Category Archives: Threat Alerts
FIRESTARTER Malware: CISA Warns of Persistence on Cisco Firewalls
CISA has updated its emergency directive warning that FIRESTARTER malware can survive firmware patches on Cisco devices, requiring advanced forensic removal methods. Continue reading
TestFlight Phishing and QR Code Lures Rise in VIPRE Q1 2026 Report
The VIPRE Q1 2026 report reveals a surge in TestFlight phishing and QR-embedded PDF lures, marking a shift in social engineering tactics used to bypass security. Continue reading
Kyber Ransomware Adopts Kyber1024 Post-Quantum Encryption
A new variant of Kyber Ransomware has been detected using Kyber1024 post-quantum cryptography to encrypt Windows and VMware ESXi endpoints, targeting high-value infrastructure. Continue reading
Silent Subject Phishing: New VIP Campaign Bypasses Security
Security researchers have identified a surge in Silent Subject Phishing targeting corporate VIPs, using empty subject lines to evade traditional detection methods. Continue reading
Checkmarx Supply Chain Attack: Malicious KICS Images and VS Code Extensions
A sophisticated Checkmarx supply chain attack has been identified, involving poisoned KICS Docker images and malicious VS Code extensions designed to exfiltrate sensitive credentials and developer tokens. Continue reading
Vibe Coding Phishing: AI-Powered Softr Exploits Rise in 2026
Cisco Talos identifies vibe coding phishing as a top threat, utilizing AI-driven no-code platforms like Softr to automate credential harvesting at scale. Continue reading
AI Voice Cloning: Post-Tax Refund Extortion and Digital Fraud Trends
The SENTINEL-FRAUD assessment highlights a significant rise in AI voice cloning used for post-tax refund extortion and sophisticated social engineering attacks. Continue reading
Cisco SD-WAN Vulnerabilities Under Active Exploitation: CISA Issues Warning
CISA has added several Cisco SD-WAN vulnerabilities to its Known Exploited Vulnerabilities catalog following reports of attackers using a three-flaw chain to gain full administrative control of corporate networks. Continue reading
SGLang RCE Vulnerability (CVE-2026-5760) Exploits AI Pipelines
Security researchers have identified a critical SGLang RCE vulnerability (CVE-2026-5760) that allows remote code execution through malicious GGUF model files. Continue reading