A previously undocumented threat actor, possibly tied to Russian intelligence services, is targeting Ukrainian defense, military, government, and energy organizations with a new malware family dubbed CANFAIL. Google’s Threat Intelligence Group identified the campaign, underscoring the continued intensity of state-backed operations against Ukraine’s critical sectors.
Source: Security Affairs
CISA Adds Critical BeyondTrust RS/PRA Flaw (CVE-2026-1731) to KEV
CISA has added a critical vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-1731 with a CVSS score of 9.9, the flaw is under active exploitation, and BeyondTrust has released security updates—organizations should prioritize patching.
Source: Security Affairs
300+ Malicious Chrome Extensions Caught Leaking or Stealing User Data
More than 300 Chrome extensions with a combined 37 million+ downloads were found exfiltrating user data, exposing individuals to tracking and theft of personal information. The findings highlight persistent risks in browser extension ecosystems and the need for strict permission hygiene and regular extension audits.
Source: SecurityWeek
Fintech Firm Figure Discloses Breach After Employee Phishing Attack
Blockchain-based lender Figure confirmed a data breach after a social engineering attack tricked an employee, allowing access to a limited number of files. The incident underscores how credential theft and phishing remain reliable initial access vectors against financial services.
Source: Security Affairs
Report: DHS Sent Hundreds of Subpoenas to Unmask Anti-ICE Accounts
The Department of Homeland Security reportedly issued hundreds of subpoenas to tech firms seeking to identify owners of accounts critical of ICE. The reported increase in pressure on platforms raises fresh questions about online anonymity and the handling of government data demands.
Source: TechCrunch
Ring Halts Flock Safety Deal After Super Bowl Ad Uproar
Following public backlash tied to a Super Bowl ad, Ring canceled its planned partnership with Flock Safety. The decision reflects heightened scrutiny of consumer surveillance tools and their data-sharing arrangements with law enforcement.
Source: Wired
US Official Points to Common Ground on Tackling Sexualized Deepfakes
Top Trump official Sarah Rogers rejected culture-war allegations as “a lie,” noting some shared ground on combating online sexualized deepfakes. The remarks signal potential bipartisan momentum for addressing harms from AI-generated content.
Source: Politico
You May Also Be Interested In...
287 Chrome Extensions Caught Harvesting Browsing Data from 37M Users
Your Smart Home Is Watching You: Privacy in the Age of AI Robots
WinHttpOpen user agents