New Mexico QKD Testbed Launches Entangled Photon Services

New Mexico’s ABQ-Net has become the first open-access, quantum entanglement-based network in the United States, hosting four quantum companies testing next-generation communication technologies over leased internet service provider fiber cables, according to project backers. Quantum Key Distribution Tested Over Leased Albuquerque Fiber The 50-kilometer network uses leased ISP fiber cables looped between telephone poles, subjecting … Read more

AWS Launches GuardDuty Investigation Agent to Automate Threat Triage

Amazon GuardDuty Investigation Agent Public Preview Launches for Cloud Security Amazon Web Services has released the public preview of the Amazon GuardDuty investigation agent, an AI-powered security tool designed to evaluate findings, correlate historical activity, and map threat telemetry across cloud environments. According to AWS, the new capability aims to reduce security investigation workflows from … Read more

Microsoft Works to Repair Relations with Security Researchers

The New Frontier of Cyber Warfare: From Gas Gauges to Global Espionage The digital landscape is shifting beneath our feet. As we move through 2026, the lines between traditional cybercrime and state-sponsored espionage are blurring. Recent incidents, ranging from the targeting of critical infrastructure to the weaponization of generative AI, reveal a sophisticated threat environment … Read more

Android Malware Taps Google Gemini at Runtime

Android Malware Enlists AI: A New Era of Mobile Threats A newly discovered Android malware strain, dubbed “PromptSpy” by security firm Eset, is leveraging Google’s Gemini generative AI model to enhance its persistence mechanisms. This marks the second known instance of AI-driven mobile malware, signaling a concerning trend in the cybersecurity landscape. How PromptSpy Works: … Read more

Social Engineering Hackers Target Okta Single Sign On

The Evolution of Voice Phishing: How ‘Live Phishing Panels’ Are Redefining Corporate Data Breaches Image: Oleksandr Yashchuk/Shutterstock The recent surge in attacks leveraging voice phishing, particularly those targeting Okta users and orchestrated by groups like ShinyHunters, isn’t a fleeting trend. It’s a harbinger of a more sophisticated and dangerous era of social engineering. The key … Read more

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

Cisco Zero-Days: A Harbinger of Increased Attacks on Collaboration Tools? The recent disclosure of CVE-2026-20045, a critical zero-day vulnerability impacting Cisco’s Unified Communications and Webex Calling platforms, isn’t an isolated incident. It’s a stark reminder of a growing trend: collaboration tools are rapidly becoming prime targets for malicious actors. This vulnerability, already exploited in the … Read more

OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls

The Rise of AI Health Companions: Beyond ChatGPT Health OpenAI’s launch of ChatGPT Health marks a pivotal moment, but it’s just the beginning. The integration of artificial intelligence into personal healthcare is rapidly accelerating, driven by user demand for accessible information and proactive health management. This isn’t simply about chatbots answering medical questions; it’s about … Read more

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

MongoDB Vulnerability: A Harbinger of Future Database Security Challenges A recently disclosed high-severity flaw in MongoDB (CVE-2025-14847) – allowing unauthenticated read access to heap memory – isn’t just a patch-and-move-on situation. It’s a stark reminder of the evolving threat landscape facing database security, and a glimpse into challenges we’ll see amplified in the coming years. … Read more

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

December 22, 2025Ravie LakshmananMalware / Open Source / Supply Chain Security The Rising Tide of Malicious Packages: A Looming Threat to Software Supply Chains The recent discovery of “lotusbail,” a malicious npm package masquerading as a WhatsApp API, and a wave of compromised NuGet packages targeting the cryptocurrency ecosystem, aren’t isolated incidents. They represent a … Read more

Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers

The Rise of Device Code Phishing: A Glimpse into the Future of Account Takeovers A concerning trend is rapidly gaining traction in the cybersecurity landscape: device code phishing. Recent reports, including analysis by Proofpoint of the UNK_AcademicFlare campaign attributed to a Russia-aligned group, highlight a sophisticated technique for stealing Microsoft 365 credentials. This isn’t a … Read more