Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A sophisticated hacking campaign, suspected of originating from China, has compromised Indian businesses and individuals by using a fake tax filing utility to deploy the DcRAT malware. The hackers’ tactics exploit a vulnerability in Microsoft’s Windows operating system, leveraging AI-powered threat analysis to evade detection. The attackers created a convincing fake tax filing tool, which … Read more

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions

Cybersecurity teams are increasingly relying on Artificial Intelligence (AI) to identify and address software vulnerabilities, but experts warn that this new approach comes with its own set of challenges. In 2026, the use of AI-powered Security Operations Centers (SOCs) has become more prevalent, but not all platforms are created equal. As organizations explore the benefits … Read more

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

Security professionals have long been aware of the potential for artificial intelligence (AI) models to discover and exploit software vulnerabilities, but a recent trend highlights just how easily this can be done. Over the past few months, several instances have come to light where AI-powered tools have identified previously unknown vulnerabilities in popular software packages, … Read more

ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)

A Massive Malware Campaign Unfolds: SANS ISC Stormcast Highlights the Threat The latest SANS Internet Stormcast has shed light on a significant malware campaign that’s been unfolding in recent days, affecting organizations across various sectors. The malicious activity is attributed to a highly sophisticated strain of malware known as “Emotet,” which has been wreaking havoc … Read more

Finding vulnerabilities was never the hard part

The cybersecurity industry has been obsessed with finding vulnerabilities for years, but it’s not the discovery itself that’s the problem – it’s what happens next. With the help of AI, organizations are now flooded with more data than ever before, making it impossible to prioritize and act on the most critical issues. For security teams, … Read more

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

Threat actors are using a cunning technique called prompt injection attacks to trick artificial intelligence (AI) agents into making cryptocurrency payments or trusting fake online platforms. This sophisticated tactic exploits vulnerabilities in how AI systems interact with websites, allowing hackers to manipulate these agents into performing malicious actions. The threat is particularly concerning because it … Read more

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

The emergence of QuimaRAT, a Java-based malware-as-a-service (MaaS) platform, poses a significant threat to organizations and individuals alike. This versatile threat can run on multiple operating systems, including Windows, Linux, and macOS, making it a formidable tool in the hands of malicious actors. QuimaRAT’s ability to adapt to various environments is rooted in its Java-based … Read more

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

A new and alarming vulnerability, dubbed TrojPix, has been discovered in air-gapped systems, allowing hackers to extract sensitive data through the electromagnetic emissions of video cables. This exploit is particularly concerning due to its ability to breach supposedly secure environments with minimal technical expertise. The potential for damage is substantial, as it’s estimated that thousands … Read more

Finding vulnerabilities was never the hard part

The Cybersecurity Conundrum: Why Finding Vulnerabilities Isn’t Enough Security leaders have a problem on their desk, and it’s not what you think. It’s not about discovering vulnerabilities or collecting more data; it’s about deciding which ones actually matter. Despite billions spent on better visibility, organizations are still struggling to stay secure. The introduction of AI … Read more

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

A new and sophisticated threat has emerged on the cybersecurity landscape, one that uses artificial intelligence (AI) to evade detection by traditional security scanners. SkillCloak is a malicious AI-powered tool that allows attackers to conceal their malware’s true nature, making it extremely difficult for defenders to identify and block the threats. SkillCloak works by using … Read more