Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux

04/03/2026 0 Comments 0 tags

Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that’s functional on Windows, macOS, and

APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2

04/03/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of an advanced persistent threat (APT) group dubbed Silver Dragon that has been linked to cyber attacks targeting entities in Europe and Southeast Asia since

CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog

04/03/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw impacting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog, citing active

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

03/03/2026 0 Comments 0 tags

Threat hunters have called attention to a new campaign as part of which bad actors masqueraded as fake IT support to deliver the Havoc command-and-control (C2) framework as a precursor

Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries

03/03/2026 0 Comments 0 tags

The threat actor behind the recently disclosed artificial intelligence (AI)-assisted campaign targeting Fortinet FortiGate appliances leveraged an open-source, AI-native security testing platform called CyberStrikeAI to execute the attacks. The new

Building a High-Impact Tier 1: The 3 Steps CISOs Must Follow

03/03/2026 0 Comments 0 tags

Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

03/03/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new phishing suite called Starkiller that proxies legitimate login pages to bypass multi-factor authentication (MFA) protections. It’s advertised as a cybercrime platform by

AI Agents: The Next Wave Identity Dark Matter – Powerful, Invisible, and Unmanaged

03/03/2026 0 Comments 0 tags

The Rise of MCPs in the Enterprise The Model Context Protocol (MCP) is quickly becoming a practical way to push LLMs from “chat” into real work. By providing structured access

Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets

03/03/2026 0 Comments 0 tags

Microsoft on Monday warned of phishing campaigns that employ phishing emails and OAuth URL redirection mechanisms to bypass conventional phishing defenses implemented in email and browsers. The activity, the company

SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware Chains

03/03/2026 0 Comments 0 tags

The threat activity cluster known as SloppyLemming has been attributed to a fresh set of attacks targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. The activity, per