New Lotus data wiper used against Venezuelan energy, utility firms post, april 21, 2026april 24, 2026 A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. The malware was uploaded to a publicly available platform in mid-December from a machine in Venezuela and has been analyzed by researchers at Kaspersky. Continue Reading
US warns of Iranian hackers targeting critical infrastructure post, april 7, 2026april 9, 2026 Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. The warning came earlier today in the form of a joint advisory authored by the FBI, CISA, NSA, the Environmental Protection Agency (EPA), Department of Energy (DOE), and the United States Cyber… Continue Reading
New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection post, april 7, 2026april 10, 2026 A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks. Unlike… Continue Reading
Ministerie van Financiën gehackt, systemen geblokkeerd door ministerie post, maart 23, 2026maart 24, 2026 Het ministerie van Financiën in Den Haag is vorige week getroffen door een hack. Als gevolg daarvan is besloten om systemen voor “een aantal primaire processen” op het departement te blokkeren, laat het ministerie weten. Een deel van de medewerkers kan daardoor niet inloggen op die computersystemen. Hoelang het gaat… Continue Reading
NIST Overhauls DNS Security Guidance After 12 Years, Reflecting a Transformed Threat Landscape post, maart 23, 2026maart 24, 2026 In a significant update to federal cybersecurity policy, the National Institute of Standards and Technology (NIST) has released a new version of its long-standing Domain Name System (DNS) security guidance—marking the first major revision in over a decade. Continue Reading
Why Stryker’s Outage Is a Disaster Recovery Wake-Up Call post, maart 12, 2026maart 18, 2026 A cyberattack that appears to have knocked tens of thousands of systems offline at medical technology company Stryker this week is a sobering reminder of the importance for organizations to have robust and tested business continuity and disaster recovery plans. Iranian threat group Handala claimed responsibility for the attack, calling it… Continue Reading
CrowdStrike 2026 Global Threat Report post, februari 24, 2026februari 26, 2026 In the age of AI, even less sophisticated threat actors can execute complex attacks, and advanced adversaries have become dramatically more dangerous. This year’s report exposes the latest tradecraft of the evasive adversary, who is supercharging attacks with AI and posing an unprecedented threat. Attacks by AI-enabled adversaries increased by… Continue Reading
How tenaciously Palantir courted Switzerland post, februari 18, 2026februari 23, 2026 The controversial tech company Palantir provides surveillance technology to militaries and intelligence services around the world. In Switzerland, however, its pitches have been rejected by both government authorities and the army. Internal documents have now revealed why. Continue Reading
OWASP Top 10 For AgenticApplications 2026 post, februari 16, 2026februari 23, 2026 Agentic AI systems are moving quickly from pilots to production across finance, healthcare, defense, critical infrastructure, and the public sector. Unlike task-specific automations, agents plan, decide, and act across multiple steps and systems, often on behalf of users and teams. The Agentic Security Initiative has already begun defining safeguards for… Continue Reading
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days post, februari 3, 2026februari 4, 2026 In the latest illustration of how quickly attackers can exploit newly disclosed flaws, Russia’s notorious APT28 cyber-espionage group has begun abusing a recently patched Microsoft vulnerability to steal emails and deploy malicious payloads against organizations in Central and Eastern Europe. CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office… Continue Reading