14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

21/08/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

21/08/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said

Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot

21/08/2026 0 Comments 0 tags

Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from

Wazuh and AI For Enhanced SOC Workflows

21/08/2026 0 Comments 0 tags

Artificial Intelligence (AI) has become one of this decade’s defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

21/08/2026 0 Comments 0 tags

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

21/08/2026 0 Comments 0 tags

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

21/08/2026 0 Comments 0 tags

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

20/08/2026 0 Comments 0 tags

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

20/08/2026 0 Comments 0 tags

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

20/08/2026 0 Comments 0 tags

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in.