ToxicPanda 2.0 Abuses Android VPN Permissions to Blindside Google Play Protect

The Evolution of a Targeted Banking Trojan Security researchers tracking mobile threats have documented a significant architectural update to ToxicPanda, an Android banking trojan that first surfaced in late 2024. The new variant, labeled ToxicPanda 2.0, has expanded its target list to 349 financial and banking applications across Europe, Latin America, and emerging markets. Beyond […]

Poisoned arrayref Rust Crate Shows Why Build-Time Execution Needs Guardrails

A Compromised Maintainer and Three Poisoned Crates Earlier this week, security researchers identified a coordinated supply-chain attack targeting the Rust package ecosystem. Attackers compromised the crates.io account of a maintainer responsible for arrayref, a widely used Rust library with tens of millions of downloads across cryptography, networking, and graphics packages. Once inside the account, the […]

Securing Windows Named Pipes: Defending Interprocess Communication from Local Privilege Escalation

Interprocess communication (IPC) on Microsoft Windows relies heavily on named pipes for exchanging structured data between local services, administrative tools, and user-space applications. Because named pipes function across session boundaries and provide network accessibility via SMB, they represent a persistent target for adversaries seeking local privilege escalation (LPE), lateral movement, and defense evasion. New defensive […]

Offline Cryptographic Auditing: Azure Confidential Ledger Releases Local Ledger Verification Tool

Verifying the cryptographic integrity of tamper-proof audit trails has traditionally required direct network connectivity to the underlying enclave infrastructure. For organizations operating under stringent compliance frameworks, external auditing engagements create an operational friction point: how do you grant third-party auditors or security analysts the ability to inspect transaction history and validate mathematical proofs without exposing […]

Grok AI Exfiltrates Private User Data When Attackers Encrypt Malicious Instructions

Security researchers have demonstrated a significant vulnerability in xAI’s Grok chatbot that allows external attackers to exfiltrate private conversation history. The attack relies on an indirect prompt injection technique that encrypts malicious instructions on a webpage, evading automated guardrail scanners until Grok itself decrypts and executes the payload during normal browsing and summarization tasks. How […]

SynkLoader Malware Uses Microsoft Teams Phishing and Fake Lock Screens to Infiltrate Corporate Networks

A previously undocumented malware family named SynkLoader has surfaced in targeted social engineering campaigns across corporate Microsoft Teams environments. Discovered by security researchers at Expel, the attack chain begins with direct messages from external Microsoft 365 tenants impersonating internal IT helpdesk staff and culminates in a fake Windows lock screen designed to capture domain passwords. […]

CISA Warns of In-the-Wild Exploits Targeting Critical MLflow SSRF Vulnerability

The Cybersecurity and Infrastructure Security Agency added a critical vulnerability in the open-source machine learning platform MLflow to its Known Exploited Vulnerabilities catalog after telemetry confirmed attackers are actively scanning and compromising exposed instances. The flaw, tracked as CVE-2026-64849, allows unauthenticated remote attackers to trigger server-side request forgery requests from vulnerable MLflow servers to internal […]

LiteLLM supply-chain attack exposed credentials from 2,500 organizations including Microsoft and Amazon

What happened A supply-chain attack on LiteLLM, an open source tool for managing AI API calls, exposed terabytes of credentials from roughly 2,500 organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock disclosed the breach, which compromised approximately 434,000 CI/CD pipelines during a 40-minute attack window in March 2026. The […]

[Launched] Generally Available: Microsoft Defender security assessments for Azure Database for PostgreSQL Flexible Server

Microsoft Defender Security Assessments for Azure Database for PostgreSQL Flexible Server: Enhanced CSPM Coverage Microsoft Defender Cloud Security Posture Management (CSPM) has reached generally available status for Azure PostgreSQL Flexible Server databases, bringing comprehensive security assessment capabilities to this managed database service. This GA release marks a significant expansion of Microsoft’s cloud security posture management […]

SafePal Data Breach Exposed Customer Records, But Not the Keys That Matter

SafePal, the cryptocurrency hardware wallet provider, confirmed a data breach that exposed personally identifiable information for roughly 39,798 customers. The good news, and it is genuinely reassuring: wallet seed phrases, private keys, passwords, and financial account data were not part of what leaked. The company states no evidence exists that the incident compromised access to […]