Legacy Systems, Real-World Impacts: The Reality of OT Security

Legacy Systems, Real-World Impacts: The Reality of OT Security As a cybersecurity journalist, I’ve witnessed firsthand the growing concern around operational technology (OT) security. It’s an area where legacy systems meet harsh realities, putting critical infrastructure and lives at risk. Recently, I had the opportunity to explore this complex world through the lens of vulnerability … Read more

1M+ Emails Use Hidden Text to Dupe AI Security Filters

As many as 1 million retail-themed phishing emails have been evading both static and artificial intelligence-powered email security checks by using a simple yet effective technique called text salting. This tactic involves peppering spam content with innocuous filler words or stories to break up malicious language, making it harder for automated filters to detect. The … Read more

Agentic AI Is Untamable: Ask the Right Security Questions

Agentic AI Is Creating Unpredictable Risks for Organizations, Demanding a Fundamental Shift in Security Thinking The notion that artificial intelligence (AI) can be controlled and predicted has been turned on its head by the emergence of agentic systems. These intelligent agents are capable of adapting to their environment and making decisions autonomously, creating significant risks … Read more

New Spirals ransomware encrypts victim network in under 24 hours

A new and highly aggressive strain of ransomware, dubbed Spirals, has been uncovered by researchers at Symantec’s Threat Hunter Team. This powerful threat not only encrypted a corporate network in under 24 hours but also displayed a chilling level of sophistication and speed. The attack, which occurred in June, targeted an IT services firm in … Read more

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Cyberattackers have devised a sneaky way to evade email security filters, exploiting a weakness in artificial intelligence-powered detection tools. Since April, over 1 million retail-themed phishing emails have slipped into inboxes, using hidden text to make malicious social engineering appear legitimate. These emails are not just any ordinary spam messages. They employ obvious social engineering … Read more

Agentic AI Is Untamable: Ask the Right Security Questions

Agentic AI Systems Pose Unprecedented Security Risks, Rethinking Control is Essential A recent series of incidents has brought to light the untamable nature of agentic artificial intelligence (AI) systems, which are wreaking havoc on organizations worldwide. These systems, designed to automate and optimize tasks, have become a double-edged sword, introducing significant risks that traditional security … Read more

New Spirals ransomware encrypts victim network in under 24 hours

A New Ransomware Actor Emerges, Breaching Networks in Record Time In a disturbing display of speed and sophistication, a new ransomware actor known as Spirals has successfully compromised an IT services firm’s network in South Asia, completing the entire attack from initial access to data theft and encryption in under 24 hours. This alarming pace … Read more

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Cybersecurity researchers have uncovered a sophisticated campaign of financially motivated attacks by Russian hackers using trojanized software to deploy a new backdoor called Starland RAT. The malware is designed to steal sensitive information and cryptocurrency from unsuspecting victims, with a focus on users in the United States but also affecting those in Germany, Romania, and … Read more

CISA orders feds to patch actively exploited Oracle flaw by Saturday

Federal Agencies Ordered to Patch Critical Oracle Flaw by Saturday Amid Ongoing Attacks The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to federal agencies, instructing them to patch a critical vulnerability in the Oracle E-Business Suite financial application by this coming Saturday. The move comes as threat actors continue to … Read more

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Russian Hackers Use Trojanized Software to Spread Malware, Targeting Users Globally A financially motivated Russian threat actor has been using trojanized versions of popular software applications to distribute a new backdoor called Starland RAT. The malicious operation, tracked as UAT-11795 by cybersecurity researchers at Cisco Talos, has been ongoing since June 2025 and has affected … Read more