North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning artificial intelligence (AI), cryptocurrency, financial s… Continue reading North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews

Posted in Uncategorized

Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in denial-of-service (DoS) and remote code execution.
The most severe of the lot is a critical security flaw impacting Zoom Node Multimedia… Continue reading Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws

Posted in Uncategorized

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code

The recently discovered sophisticated Linux malware framework known as VoidLink is assessed to have been developed by a single person with assistance from an artificial intelligence (AI) model.
That’s according to new findings from Check Point Research… Continue reading VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code

Posted in Uncategorized

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

LastPass is alerting users to a new active phishing campaign that’s impersonating the password management service, which aims to trick users into giving up their master passwords.
The campaign, which began on or around January 19, 2026, involves sendin… Continue reading LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

Posted in Uncategorized

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

A security vulnerability has been disclosed in the popular binary-parser npm library that, if successfully exploited, could result in the execution of arbitrary JavaScript.
The vulnerability, tracked as CVE-2026-1245 (CVSS score: N/A), affects all vers… Continue reading CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Posted in Uncategorized

Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution

A set of three security vulnerabilities has been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic, that could be exploited to read or delete arbitrary files and execute code under certain conditi… Continue reading Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution

Posted in Uncategorized