“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware [email protected] (The Hacker News)
Security experts have disclosed details of an active malware campaign that’s exploiting a DLL side-loading vulnerability in a legitimate binary associated with the open-source c-ares library to bypass security controls and deliver a wide range of commodity trojans and stealers. “Attackers achieve evasion by pairing a malicious libcares-2.dll with any signed version of the legitimate…
-
Vibe coding security risks and how to mitigate them
Vibe coding with generative AI is transforming software development, accelerating innovation and introducing new security risks to manage.Read More
-

Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution [email protected] (The Hacker News)
Fortinet has released updates to fix a critical security flaw impacting FortiSIEM that could allow an unauthenticated attacker to achieve code execution on susceptible instances. The operating system (OS) injection vulnerability, tracked as CVE-2025-64155, is rated 9.4 out of 10.0 on the CVSS scoring system. “An improper neutralization of special elements used in an OS…
-

New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification [email protected] (The Hacker News)
Research analyzing 4,700 leading websites reveals that 64% of third-party applications now access sensitive data without business justification, up from 51% in 2024. Government sector malicious activity spiked from 2% to 12.9%, while 1 in 7 Education sites show active compromise. Specific offenders: Google Tag Manager (8% of violations), Shopify (5%), Facebook Pixel (4%). Download…
-

Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited [email protected] (The Hacker News)
Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild. Of the 114 flaws, eight are rated Critical, and 106 are rated Important in severity. As many as 58 vulnerabilities have been classified as privilege escalation, followed…
-

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow [email protected] (The Hacker News)
Node.js has released updates to fix what it described as a critical security issue impacting “virtually every production Node.js app” that, if successfully exploited, could trigger a denial-of-service (DoS) condition. “Node.js/V8 makes a best-effort attempt to recover from stack space exhaustion with a catchable error, which frameworks have come to rely on for service availability,”…
-

PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces [email protected] (The Hacker News)
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025. The activity has been attributed with medium confidence to a Russian hacking group tracked as Void Blizzard (aka Laundry Bear or UAC-0190). The threat actor is…
-

Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages [email protected] (The Hacker News)
Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. “Enterprise organizations that are clients of these payment providers are the most likely to be impacted,” Silent Push said in a report…
-

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that’s capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX) available in over 170 countries, while masquerading as a tool to automate trading on the platform. The extension, named MEXC API Automator (ID: pppdfgkfdemgfknfnhpkibbkabhghhfh), has 29 downloads and is stillRead…
-
Deepfake phishing is here, but many enterprises are unprepared
Deepfake phishing attacks are on the rise, as attackers use AI to deceive and defraud end users and their employers. Learn what CISOs can do to protect their organizations.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
