The threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian governmental, academic, and strategic entities with a remote access trojan (RAT) that grants …
Homepage-Fragments
Friday Squid Blogging: Squid Found in Light Fixture Probably a college prank . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog …
Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, alerts start flowing, and dashboards fill …
Flock Exposes Its AI-Enabled Surveillance Cameras 404 Media has the story : Unlike many of Flock’s cameras, which are designed to capture license plates as people drive by, Flock’s Condor cameras are …
** Jan 02, 2026 ** Ravie Lakshmanan Cloud Security / Email Security Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate …
TV producer Keaton Stone became ‘accidental journalist’ with Al Fayed investigation
Keaton Stone speaks while picking up the Investigation of the Year prize at the British Journalism Awards 2025 for Al Fayed: Predator at Harrods. He’s between executive producer Mike Radford and …
As web browsers evolve into all-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow down browsing sessions …
ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories
** Jan 01, 2026 ** Ravie Lakshmanan Cybersecurity / Hacking News The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past …
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers
** Jan 01, 2026 ** Ravie Lakshmanan Network Security / Vulnerability Cybersecurity researchers have disclosed details of a persistent nine-month-long campaign that has targeted Internet of Things …
** Dec 31, 2026 ** Ravie Lakshmanan Software Security / Data Breach Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 …
** Dec 31, 2026 ** Ravie Lakshmanan Cybersecurity / Malware Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight …
** Dec 31, 2026 ** Ravie Lakshmanan API Security / Vulnerability IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the …
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster , has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users …
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
** Dec 31, 2026 ** Ravie Lakshmanan Spyware / Mobile Security The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the …
LinkedIn Job Scams Interesting article on the variety of LinkedIn job scams around the world: In India, tech jobs are used as bait because the industry employs millions of people and offers …
Trump files lawsuit against BBC over ‘deceptive, disparaging, inflammatory’ editing
Donald Trump. Picture: Shutterstock US President Donald Trump has filed a defamation lawsuit against the BBC seeking up to $10bn (£7.5bn) in response to the editing of a speech he made before the …
** Dec 30, 2026 ** Ravie Lakshmanan Vulnerability / Email Security The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools …
A person pulls a copy of The Daily Telegraph out from a newsstand in Paris, France in March 2017. Picture: Hadrian/Shutterstock
Clandestine Airstrips, a Mexican Mega Leak, and a Crisis of Unidentified Missing People: 2025’s Best Investigative Stories in Spanish
The investigative stories produced in the Spanish-speaking world this year show a vibrant journalistic landscape, despite the challenges reporters now face in many places — from rampant disinformation …
Close-up of Google app including search bar and link to AI Mode. Picture: Shutterstock/Nwz Last week Google announced a raft of deals with national news organisations , under the banner of a new …
Chinese robot pictured at Web Summit in Lisbon. Picture: Press Gazette/Dominic Ponsford A broad coalition of news publishers have backed shared licensing technology which seeks to protect content in …
AP launches verification dashboard for publishers to meet ‘demand for authenticity’
AP Verify dashboard homepage Associated Press has launched an AI-powered tool to help journalists verify text, photos and videos in one place. The AP Verify dashboard will let subscribers access …
Using AI-Generated Images to Get Refunds Scammers are generating images of broken merchandise in order to apply for refunds. Tags: AI , China , scams Posted on December 30, 2025 at 7:02 AM • 0 …
The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access trojan called ValleyRAT (aka Winos 4.0). …
** Dec 30, 2026 ** Ravie Lakshmanan Malware / Cyber Espionage The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new …