Posts by Sami Laiho
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
www.bleepingcomputer.com/news/securit...
APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials
www.darkreading.com/cloud-securi...
APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook
Reconnaissance and Software Tampering Attacks
www.genians.co.kr/en/blog/thre...
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain
Incident
thehackernews.com/2026/04/open...
wolfSSL - Missing hash/digest size and OID checks
URL: github.com/advisories/G...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.3
Axios Vulnerability Disclosure: Unrestricted Cloud Metadata Exfiltration via
Header Injection Chain
URL: github.com/advisories/G...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 10.0
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
thehackernews.com/2026/04/adob...
Cockpit - Unauthenticated remote code execution due to SSH command-line
argument injection
URL: github.com/cockpit-proj...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
Cockpit - Unauthenticated remote code execution due to SSH command-line
argument injection
URL: github.com/cockpit-proj...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
Marimo - Pre-Auth Remote Code Execution via Terminal WebSocket Authentication
Bypass
URL: github.com/marimo-team/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 9.3
Security update available for Adobe Acrobat Reader | APSB26-43
URL: helpx.adobe.com/security/pro...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 8.6
March 2026 Cyber Threat Landscape Shows No Relief as Ransomware Rebounds and
GenAI Risks Intensify
blog.checkpoint.com/research/mar...
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad
Data
thehackernews.com/2026/04/citi...
Recovery scammers hit you when you’re down: Here’s how to avoid a second
strike
www.welivesecurity.com/en/scams/rec...
New VENOM phishing attacks steal senior executives' Microsoft logins
www.bleepingcomputer.com/news/securit...
Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10
Hours
www.sysdig.com/blog/marimo-...
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
www.bleepingcomputer.com/news/securit...
My #AI avatar fell off the wagon apparently...
Join me for #techmentor and #cybersecurity Live in #redmond with a BIG discount!
bit.ly/4tw0Ndi