“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs [email protected] (The Hacker News)
Cybersecurity researchers have flagged yet another evolution of the ongoing GlassWorm campaign, which employs a new Zig dropper that’s designed to stealthily infect all integrated development environments (IDEs) on a developer’s machine. The technique has been discovered in an Open VSX extension named “specstudio.code-wakatime-activity-tracker,” which masquerades as WakaTime, aRead More
-

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About [email protected] (The Hacker News)
While much of the discussion on AI security centers around protecting ‘shadow’ AI and GenAI consumption, there’s a wide-open window nobody’s guarding: AI browser extensions. A new report from LayerX exposes just how deep this blind spot goes, and why AI extensions may be the most dangerous AI threat surface in your network that isn’t on anyone’s Read More
-

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows [email protected] (The Hacker News)
Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. “This project represents a significantRead More
-

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure [email protected] (The Hacker News)
A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and includingRead More
-

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers [email protected] (The Hacker News)
Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations across…
-
RSAC 2026 Conference: Key news and industry analysis
Check out SearchSecurity’s RSAC 2026 guide for reports on notable presentations and breaking news at the world’s biggest infosec event.Read More
-

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets [email protected] (The Hacker News)
Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data,” the Microsoft DefenderRead More
-

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns [email protected] (The Hacker News)
A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and suspected universities to deploy a new Lua-based malware called LucidRook. “LucidRook is a sophisticated stager that embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download andRead More
-
Next-generation firewall buyer’s guide for CISOs
NGFWs are crucial tools for modern security operations, but CISOs need to understand the often complex deployment, maintenance and budgeting implications.Read More
-

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories [email protected] (The Hacker News)
Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d normally trust without thinking twice. Quiet escalations more than loud zero-days, but the kind that matter more…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
