Linux backdoor.

Thousands Of Public Google Cloud API Keys Exposed With Gemini Access After API Enablement

Researchers have uncovered nearly 3,000 publicly exposed Google Cloud API keys that gained unintended access to Gemini endpoints after API enablement, raising concerns over data exposure and unexpected billing charges.

Software Developer Accidentally Gains Control Of Thousands Of DJI Robot Vacuums Exposing Security Vulnerability

A software developer accidentally accessed and controlled about 7,000 DJI Romo robot vacuums worldwide while trying to connect his own device to a PlayStation controller, exposing serious security vulnerabilities in smart home devices.

Recent articles

spot_img