Category: cyber-security-news

  • AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack

    AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU. Emerging from XLab’s continuous monitoring of global DDoS incidents, this botnet leveraged…

  • Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online

    Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online The Great Firewall of China (GFW) suffered its largest-ever internal data breach. More than 500 GB of sensitive material—including source code, work logs, configuration files, and internal communications—was exfiltrated and published online.  The breach stems from Geedge Networks and the MESA Lab at the…

  • Top 10 Best Ransomware Protection Solutions in 2025

    Top 10 Best Ransomware Protection Solutions in 2025 Ransomware continues to be one of the most destructive and pervasive cyber threats facing organizations of all sizes. In 2025, the sophistication of ransomware attacks has reached unprecedented levels, with threat actors employing advanced techniques like double extortion, supply chain attacks, and leveraging artificial intelligence to bypass…

  • New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

    New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm Emerging in early September 2025, the Yurei ransomware has swiftly drawn attention for its novel combination of Go-based execution and ChaCha20 encryption. First documented on September 5 when a Sri Lankan food manufacturer fell victim, the threat actor behind Yurei adopted a double-extortion model:…

  • DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments

    DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments DarkCloud Stealer has recently emerged as a potent threat targeting financial organizations through convincing phishing campaigns. Adversaries employ weaponized RAR attachments masquerading as legitimate documents to deliver a multi-stage JavaScript-based payload. Upon opening the archive, victims execute a VBE script that leverages Windows Script Host to…

  • New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

    New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, combines multiple anti-analysis techniques and adversary-in-the-middle (AitM) capabilities to target Microsoft 365 and Google accounts…

  • Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing

    Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing Nmap vs Wireshark are the most popular Network penetration testing tools. Security professionals face an increasingly complex threat landscape, and picking the right penetration testing tools can make the difference between a secure infrastructure and a compromised network. While both serve critical roles in…

  • FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration

    FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes. The advisory, published by the FBI on September 12, 2025,…

  • New Malvertising Campaign Leverages GitHub Repository to Deliver Malware

    New Malvertising Campaign Leverages GitHub Repository to Deliver Malware A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform to deceive unsuspecting users into downloading…

  • EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections

    EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques to infiltrate systems…

  • What Are The Takeaways From The Scattered LAPSUS $Hunters Statement?

    What Are The Takeaways From The Scattered LAPSUS $Hunters Statement? The well-known group of cybercriminals called Scattered Lapsus$ Hunters released a surprising farewell statement on BreachForums. This manifesto, a mix of confession and strategic deception, offers vital insights into the changing landscape of modern cybercrime and the increasing pressure from global law enforcement agencies. The…

  • New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT

    New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT Cybersecurity researchers have uncovered a sophisticated malware campaign that exploits SVG (Scalable Vector Graphics) files and email attachments to distribute dangerous Remote Access Trojans, specifically XWorm and Remcos RAT. This emerging threat represents a significant evolution in attack methodologies, as threat actors…

  • Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints

    Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints A sophisticated backdoor malware known as Backdoor.WIN32.Buterat has emerged as a significant threat to enterprise networks, demonstrating advanced persistence techniques and stealth capabilities that enable attackers to maintain long-term unauthorized access to compromised systems. The malware has been identified targeting government and corporate environments through…

  • Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods

    Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods Microsoft is investigating a significant Exchange Online service disruption that is preventing users in North and South America from accessing their mailboxes. The ongoing incident, tracked under the ID EX1151485 in the admin center, impacts all methods of connecting to the email service.…

  • VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests)

    VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests) Oracle has released VirtualBox 7.2.2, a maintenance update for its open-source virtualization platform, focusing on improving stability and addressing a range of bugs. Released on September 10, 2025, this version comes as a follow-up to the major 7.2 release, which introduced significant new…

  • Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices

    Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices Apple has issued a warning regarding highly sophisticated “mercenary spyware” attacks targeting a select group of its users. The company’s threat notification system is designed to alert and support individuals who may have been targeted due to their profession or public profile, such as journalists,…

  • Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects

    Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects Microsoft has officially announced a multi-phase plan to deprecate VBScript in Windows, a move that signals a significant shift for developers, particularly those working with Visual Basic for Applications (VBA). The change, first detailed in May 2024, will gradually phase out the legacy…

  • Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

    Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges Microsoft has addressed four elevation of privilege vulnerabilities in its Windows Defender Firewall service, all rated as “Important” in severity. The security flaws were detailed in Microsoft’s September 9, 2025, security update release. If exploited, these vulnerabilities could allow an authenticated attacker to gain higher privileges on…

  • ACSC Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks

    ACSC Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a severe access control vulnerability in SonicWall products that is being actively exploited in attacks. The flaw, tracked as CVE-2024-40766, affects multiple generations of SonicWall firewalls and carries a critical CVSS score…

  • DDoS Mitigation Provider targeted In 1.5 Gpps 1.5 Billion Packets per Second DDoS Attack

    DDoS Mitigation Provider targeted In 1.5 Gpps 1.5 Billion Packets per Second DDoS Attack FastNetMon, a prominent provider of DDoS detection solutions, announced this week that it had identified and helped mitigate a record-breaking distributed denial-of-service (DDoS) attack. The assault targeted a major DDoS scrubbing vendor located in Western Europe, pushing packet-forwarding rates to an…

  • 1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon

    1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The malicious traffic was primarily a UDP…

  • Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities

    Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms “gross cybersecurity negligence,” accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption…

  • Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs

    Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations. The schemes reportedly extorted over 250 companies in…

  • Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code

    Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were disclosed on September 9, 2025, and affect various versions of the popular productivity suite. While Microsoft…

  • Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication

    Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication Sophos has resolved an authentication bypass vulnerability in its AP6 Series Wireless Access Points that could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security testing and has released a firmware update to address it. The security vulnerability allows an attacker…

  • HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

    HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns. The bug bounty platform announced the…

  • Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System

    Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System A critical vulnerability CVE-2025-42922 has been discovered in SAP NetWeaver that allows an authenticated, low-privileged attacker to execute arbitrary code and achieve a full system compromise. The flaw resides in the Deploy Web Service upload mechanism, where insufficient access control validation permits the…

  • Windows BitLocker Vulnerability Let Attackers Elevate Privileges

    Windows BitLocker Vulnerability Let Attackers Elevate Privileges Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry an “Important” severity rating. Both vulnerabilities could allow an authorized attacker to gain full SYSTEM privileges on a…

  • SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

    SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. Marketed on the dark web as a “spam-as-a-service” platform, SpamGPT automates nearly every…

  • Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials

    Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company’s core Salesforce environment was not impacted, the incident exposed sensitive information contained…

  • Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads

    Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved injecting malicious code designed to steal cryptocurrency from users. The compromised packages include…

  • Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

    Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM. The company confirmed that the incident was limited to its CRM platform and did…

  • New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability

    New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability A new technique to exploit a complex use-after-free (UAF) vulnerability in the Linux kernel successfully bypasses modern security mitigations to gain root privileges. The method targets CVE-2024-50264, a difficult-to-exploit race condition bug in the AF_VSOCK subsystem that was recognized with a Pwnie Award for its complexity. The vulnerability,…

  • U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China

    U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China U.S. federal authorities have launched an investigation into a sophisticated malware campaign that targeted sensitive trade negotiations between Washington and Beijing. The attack, which surfaced in July 2025, involved fraudulent emails purportedly sent by Representative John Moolenaar, chairman of the House Select Committee on Strategic…

  • How Microsoft Azure Storage Logs Aid Forensics Following a Security Breach

    How Microsoft Azure Storage Logs Aid Forensics Following a Security Breach After a security breach, forensic investigators work quickly to follow the attacker’s trail. Security experts have analyzed this situation and found that a key source of evidence is often overlooked: Microsoft Azure Storage logs. While frequently overlooked, these logs provide invaluable insights that can…

  • Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data

    Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data The notorious Lazarus APT group has evolved its attack methodology by incorporating the increasingly popular ClickFix social engineering technique to distribute malware and steal sensitive intelligence data from targeted organizations. This North Korean-linked threat actor, internally tracked as APT-Q-1 by security researchers, has demonstrated…

  • Australian Authorities Uncovered Activities and Careers of Ransomware Criminal Groups

    Australian Authorities Uncovered Activities and Careers of Ransomware Criminal Groups Ransomware has emerged as one of the most devastating cybercrime threats in the contemporary digital landscape, with criminal organizations operating sophisticated billion-dollar enterprises that target critical infrastructure across multiple nations. Between 2020 and 2022, ransomware groups conducted over 865 documented attacks against organizations in Australia,…

  • Atomic Stealer Disguised as Cracked Software Attacking macOS Users

    Atomic Stealer Disguised as Cracked Software Attacking macOS Users A sophisticated malware campaign targeting macOS users has emerged, exploiting the widespread desire for free software to deliver the notorious Atomic macOS Stealer (AMOS). This information-stealing malware masquerades as cracked versions of popular applications, tricking unsuspecting users into compromising their own systems while believing they are…

  • Critical Argo CD API Vulnerability Exposes Repository Credentials

    Critical Argo CD API Vulnerability Exposes Repository Credentials A critical vulnerability has been discovered in Argo CD that allows API tokens with limited permissions to access sensitive repository credentials. The flaw in the project details API endpoint exposes usernames and passwords, undermining the platform’s security model by granting access to secrets without explicit permissions. The…

  • Top 10 Best AI Penetration Testing Companies in 2025

    Top 10 Best AI Penetration Testing Companies in 2025 AI is no longer just a buzzword; it’s a fundamental part of business operations, from customer service chatbots to complex financial models. However, this adoption has created a new and specialized attack surface. Traditional penetration testing, which focuses on network and application vulnerabilities, is insufficient to…

  • 10 Best Cloud Penetration Testing Companies in 2025

    10 Best Cloud Penetration Testing Companies in 2025 As more businesses migrate their infrastructure to the cloud, cloud penetration testing has become a critical service. Unlike traditional network tests, cloud pentesting focuses on unique attack vectors such as misconfigured services, insecure APIs, and overly permissive IAM (Identity and Access Management) policies. In 2025, the best…

  • “GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload

    “GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload A sophisticated malware campaign, dubbed “GPUGate,” abuses Google Ads and GitHub’s repository structure to trick users into downloading malicious software. The Arctic Wolf Cybersecurity Operations Center, the attack chain uses a novel technique to evade security analysis by leveraging a computer’s Graphics Processing…

  • SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month

    SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month A new ransomware threat has emerged as one of 2025’s most prolific cybercriminal operations, with SafePay ransomware claiming attacks against 73 victim organizations in June alone, followed by 42 additional victims in July. This surge has positioned SafePay as a significant threat actor…

  • 143,000 Malware Files Attacked Android and iOS Device Users in Q2 2025

    143,000 Malware Files Attacked Android and iOS Device Users in Q2 2025 Cybercriminals unleashed a massive wave of mobile malware attacks during the second quarter of 2025, with security researchers detecting nearly 143,000 malicious installation packages targeting Android and iOS devices. This surge represents a significant escalation in mobile cyber threats, affecting millions of users…

  • New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing

    New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing A recent investigation has revealed that Microsoft employed China-based engineers to maintain and support SharePoint software, the same collaboration platform that was recently compromised by Chinese state-sponsored hackers. This revelation raises significant concerns about cybersecurity practices and potential insider threats within critical…

  • Kali Linux vs Parrot OS – Which Penetration Testing Platform is Most Suitable for Cybersecurity Professionals?

    Kali Linux vs Parrot OS – Which Penetration Testing Platform is Most Suitable for Cybersecurity Professionals? Penetration testing and ethical hacking have been dominated by specialized Linux distributions designed to provide security professionals with comprehensive toolsets for vulnerability assessment and network analysis. Among the most prominent options, Kali Linux and Parrot OS have emerged as leading contenders, each offering…

  • TAG-150 Hackers Deploying Self-Developed Malware Families to Attack Organizations

    TAG-150 Hackers Deploying Self-Developed Malware Families to Attack Organizations A sophisticated new threat actor designated TAG-150 has emerged as a significant cybersecurity concern, demonstrating rapid development capabilities and technical sophistication in deploying multiple self-developed malware families since March 2025. The group has successfully created and deployed CastleLoader, CastleBot, and their latest creation, CastleRAT, a previously…

  • Colombian Malware Weaponizing SWF and SVG to Bypass Detection

    Colombian Malware Weaponizing SWF and SVG to Bypass Detection A previously unseen malware campaign began circulating in early August 2025, through email attachments and web downloads, targeting users in Colombia and beyond. By leveraging two distinct vector-based file formats—Adobe Flash SWF and Scalable Vector Graphics (SVG)—the attackers crafted a multiphase operation that evaded traditional antivirus…

  • Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files

    Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files A new technique that allows attackers to read highly sensitive files on Windows systems, bypassing many of the modern security tools designed to prevent such breaches. A report from Workday’s Offensive Security team explains how, by reading data directly from a…

  • Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign

    Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign Cybercriminals are increasingly exploiting the trust organizations place in artificial intelligence platforms to conduct sophisticated phishing attacks, according to a new report from cybersecurity firm Cato Networks. The company’s Managed Detection and Response (MDR) service recently uncovered a campaign where threat actors leveraged…

  • Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges

    Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges A recently patched vulnerability in a core Windows driver could allow a local attacker to execute code with the highest system privileges, effectively taking full control of a target machine. The flaw, identified as CVE-2025-53149, is a heap-based buffer overflow discovered in the Kernel Streaming WOW…

  • CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks

    CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity vulnerability in the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, signaling that it is being actively exploited in attacks. The warning, issued on September 4, 2025, calls for urgent…

  • Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments

    Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish long-term footholds within global telecommunications and government networks. These actors, often identified under monikers such as Salt Typhoon and OPERATOR…

  • Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses

    Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses A sprawling network of illicit Internet Protocol Television (IPTV) services has been discovered, operating across more than 1,100 domains and in excess of 10,000 IP addresses. This sprawling infrastructure, which has remained active for several years, delivers unauthorized streams of premium content—including…

  • New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face

    New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source…

  • XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust

    XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust Emerging quietly in mid-2025, the XWorm backdoor has evolved into a deceptively sophisticated threat that preys on both user confidence and system conventions. Initial reports surfaced when organizations noted a sudden uptick in obscure .lnk-based phishing emails masquerading as benign documents. Security…

  • Threat Actors Attack PayPal Users in New Account Profile Set up Scam

    Threat Actors Attack PayPal Users in New Account Profile Set up Scam A sophisticated phishing campaign targeting PayPal’s massive user base has emerged, utilizing deceptive “Set up your account profile” emails to compromise user accounts through an ingenious secondary user addition scheme. The attack leverages advanced email spoofing techniques and psychological manipulation tactics to bypass…

  • Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack

    Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack In response to the discovery of actively exploited 0-day vulnerabilities, Google has released its September 2025 Android Security Bulletin, rolling out patch level 2025-09-05 to safeguard millions of devices. The bulletin details critical issues in both System and Kernel components, and emphasizes the…

  • CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks

    CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177).  This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor to manipulate linked device synchronization messages and force a target device to fetch and process content…

  • Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes

    Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes.  Originally marketed as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed by malicious operators…

  • New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files

    New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide. First detected in late August 2025, TinyLoader installs multiple secondary payloads—most notably RedLine Stealer and DCRat—transforming infected machines…

  • PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability

    PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities.  The flaw resides in the unsafe deserialization of HTTP header contents in both the msdeployagentservice and msdeploy.axd…

  • Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely

    Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code.  These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each carry a CVSS score of 9.8 and exploit buffer-corruption weaknesses to compromise device security. Key…

  • New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities

    New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities A sophisticated Windows-based keylogger known as TinkyWinkey began surfacing on underground forums in late June 2025, targeting enterprise and individual endpoints with unprecedented stealth. Unlike traditional keylogging tools that rely on simple hooks or user-mode processes, TinkyWinkey leverages dual components—a Windows service and an injected…

  • MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files

    MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files A critical flaw in the Mobile Security Framework (MobSF) has been discovered, allowing authenticated attackers to upload and execute malicious files by exploiting improper path validation.  The vulnerability, present in version 4.4.0 and patched in 4.4.1, underscores the importance of rigorous sanitization when handling user‐supplied…

  • HashiCorp Vault Vulnerability Let Attackers to Crash Servers

    HashiCorp Vault Vulnerability Let Attackers to Crash Servers A critical denial-of-service vulnerability in HashiCorp Vault could allow malicious actors to overwhelm servers with specially crafted JSON payloads, leading to excessive resource consumption and rendering Vault instances unresponsive.  Tracked as CVE-2025-6203 and published on August 28, 2025, the flaw affects both Vault Community and Enterprise editions…

  • Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps

    Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps A critical security vulnerability has emerged in Azure Active Directory (Azure AD) configurations that exposes sensitive application credentials, providing attackers with unprecedented access to cloud environments.  This vulnerability centers around the exposure of appsettings.json files containing ClientId and ClientSecret credentials, effectively handing…

  • Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users

    Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users Amazon’s threat intelligence team uncovered a sophisticated watering hole campaign in late August 2025, which is orchestrated by APT29, also known as Midnight Blizzard, a Russian Foreign Intelligence Service–linked actor. The operation relied on the compromise of legitimate websites to redirect unsuspecting visitors to malicious…

  • Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks

    Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks Infostealer malware, initially designed to indiscriminately harvest credentials from compromised hosts, has evolved into a potent weapon for state-sponsored Advanced Persistent Threat (APT) groups. Emerging in early 2023, families such as RedLine, Lumma, and StealC quickly proliferated across phishing campaigns and malicious downloads. These…

  • Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution

    Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution Critical vulnerabilities in Sitecore Experience Platform allow attackers to achieve complete system compromise through a sophisticated attack chain combining HTML cache poisoning with remote code execution capabilities. These flaws also enable attackers to enumerate cache keys and configuration details via the exposed ItemServices API, streamlining targeted exploitation.…

  • AI Waifu RAT Attacking Users With Novel Social Engineering Techniques

    AI Waifu RAT Attacking Users With Novel Social Engineering Techniques A sophisticated malware campaign targeting niche Large Language Model (LLM) role-playing communities has emerged, leveraging advanced social engineering tactics to distribute a dangerous Remote Access Trojan (RAT). The malware, dubbed “AI Waifu RAT” by security researchers, masquerades as an innovative AI character enhancement tool that…

  • Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents

    Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents Cybercriminals are exploiting Windows Defender Application Control (WDAC) policies to systematically disable Endpoint Detection and Response (EDR) agents, creating a dangerous blind spot in corporate security infrastructure. Real-world threat actors, including ransomware groups like Black Basta, have now adopted a sophisticated attack technique originally…

  • Top 10 Best Web Application Penetration Testing Companies in 2025

    Top 10 Best Web Application Penetration Testing Companies in 2025 Web application penetration testing in 2025 goes beyond a simple, one-time assessment. The top companies combine human expertise with automation and intelligent platforms to provide continuous, on-demand testing. The rise of Penetration Testing as a Service (PTaaS) and bug bounty programs reflects this evolution, offering…

  • Microsoft Confirms Recent Windows 11 24H2 Security Update Not Causing SSD/HDD Failures

    Microsoft Confirms Recent Windows 11 24H2 Security Update Not Causing SSD/HDD Failures Microsoft has officially addressed growing concerns among Windows 11 users, stating that its August 2025 security update for version 24H2 is not responsible for the scattered reports of SSD and HDD failures that have recently surfaced on social media and tech forums. The…

  • New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files

    New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files A new malware campaign, dubbed “Sindoor Dropper,” is targeting Linux systems using sophisticated spear-phishing techniques and a multi-stage infection chain. The campaign leverages lures themed around the recent India-Pakistan conflict, known as Operation Sindoor, to entice victims into executing malicious files. This activity’s standout…

  • Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed

    Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed A critical zero-day vulnerability in Citrix NetScaler products, identified as CVE-2025-6543, has been actively exploited by threat actors since at least May 2025, months before a patch was made available. While Citrix initially downplayed the flaw as a “memory overflow vulnerability leading to unintended…

  • Top 10 Attack Surface Management Software Solutions In 2025

    Top 10 Attack Surface Management Software Solutions In 2025 Attack Surface Management (ASM) is a proactive security discipline focused on continuously discovering, analyzing, and reducing an organization’s external-facing digital footprint. In 2025, with the proliferation of cloud services, remote work, and supply chain dependencies, an organization’s attack surface has grown exponentially. Top ASM solutions have…

  • Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K

    Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K A significant global effort to patch a critical zero-day remote code execution (RCE) vulnerability in Citrix NetScaler devices has seen the number of exposed systems drop from approximately 28,200 to 12,400 in just one week. Data from The Shadowserver Foundation, a…

  • WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

    WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems to compromise devices and access…

  • U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals

    U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals The U.S. Attorney’s Office for the District of New Mexico announced Thursday that federal authorities have executed a court-authorized seizure of two domain names and one affiliated blog associated with VerifTools, an online marketplace peddling counterfeit driver’s licenses, passports, and other state-…

  • Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach

    Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company’s third-party Salesforce systems. The incident, which occurred in June 2025, has…

  • NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads

    NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads NodeBB, a popular open-source forum platform, has been found vulnerable to a critical SQL injection flaw in version 4.3.0.  The flaw, tracked as CVE-2025-50979, resides in the search-categories API endpoint, allowing unauthenticated, remote attackers to inject both boolean-based blind and PostgreSQL error-based payloads.  Successful…

  • How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?

    How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR? Adversary-in-the-Middle (AiTM) attacks are among the most sophisticated and dangerous phishing techniques in the modern cybersecurity landscape. Unlike traditional phishing attacks that merely collect static credentials, AiTM attacks actively intercept and manipulate communications between users and legitimate services in real-time, enabling attackers to bypass multi-factor authentication (MFA)…

  • TransUnion Hack Exposes 4M+ Customers Personal Information

    TransUnion Hack Exposes 4M+ Customers Personal Information TransUnion, one of the nation’s three major credit reporting agencies, has disclosed a significant data breach that exposed the personal information of more than four million U.S. customers. The company is now alerting affected individuals about the cyber incident, which involved unauthorized access to data stored on a…

  • New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware

    New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware A sophisticated new Mac malware campaign has emerged, targeting users through a deceptive PDF conversion website that conceals a dangerous two-stage payload. The malware, dubbed “JSCoreRunner,” represents a significant evolution in macOS threats, demonstrating how cybercriminals are adapting their techniques to bypass Apple’s…

  • Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript

    Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript Nagios XI, a widely-deployed network monitoring solution, has addressed a critical cross-site scripting (XSS) vulnerability in its Graph Explorer feature that could enable remote attackers to execute malicious JavaScript code within users’ browsers.  The security flaw was patched in version 2024R2.1, released on August 12,…

  • PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input

    PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security.  The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a CVSS v4.0…

  • Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics

    Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501. The group has shifted from traditional on-premises ransomware to a more destructive, cloud-native strategy that involves data exfiltration and destruction, fundamentally changing the nature…

  • Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet

    Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide.  The flaw, designated CVE-2025-40779, allows remote attackers to crash DHCP services with just a single maliciously crafted packet, potentially disrupting network…

  • TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures

    TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions. First observed in 2018, this group has adopted an array of commodity remote access trojans (RATs) such as AsyncRAT,…

  • New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens

    New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens A sophisticated malware campaign has emerged, targeting Indonesia’s most vulnerable digital citizens through a calculated exploitation of trust in the nation’s pension fund system. The malicious operation impersonates PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN), the state-owned pension fund managing over $15.9 billion…

  • CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks

    CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775.  This memory overflow vulnerability enables remote code execution (RCE) and has been actively exploited by malicious cyber actors, prompting immediate inclusion in CISA’s Known Exploited Vulnerabilities…

  • China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled

    China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled China-based threat actor Mustang Panda has emerged as one of the most sophisticated cyber espionage groups operating in the current threat landscape, with operations dating back to at least 2014. This advanced persistent threat (APT) group has systematically targeted government entities, nonprofit organizations, religious institutions,…

  • Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances

    Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances A sophisticated data exfiltration campaign targeting corporate Salesforce instances has exposed sensitive information from multiple organizations through compromised OAuth tokens associated with the Salesloft Drift third-party application.  The threat actor, designated as UNC6395, systematically harvested credentials and sensitive data between August 8-18,…

  • Critical Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code

    Critical Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code Google has released an emergency security update for Chrome to address a critical use-after-free vulnerability (CVE-2025-9478) in the ANGLE graphics library that could allow attackers to execute arbitrary code on compromised systems.  The vulnerability affects Chrome versions prior to 139.0.7258.154/.155 across Windows, Mac, and…

  • New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access

    New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections. The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible…

  • DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment

    DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation’s entire Social Security dataset in an unsecured cloud environment.  Chief Data Officer…

  • Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs

    Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs A massive coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with threat actors deploying over 30,000 unique IP addresses to probe for vulnerabilities in Microsoft RD Web Access and RDP Web Client authentication portals.  The campaign represents one of the…

  • CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks

    CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks CISA has issued a critical alert regarding three newly identified vulnerabilities being actively exploited by threat actors. On August 25, 2025, CISA added these high-risk Common Vulnerabilities and Exposures (CVEs) to its Known Exploited Vulnerabilities (KEV) Catalog, signaling immediate concern for federal agencies…

  • Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection

    Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection A stealthy espionage campaign emerged in early 2025 targeting diplomats and government entities in Southeast Asia and beyond. At the heart of this operation lies STATICPLUGIN, a downloader meticulously disguised as a legitimate Adobe plugin update. Victims encountered a captive portal hijack that redirected…