Google shipped Chrome 145 to fix CVE-2026-2441, a high-severity use-after-free in CSS that’s already being exploited in the wild. The bug can enable arbitrary code execution within the renderer sandbox via a malicious page and could be chained with other flaws for full compromise. Admins should push the update across all platforms and ensure browsers are restarted to complete the fix.
Source: SecurityWeek
Microsoft warns of “ClickFix” attacks abusing DNS lookups to stage malware
Microsoft detailed a new variant of the ClickFix social-engineering tactic that tricks users into running nslookup commands, which then retrieve next-stage payloads via DNS. The campaign ultimately drops ModeloRAT and uses DNS traffic to sidestep common web filters. Mitigate by restricting command execution, monitoring anomalous DNS queries, and training users to avoid copy-pasting terminal commands from prompts.
Source: SecurityWeek
Lazarus Group ties seen in malicious npm and PyPI packages spread via fake recruiting
Researchers at ReversingLabs found malicious packages on npm and PyPI connected to a fake job recruitment campaign attributed to North Korea–linked Lazarus Group. The packages target developers, triggering code execution at install/build time to plant malware. Teams should audit recent dependency changes, lock versions with integrity checks, and consider mirroring only vetted registries.
Source: Security Affairs
ChatGPT adds Lockdown Mode to blunt prompt injection and data exfiltration
OpenAI introduced Lockdown Mode and Elevated Risk labels in ChatGPT to reduce prompt-injection risks, especially when using external tools or integrations. Lockdown Mode constrains tool and network access to prevent prompt-based data exfiltration. Organizations integrating ChatGPT with third-party systems should evaluate and enable these controls for high-risk workflows.
Source: Help Net Security
Android 17 beta lands with upgraded privacy, security, and performance
Google released the first Android 17 beta and aims to reach Platform Stability in March, with final APIs and behavior definitions following soon after. Developers will have months before the stable release to adapt to permission, background behavior, and media/connectivity changes. Begin compatibility testing now to avoid breakage and regressions.
Source: Help Net Security
New ZeroDayRAT mobile spyware enables real-time surveillance on Android and iOS
Researchers described ZeroDayRAT, a turnkey spyware platform marketed on Telegram that supports real-time monitoring and data theft across Android and iOS. The offering illustrates the maturation of commercialized mobile espionage kits available to a wide buyer base. High-risk users and enterprises should harden device policies, scrutinize app permissions, and consider mobile threat defense solutions.
Source: The Hacker News
DoJ: Former L3Harris cyber exec sold eight zero-day exploit kits to Russia
The US Justice Department alleges a former general manager of L3Harris’s cyber unit Trenchant sold eight zero-day exploit kits to Russia. The case underscores the risks in the offensive tooling market and potential violations of export controls and sanctions. Expect tighter scrutiny on vulnerability brokering and increased due diligence demands across supply chains.
Source: The Register
You May Also Be Interested In...
Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix
In GitHub’s advisory pipeline, some advisories move faster than others
Alleged Discord Exploit Sale & WormGPT Database Leak Detected