Technology radar

Cybersecurity

Risk, identity, incident response and compliance.

Daily update 11 categories Source cited in every entry
Cybersecurity

When AI Coding Agents Become Malware Delivery Systems

AI coding agents are becoming part of everyday development work. Developers use them to find libraries, configure projects, troubleshoot installation problems, and set up new tools.

Read the entry
Cybersecurity
Cybersecurity

Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026

This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's eff…

Read
Cybersecurity

How to implement HMAC authentication in ASP.NET Core

Security is a major concern for web applications and services that use the HTTP protocol. Although HTTP is a versatile protocol that can be…

Read
Cybersecurity
Cybersecurity

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.

Read
Cybersecurity
Cybersecurity

Android Malware Hijacks Update System for Car Head Units

Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functi…

Read
Cybersecurity

Inside Arctic Wolf’s new agentic security platform

AI-powered attacks are becoming faster and more automated, putting pressure on security teams that still investigate alerts sequentially. A…

Read
Cybersecurity

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's neve…

Read
Cybersecurity
Cybersecurity

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user …

Read
Cybersecurity
Cybersecurity

Nigeria Looks to Sovereign Cloud for Cyber, National Security

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase d…

Read
Cybersecurity
Cybersecurity

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

Read
Cybersecurity

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On …

Read
Cybersecurity

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Ser…

Read
Cybersecurity

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by …

Read
Cybersecurity

Grok Bot vs. Hermes: Where each draws the security boundary

Put several AI bots to work, and a mistake by one may not stay within its assigned task. For example, The post Grok Bot vs. Hermes: Where e…

Read
Cybersecurity

Empowering autonomous agents with advanced security governance

AI agents are the ultimate insiders. We grant them permission to read emails, query databases, and trigger API calls. They don’t just retri…

Read
Cybersecurity

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access managemen…

Read
Cybersecurity

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliv…

Read
Cybersecurity

Anthropic brings Mythos 5 to its Claude Security vulnerability scanner

Earlier this year, Anthropic launched Claude Security, an enterprise tool that helps development teams scan their codebase for security vul…

Read
Cybersecurity

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are…

Read
Cybersecurity

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perfo…

Read
Cybersecurity

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware…

Read
Cybersecurity

Wazuh and AI For Enhanced SOC Workflows

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and educat…

Read
Cybersecurity

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehen…

Read
Cybersecurity

Backdoored Rust packages hit crates.io, exposing developers to malware at build time

Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carry…

Read
Cybersecurity

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The …

Read
Cybersecurity

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account publ…

Read
Cybersecurity

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single ou…

Read
Cybersecurity

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defen…

Read
Cybersecurity

Researchers hid an attack inside AES encryption. The AI model cracked it open willingly.

Security filters are designed to catch malicious instructions before an AI model can act on them. Researchers at AI security The post Resea…

Read
Cybersecurity

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artifici…

Read
How the radar works

Published daily, edited by me

A scheduled process prepares the entries for each category every day; I review them, edit them and add my own from the administration console.

1 · It runs every day

A scheduled task runs in the early hours and goes through the active categories.

2 · It drafts the entry

Title, summary and analysis, with the source cited and the original link always visible.

3 · It assigns the image

It takes the cover image from the source or a stock image with a free-use license.

4 · I edit and publish

From the console I approve, correct or write my own entries and articles.

Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.