“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception [email protected] (The Hacker News)
Unmasking impostors is something the art world has faced for decades, and there are valuable lessons from the works of Elmyr de Hory that can apply to the world of defensive cybersecurity. During the 1960s, de Hory gained infamy as a premier forger, passing off counterfeit masterworks of Picasso, Matisse, and Renoir to unsuspecting collectors…
-

ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories [email protected] (The Hacker News)
Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little bit of everything in this one, too. Weird delivery tricks, old problems coming back in…
-

Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks [email protected] (The Hacker News)
The kernel exploit for two security vulnerabilities used in the recently uncovered Apple iOS exploit kit known as Coruna is an updated version of the same exploit that was used in the Operation Triangulation campaign back in 2023, according to new findings from Kaspersky. “When Coruna was first reported, the public evidence wasn’t sufficient to…
-
![[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks info@thehackernews.com (The Hacker News)](https://sekuritasit.com/wp-content/uploads/2026/03/validate-itcWdw.jpg)
[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks [email protected] (The Hacker News)
Most teams have security tools in place. Alerts are firing, dashboards look clean, threat intel is flowing in. On the surface, everything feels under control. But one question usually stays unanswered: Would your defenses actually stop a real attack? That’s where things get shaky. A control exists, so it’s assumed to work. A detection rule…
-

WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites [email protected] (The Hacker News)
Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. “Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec said in a report…
-

LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace [email protected] (The Hacker News)
The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating…
-

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data [email protected] (The Hacker News)
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. “It logs keystrokes, dumps cookies and session tokens, captures screenshots, andRead More
-

The Kill Chain Is Obsolete When Your AI Agent Is the Threat [email protected] (The Hacker News)
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there’s a…
-

Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks [email protected] (The Hacker News)
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases “milan” and “okart,” is said to…
-

Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse [email protected] (The Hacker News)
Cybersecurity researchers are calling attention to an active device code phishing campaign that’s targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
