VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
Ravie LakshmananJun 08, 2026Software Supply Chain / Malware !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPMxcu3ZcBpbZRC5rw9BlnoZMoXgrA-dRRquG6...
145 posts from this source
Ravie LakshmananJun 08, 2026Software Supply Chain / Malware !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPMxcu3ZcBpbZRC5rw9BlnoZMoXgrA-dRRquG6...
Ravie LakshmananJun 06, 2026Cybersecurity / Artificial Intelligence !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBOQJLNqTRWigWAgPKNCKXr8hOgMZD...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKr3KoscB_oGLqU5_JV16DIaB7jXY1ko8PiJDTuwrxbHcZV2DYJpfkx8lqwNbscwTSTVQUMwd8vBf-nI13mQE7vzzmUzwKF3BF6q...
Ravie LakshmananJun 06, 2026Vulnerability / Patch Management !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ_ZbsHhh5kUS5501itVSeBa91H50qNfHH_PQ...
Swati KhandelwalJun 06, 2026Vulnerability / Endpoint Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyg1vRQART17ZjJXANnrQ8Vtn7h_tM5IihGJ...
Ravie LakshmananJun 06, 2026Supply Chain Attack / Malware !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgG8k6LtHNQ3cHl_X1AZbXRn6LZCNZ6lMLjy-9HG7...
Ravie LakshmananJun 06, 2026Vulnerability / Network Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYckKvOFV_Xz1o-nUKCcjlMQmOxdFC6FMzIjM...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFimSGBOnvlCj_r6fiLdzK6V8DLTIQYjROKxHgQH8QxyRVIL3NDpQe9lBISjqCSjcZNl6VPhHVFtdJ8gPe2FfNjR9kGND1GSZmgx...
Ravie LakshmananJun 05, 2026Spyware / Mobile Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimTj2SdhVr1jj9e2RqrAOW9dIsBmuMZJsqWGt6weL0DO...
Ravie LakshmananJun 05, 2026Cyber Espionage / Threat Intelligence !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiab_7FEmO4woH_bG4spUNJRFCFvvmpF9...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsdgNCJHCuVqNf4dGZYDAmzpytkCd3NBt-TKUtEo-bSBKeuqJzzk7CGB5l-JxHyIz5mVjHRn7csD0zZNm4MipX2Kwhfx8gB_Qdk8...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgKOwHRwFSrcOI7vBYVGbebtc3DwR3w7SYc9l7FUXp1yXc_N2MbNNlEXtfRjVneU4wz2YB8PqC_k54o_6ZpB2oKZKhVBlK7IC-CG...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMkj_adwzUUFP7yWyIFVKIKKQGDjqfvPuxKoR4mrrJ_SX3EACoJ3toLV3ZkYmePeA-nKWWfVC-90aOa5yjepuVYNy2lc820-onK2...
Ravie LakshmananJun 05, 2026Threat Intelligence / Cloud Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibu0mX9Tusu3siXFJzPskfA1ZYZ2OdRJT...
Overview Cisco has patched a vulnerability in Unified Communications Manager Unified CM that allowed an unauthenticated attacker on the network to write files...
Swati KhandelwalJun 04, 2026Vulnerability / AI Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiaBF9jAklPh1ncr_eVPGnV229BSTNgAjkScVm-yTX...
Image: Agentic AI Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challen...
It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrappe...
A new China‑linked cybercrime group known as TA4922 has expanded its targeting focus to European organizations in the United Kingdom, Germany, Italy, and South...
markdown !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFQkJElJQpI5ODTBzh1EzrxsRYamFN0ntC9V6vF4b4FfEJ0svPhI_1TnKm960eIsewSFT-DR1RtNk3M511OQK6I-k3...
Cybersecurity researchers have flagged a large‑scale operation that impersonates open‑source and freeware projects to funnel unsuspecting users through a Traffi...
Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small,...
Ravie Lakshmanan June 4, 2026 – Cryptocurrency / Law Enforcement !Police crypto imagehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTf5wAHnoXtVauil...
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C software development kit for Sicoob, one of Brazil's largest coopera...
A critical security vulnerability has been disclosed in Gogs, a popular open‑source self‑hosted Git service. The flaw allows any authenticated user to achieve r...
Threat actors are exploiting a critical, now‑patched security flaw in FortiClient Endpoint Management Server EMS to deliver a credential‑stealing malware payloa...
!Microsoft and GitHub imagehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIMDR_KVt17sFMXeEhMvDYHLwBX_Aix1bz3y0izMs7PsVIuGSQhOLX_khN3Ckl_eRm9OEMAlVm...
Every time you think the industry has finally stopped doing some reckless, low‑effort crap, somebody spins up a fresh box full of sketchy loaders, fake installe...
State of AI Usage Report 2026 full report here by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't...
Overview Latin America and Europe have become the target of two banking‑trojan campaigns designed to infect Windows and Android devices with Grandoreiro and BT...
!npm AI imagehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlezHawmKBTFBZSgR52vL_EBxfwIlMa0i4LdDK2xC_c8nw704KQHbRNSHYAy8TY4ShZMFwAJoZKUBSDJBCVnwbOR...
CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control C2 channels associ...
Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents...
Introduction When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool,...
!Gitea main interfacehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtYSLWixSGb7jW2drND6NlHzXB4eHO0QyZNOovK9iVyaHGS6fSN4eqhWkijIhevhInH56hv03c29ziWC...
Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence AI chatbot interactions as a mechanism for surfacing maliciou...
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents i...
Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone—they’...
!SharePointhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi34meakbjhvY3-jNVG7Q8tPJ5Xk1a-vtGSeKgfVDApX6pn88G7gYhK2oz34my6QeWHsldmSJuV4o8tlBOmw-9Ul32E...
The Indian Computer Emergency Response Team CERT‑In has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet‑exp...
Ravie Lakshmanan May 26 2026 – Artificial Intelligence / Cloud Security !Indian CERThttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9yN2AliOVdy0oCCM...
The Iranian state‑sponsored threat actor known as Nimbus Manticore also referred to as Screening Serpens and UNC1549 has been linked to a new campaign that uses...
!KnowledgeDeliver LMShttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZKxsveHlyTguEODsRiYVuCPiOkIgyd3imCYdnpwwV2NQ0pw9oPEQoVw-2T98HW0KgZvRqQ_zeZIT-4E...
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from t...
Threat Overview Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel C...
Ask a cybersecurity pro about Network Detection and Response NDR and you might still hear “Noisy,” “Too much data.” But ask the teams running NDR that includes...
Cybersecurity researchers have shed light on a cross‑platform malware called RemotePE that has been put to use by the North Korea‑linked Lazarus Group in attack...
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential‑stealing malware. The cam...