Blog

Home | Cloud Solutions

Latest News

All the latest news

    Trending Cloud Solutions

    Cloud & IT Infrastructure News

    • Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

      Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069. "We have attributed the attack to a suspected North Korean threat actor we track as UNC1069," John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), told The Hacker News in a statement. "North Korean

    • Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

      Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently released due to a human error. "No sensitive customer data or credentials were involved or exposed," an Anthropic spokesperson said in a statement shared with CNBC News. "This was a release packaging issue caused by human error, not a security

    • Android Developer Verification Rollout Begins Ahead of September Enforcement

      Google on Monday said it's officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while "hiding behind anonymity." The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and Thailand this September, before it expands globally next year. As part of this

    • TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

      A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos. The vulnerability in question is CVE-2026-3502 (CVSS score: 7.8), a lack of integrity check when fetching application update code, allowing an attacker to distribute a tampered update,

    • Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

      Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization's cloud environment. According to Palo Alto Networks Unit 42, the issue relates to how the Vertex AI permission model can be misused

    • The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority

      The cybersecurity landscape is accelerating at an unprecedented rate. What is emerging is not simply a rise in the number of vulnerabilities or tools, but a dramatic increase in speed. Speed of attack, speed of exploitation, and speed of change across modern environments. This is the defining challenge of the new era of digital warfare: the weaponization of Artificial Intelligence. Threat actors

    • Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

      Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. "The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonating

    • Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

      The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency that delivers a trojan capable of targeting Windows, macOS, and Linux systems. Versions 1.14.1 and 0.30.4 of Axios have been found to inject "plain-crypto-js" version 4.2.1 as a fake dependency. According to StepSecurity, the two

    • OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

      A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point. "A single malicious prompt could turn an otherwise ordinary conversation into a covert exfiltration channel, leaking user messages, uploaded files, and other sensitive content," the cybersecurity company said in

    • DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials

      A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad. "It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is blocked," ReliaQuest researchers Thassanai

    Subscribe For Your First Line Of Digital Defense

    Stay informed, stay protected. CyberShield Weekly brings you the latest cybersecurity headlines, expert insights, and real-world threat alerts—delivered straight to your inbox. Whether you’re an IT pro or a business owner, our newsletter equips you with the knowledge to defend against today’s digital threats. 

    KulwebTech Blog delivers expert insights, industry news, and practical advice on cybersecurity, cloud solutions, and IT innovation. 

    Stay connected. Stay secure.

    Copyright © 2025  Kulweb Technologies. All Rights Reserved.