Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Tenable reveals that attackers now target configuration files for AI coding assistants, such as settings.json and .cursorrules, to inject persistent malware. This new worm class evades AI-based scanners and propagates through organizational repositories by leveraging developer workflows.
Project CAV3RN cyberespionage framework abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery.
The article reports on a new communication module for Project CAV3RN that abuses Outlook calendar events for command-and-control. It also uses DNS AAAA records to recover configuration.
In June 2026, Kaspersky researchers identified a new module within the Project CAV3RN framework, a sophisticated cyberespionage tool targeting Israeli entities. This module, designed to replace the previous HTTP/WebSocket communication component, leverages Microsoft Outlook calendar events accessed via Microsoft Graph for command-and-control (C2) operations.
CrowdStrike discusses the detection of SANDWORM_MODE and the emerging class of AI toolchain supply chain attacks. The article highlights the need for new detection methods to counter these threats.
CrowdStrike examines the detection of SANDWORM_MODE and the emerging class of AI toolchain supply chain attacks. The article emphasizes the importance of adapting defenses to these new attack methods.