• Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

    Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

    Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing persistence and enabling remote access. It’s currently not known what lures the threat actors use to…

    Read More

  • Block the Prompt, Not the Work: The End of “Doctor No”

    Block the Prompt, Not the Work: The End of “Doctor No”

    There is a character that keeps appearing in enterprise security departments, and most CISOs know exactly who that is. It doesn’t build. It doesn’t enable. Its entire function is to say “No.” No to ChatGPT. No to DeepSeek. No to the file-sharing tool the product team swears by. For years, this looked like security. But…

    Read More

  • 3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)

    3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)

    For years, cybersecurity has followed a familiar model: block malware, stop the attack. Now, attackers are moving on to what’s next. Threat actors now use malware less frequently in favor of what’s already inside your environment, including abusing trusted tools, native binaries, and legitimate admin utilities to move laterally, escalate privileges, and persist without raising…

    Read More

  • Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

    Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

    Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069. “We have attributed the attack to a suspected North Korean threat actor we track as UNC1069,” John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), told The Hacker…

    Read More

  • Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

    Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

    Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently released due to a human error. “No sensitive customer data or credentials were involved or exposed,” an Anthropic spokesperson said in a statement shared with CNBC News. “This was a release packaging issue caused by…

    Read More

  • Android Developer Verification Rollout Begins Ahead of September Enforcement

    Android Developer Verification Rollout Begins Ahead of September Enforcement

    Google on Monday said it’s officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while “hiding behind anonymity.” The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and Thailand this September, before it expands globally next year.…

    Read More

  • Council talks tourism, Spectrum agreement

    Council talks tourism, Spectrum agreement

    THE DALLES — The Dalles City Council meeting on March 23 began with a tourism report from Explore The Dalles Tourism Director Lynn Cox, covering July 1, 2025, to January. 31, 2026. According to Cox, the city recorded over five…

    Read More

  • TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

    TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

    A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos. The vulnerability in question is CVE-2026-3502 (CVSS score: 7.8), a lack of integrity check when fetching application update code, allowing an attacker…

    Read More

  • Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

    Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

    Cybersecurity researchers have disclosed a security “blind spot” in Google Cloud’s Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization’s cloud environment. According to Palo Alto Networks Unit 42, the issue relates to how the Vertex AI…

    Read More

  • Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

    Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

    Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. “The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonating

    Read More