RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritymalware

Harvester APT Port GoGra Backdoor to Linux, Abuses Microsoft Graph API for C2

The Harvester threat group has expanded its Linux tooling with a port of the GoGra backdoor, previously seen only on Windows, and is using it against targets in

via The Hacker News ·
privacypolicy

ICE Confirms Use of Graphite Spyware in Domestic Operations

U.S. Immigration and Customs Enforcement has acknowledged deploying Graphite, a zero-click spyware product from Israeli vendor Paragon Solutions. The agency fra

via Schneier on Security ·
cybersecuritymalware

Kyber ransomware ships dual ESXi/Windows payloads, fakes post-quantum crypto on Linux

Rapid7 analyzed two Kyber ransomware variants deployed in tandem during a March 2026 incident, with one targeting VMware ESXi and a Rust-built sibling hitting W

via BleepingComputer ·
cybersecuritymalware

Lotus Wiper Hits Venezuelan Energy Grid in Destructive Campaign

A previously uncatalogued wiper dubbed Lotus has surfaced in attacks against Venezuelan energy infrastructure, destroying data rather than encrypting it for ran

via The Hacker News ·
cybersecurityvulnerability

Microsoft patches critical ASP.NET Core flaw letting attackers forge SYSTEM-level auth

Microsoft pushed an emergency fix for CVE-2026-40372, a high-severity bug in the Microsoft.AspNetCore.DataProtection NuGet package (versions 10.0.0 through 10.0

via Ars Technica ·
cybersecurityvulnerability

Microsoft Ships Emergency Fix for Critical ASP.NET Core Auth Bypass

Microsoft has issued out-of-band patches for CVE-2026-40372, a critical privilege escalation flaw in ASP.NET Core's Data Protection cryptographic APIs. A regres

via BleepingComputer ·
vulnerabilitycybersecurity

Microsoft Ships Fix for Critical ASP.NET Core Privilege Escalation Flaw

Microsoft has released a patch for CVE-2026-40372, a critical privilege escalation vulnerability in ASP.NET Core. The flaw allows an attacker to elevate privile

via The Hacker News ·
cybersecuritymalware

Mustang Panda Deploys LOTUSLITE Variant Against Indian Banks, South Korean Policy Targets

China-linked threat actor Mustang Panda has resurfaced with a refined variant of its LOTUSLITE backdoor, aimed squarely at financial institutions in India and p

via The Hacker News ·
tech-culturecloud

NASA's Artemis II proves laser comms can stream HD video from the Moon

Artemis II's four-person crew beamed most of their video home over radio — S-band at 3-5 MB/s, a modest step up from Apollo's 50 KB/s but still low-definition b

via Ars Technica ·
cybersecuritymalware

North Korea's 'Contagious Interview' Job Scam Now Self-Propagates Through Victims

DPRK-aligned threat actors running the long-tracked 'Contagious Interview' campaign have evolved their playbook: the fake job recruitment scheme now spreads thr

via Dark Reading ·
cybersecuritymalware

Ransomware Negotiator Flips Sides, Pleads Guilty in BlackCat Extortion Scheme

A ransomware negotiator — one of the professionals companies hire to broker payments with extortion crews — has pleaded guilty to conspiring with the BlackCat/A

via Dark Reading ·
cybersecurityidentity

Scattered Spider's 'Tylerb' Pleads Guilty to $8M Crypto Theft Spree

Tyler Robert Buchanan, a 24-year-old Scottish national and senior operator in the Scattered Spider cybercrime collective, has pleaded guilty in U.S. federal cou

via Krebs on Security ·