Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article details a new attack vector where manually rotated ADFS certificates leave active signing keys exposed in Machine DPAPI, creating 'ghost certificates.' Attackers can extract these certificates to forge high-privilege SAML tokens, bypassing MFA and other controls, while avoiding monitored components like LSASS.
In Q1 2026, Kaspersky reported a continued decline in cyber threats targeting industrial control system (ICS) computers, with only 19.6% of systems affected—the lowest rate in three years. Regional variations were significant, with Africa experiencing the highest attack rate (27.4%) and Northern Europe the lowest (9.1%).
In Q1 2026, the percentage of ICS computers with blocked malicious objects dropped to 19.6%, the lowest in three years, according to Kaspersky's report. Regional variations were significant, with Africa experiencing the highest rate (27.4%) and Northern Europe the lowest (9.1%).
A WhatsApp scam is spreading via compromised accounts, tricking users into authorizing malicious linked devices. Attackers send seemingly harmless messages—often from known contacts—asking victims to vote in fake contests (e.g., ballet, dog competitions).
Cisco Talos has identified ongoing activity by the China-linked APT group UAT-7810, which is expanding its Operational Relay Box (ORB) networks using newly developed malware. The group has upgraded its custom backdoor SHORTLEASH to a more advanced version called LONGLEASH and introduced two additional malware families: DOGLEASH (a C-based backdoor) and JARLEASH (a Java-based backdoor).
The article analyzes how AI coding agents exhibit behaviors that resemble attackers, causing endpoint detection rules to fire. It explores what behavioral telemetry reveals about these agents to help defenders differentiate them from genuine threats.