Category: cyber-security-news

  • Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof

    Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof Android droppers have evolved from niche installers for heavyweight banking Trojans into universal delivery frameworks, capable of deploying even rudimentary spyware or SMS stealers. Initially, droppers served banking malware families that required elevated Accessibility permissions to harvest credentials. These small applications appeared…

  • Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database

    Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database A sophisticated campaign of cyber sabotage unfolded against Iran’s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids. Rather than targeting each ship individually—a logistical nightmare across international waters—the attackers infiltrated Fanava Group,…

  • Microsoft 365 Exchange Online Outage Blocks Email on Outlook Mobile App

    Microsoft 365 Exchange Online Outage Blocks Email on Outlook Mobile App Microsoft is investigating a significant service incident within Exchange Online, identified as EX1137017, which is preventing some users from sending or receiving emails through the Outlook mobile application. The issue, which remains ongoing, specifically impacts customers utilizing Hybrid Modern Authentication (HMA), a common configuration…

  • Hundreds of Thousands of Users’ Grok Chats Exposed in Google Search Results

    Hundreds of Thousands of Users’ Grok Chats Exposed in Google Search Results A significant data exposure has revealed hundreds of thousands of private user conversations with Elon Musk’s AI chatbot, Grok, in public search engine results. The incident, stemming from the platform’s “share” feature, has made sensitive user data freely accessible online, seemingly without the…

  • New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection

    New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection Phishing has always been about deceiving people. But in this campaign, the attackers weren’t only targeting users; they also attempted to manipulate AI-based defenses. This is an evolution of the Gmail phishing chain I documented last week. That campaign relied on urgency and redirects,…

  • Microsoft Confirms August 2025 Update Causes Severe Lag in Windows 11 24H2, and Windows 10

    Microsoft Confirms August 2025 Update Causes Severe Lag in Windows 11 24H2, and Windows 10 Microsoft has officially confirmed that its August 2025 security update is causing significant performance problems for users of NDI (Network Device Interface) technology. Content creators, broadcasters, and IT professionals who installed the update are reporting severe lag, stuttering, and choppy…

  • 20 Best Network Monitoring Tools in 2025

    20 Best Network Monitoring Tools in 2025 A network monitoring tool is software or hardware that helps businesses monitor their computer networks and learn more about their security, health, and performance. These tools record and examine network traffic, monitor network hardware, and give users immediate access to information on bandwidth usage, latency, packet loss, and…

  • CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks

    CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Apple’s iOS, iPadOS, and macOS operating systems that threat actors are actively exploiting.  The vulnerability, tracked as CVE-2025-43300, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling that…

  • Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts

    Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts Cybercriminals are increasingly leveraging Virtual Private Server (VPS) infrastructure to orchestrate sophisticated attacks against Software-as-a-Service (SaaS) platforms, exploiting the anonymity and clean reputation of these hosting services to bypass traditional security controls. A coordinated campaign identified in early 2025 demonstrated how threat actors systematically abuse VPS…

  • Chinese MURKY PANDA Attacking Government and Professional Services Entities

    Chinese MURKY PANDA Attacking Government and Professional Services Entities A sophisticated China-nexus threat actor designated MURKY PANDA has emerged as a significant cybersecurity concern, conducting extensive cyberespionage operations against government, technology, academic, legal, and professional services entities across North America since late 2024. This advanced persistent threat group demonstrates exceptional capabilities in cloud environment exploitation…

  • Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection

    Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection A method to silently exfiltrate Windows secrets and credentials, evading detection from most Endpoint Detection and Response (EDR) solutions. This technique allows attackers who have gained an initial foothold on a Windows machine to harvest credentials for lateral movement across a network without…

  • Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails

    Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails Microsoft has announced significant restrictions on email sending capabilities for organizations using default onmicrosoft.com domains, implementing a throttling system that limits external email delivery to 100 recipients per organization every 24 hours.  The policy change, announced through the Exchange Team Blog, aims to prevent spam abuse…

  • ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words

    ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words A critical vulnerability in OpenAI’s latest flagship model, ChatGPT-5, allows attackers to sidestep its advanced safety features using simple phrases. The flaw, dubbed “PROMISQROUTE” by researchers at Adversa AI, exploits the cost-saving architecture that major AI vendors use to manage the immense…

  • AI Systems Can Generate Working Exploits for Published CVEs in 10-15 Minutes

    AI Systems Can Generate Working Exploits for Published CVEs in 10-15 Minutes Artificial intelligence systems can automatically generate functional exploits for newly published Common Vulnerabilities and Exposures (CVEs) in just 10-15 minutes at approximately $1 per exploit.  This breakthrough significantly compresses the traditional “grace period” that defenders typically rely on to patch vulnerabilities before working…

  • Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes

    Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes The Anatsa banking trojan, also known as TeaBot, continues to evolve as one of the most sophisticated Android malware threats targeting financial institutions worldwide. First discovered in 2020, this malicious software has demonstrated remarkable persistence in infiltrating Android devices through the official Google…

  • New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor

    New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor Linux environments, long considered bastions of security, are facing a sophisticated new threat that challenges traditional assumptions about operating system safety. A recently discovered malware campaign exploits an ingenious attack vector that weaponizes RAR archive filenames to deliver the VShell backdoor, demonstrating how attackers are…

  • Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices

    Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices Cybersecurity researchers have identified a sophisticated social engineering technique called ClickFix that has been rapidly gaining traction among threat actors since early 2024. This deceptive attack method targets both Windows and macOS devices, tricking users into executing malicious commands through seemingly legitimate…

  • New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain

    New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain A sophisticated attack chain that combines MITM6 with NTLM relay techniques to achieve full Active Directory domain compromise.  The attack exploits Windows’ default IPv6 auto-configuration behavior, allowing attackers to escalate from network access to Domain Admin privileges in minutes.  Key Takeaways1.…

  • CISA Releases Four ICS Advisories Surrounding Vulnerabilities, and Exploits

    CISA Releases Four ICS Advisories Surrounding Vulnerabilities, and Exploits CISA issued four comprehensive Industrial Control Systems (ICS) advisories on August 19, 2025, highlighting serious vulnerabilities affecting critical infrastructure sectors including energy and manufacturing. These advisories detail exploitable vulnerabilities with CVSS scores ranging from 5.8 to 9.8, requiring immediate attention from system administrators and security professionals.…

  • Critical Apache Tika PDF Parser Vulnerability Allow Attackers to Access Sensitive Data

    Critical Apache Tika PDF Parser Vulnerability Allow Attackers to Access Sensitive Data A critical security vulnerability has been discovered in Apache Tika’s PDF parser module that could enable attackers to access sensitive data and trigger malicious requests to internal systems.  The flaw, designated as CVE-2025-54988, affects multiple versions of the widely used document parsing library…

  • Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine

    Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine A critical security vulnerability has been discovered in Microsoft’s VS Code Remote-SSH extension that allows attackers to execute malicious code on developers’ local machines through compromised remote servers.  Security researchers have demonstrated how this attack, dubbed “Vibe Hacking,” exploits the inherent trust…

  • New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials

    New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials A sophisticated malware campaign targeting macOS users has emerged between June and August 2025, successfully attempting to compromise over 300 customer environments through deceptive help websites. The malicious operation deploys SHAMOS, a variant of the notorious Atomic macOS Stealer (AMOS), developed by…

  • Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems

    Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems A sophisticated campaign uncovered where adversaries are exploiting CVE-2023-46604, a critical remote code execution vulnerability in Apache ActiveMQ, to compromise cloud-based Linux systems. In this case, attackers are patching the very vulnerability they exploited to maintain exclusive access and evade detection, demonstrating advanced…

  • Serial Hacker Jailed for Hacking and Defacing Organizations’ Websites

    Serial Hacker Jailed for Hacking and Defacing Organizations’ Websites A sophisticated cybercriminal operation targeting government institutions and private organizations across multiple continents has culminated in the sentencing of Al-Tahery Al-Mashriky, a 26-year-old hacker from Rotherham, South Yorkshire. The prolific attacker, who operated under multiple aliases within the extremist hacking collective “Yemen Cyber Army,” was sentenced…

  • Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data

    Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data A Chrome VPN extension with over 100,000 installations and verified badge status has been discovered operating as sophisticated spyware, continuously capturing user screenshots and exfiltrating sensitive data without consent. The extension, known as FreeVPN.One, masqueraded as a legitimate privacy tool while secretly…

  • CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories

    CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories A critical remote code execution (RCE) vulnerability in CodeRabbit’s production infrastructure that provided unauthorized access to over one million code repositories, including private ones.  The vulnerability, discovered in December 2024 and responsibly disclosed in January 2025, exploited the platform’s static analysis tool integration to…

  • Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware

    Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware Cybersecurity researchers have uncovered a sophisticated campaign by the Paper Werewolf threat actor group, also known as GOFFEE, targeting Russian organizations through the exploitation of critical vulnerabilities in WinRAR archiving software. The campaign, active since July 2025, demonstrates the group’s advanced capabilities in leveraging both known…

  • New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users

    New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users A sophisticated new cyberthreat campaign has emerged that combines impersonation of trusted news sources with deceptive security verification prompts to trick users into executing malicious commands on their systems. According to a Reddit post, the ClickFix attack masquerades as legitimate BBC news…

  • PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware

    PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware A sophisticated malware campaign has been identified, utilizing PipeMagic, a highly modular backdoor deployed by the financially motivated threat actor Storm-2460.  This advanced malware masquerades as a legitimate open-source ChatGPT Desktop Application while exploiting the zero-day vulnerability CVE-2025-29824 in Windows Common Log File…

  • SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security

    SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security Enterprise security strategies have evolved dramatically to address modern threats, yet SSH keys—critical cryptographic credentials that provide direct access to mission-critical systems—remain largely ungoverned and poorly managed across organizations. Despite their fundamental role in securing remote access to…

  • Crypto Developers Attacked With Malicious npm Packages to Steal Login Details

    Crypto Developers Attacked With Malicious npm Packages to Steal Login Details A sophisticated new threat campaign has emerged targeting cryptocurrency developers through malicious npm packages designed to steal sensitive credentials and wallet information. The attack, dubbed “Solana-Scan” by researchers, specifically targets the Solana cryptocurrency ecosystem by masquerading as legitimate software development kits and scanning tools.…

  • CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks

    CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks CISA has issued a critical warning regarding a high-severity OS command injection vulnerability in Trend Micro Apex One Management Console that threat actors are actively exploiting in the wild.  The vulnerability, tracked as CVE-2025-54948 and classified under CWE-78, poses significant risks…

  • HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM

    HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM Workday, a leading provider of enterprise cloud applications for finance and human resources, has confirmed it was the target of a sophisticated social engineering campaign that resulted in a data breach via a third-party Customer Relationship Management (CRM) platform. The company emphasized that the…

  • Hundreds of TeslaMate Installations Leaking Sensitive Vehicle Data in Real Time

    Hundreds of TeslaMate Installations Leaking Sensitive Vehicle Data in Real Time A cybersecurity researcher has discovered that hundreds of publicly accessible TeslaMate installations are exposing sensitive Tesla vehicle data without authentication, revealing GPS coordinates, charging patterns, and personal driving habits to anyone on the internet.  The vulnerability stems from misconfigured deployments of the popular open-source…

  • Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption

    Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption A significant security update rolled out by Microsoft with the Windows 11 24H2 (KB5063878) release is causing widespread issues for users, with reports surfacing that the update can render SSDs and HDDs inaccessible and may potentially corrupt user data. Last week’s Patch Tuesday…

  • North Korean Hackers Stealthy Linux Malware Leaked Online

    North Korean Hackers Stealthy Linux Malware Leaked Online In a significant breach of both cybersecurity defenses and secrecy, a trove of sensitive hacking tools and technical documentation, believed to originate from a North Korean threat actor, has recently been leaked online. The dump, revealed through an extensive article in Phrack Magazine, includes advanced exploit tactics,…

  • Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext

    Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext A threat actor operating under the alias “Chucky_BF” has posted a concerning advertisement on a well-known cybercrime forum, claiming to possess and sell a “Global PayPal Credential Dump 2025” containing over 15.8 million email and plaintext password pairs.  The dataset, measuring…

  • New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD

    New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD A newly discovered zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution allows attackers to bypass security measures, execute malicious code, and trigger a BSOD system crash, according to the Ashes Cybersecurity research. The vulnerability resides in a core…

  • CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure

    CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure CISA in collaboration with international partners, has released comprehensive guidance, titled “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators,” to strengthen cybersecurity defenses across critical infrastructure sectors. The document emphasizes the critical importance of maintaining accurate operational technology (OT)…

  • Google Awards $250,000 Bounty for Chrome RCE Vulnerability Discovery

    Google Awards $250,000 Bounty for Chrome RCE Vulnerability Discovery Google has awarded a record-breaking $250,000 bounty to security researcher “Micky” for discovering a critical remote code execution vulnerability in Chrome’s browser architecture.  The vulnerability allowed malicious websites to escape Chrome’s sandbox protection and execute arbitrary code on victim systems.  Key Takeaways1.Google paid researcher “Micky” a…

  • Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code

    Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code A critical vulnerability in the Microsoft Web Deploy tool could allow authenticated attackers to execute remote code on affected systems.  The vulnerability, tracked as CVE-2025-53772, was disclosed on August 12, 2025, and carries a CVSS score of 8.8, indicating high severity. The flaw stems from…

  • New Gmail Phishing Attack With Weaponized Login Flow Steals Credentials

    New Gmail Phishing Attack With Weaponized Login Flow Steals Credentials A sophisticated new phishing campaign targeting Gmail users through a multi-layered attack that uses legitimate Microsoft Dynamics infrastructure to bypass security measures and steal login credentials. The attack begins with deceptive “New Voice Notification” emails that appear to come from legitimate voicemail services. These emails…

  • Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) – Technical Details Revealed

    Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) – Technical Details Revealed Cybersecurity researchers from watchTowr Labs have published a comprehensive technical analysis of a critical pre-authentication command injection vulnerability affecting Fortinet FortiSIEM systems, designated as CVE-2025-25256. The vulnerability carries a maximum CVSS score of 9.8 and has already been exploited in the wild, making it one…

  • Palo Alto Networks Released A Mega Malware Analysis Tutorials Useful for Every Malware Analyst

    Palo Alto Networks Released A Mega Malware Analysis Tutorials Useful for Every Malware Analyst Palo Alto Networks has published an extensive malware analysis tutorial detailing the dissection of a sophisticated .NET-based threat that delivers the Remcos remote access trojan (RAT). The malware’s emergence highlights a trend in which threat actors increasingly abuse legitimate development environments…

  • Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection

    Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection The cybersecurity landscape faces a new sophisticated threat as the Crypto24 ransomware group demonstrates an alarming evolution in attack methodology, seamlessly blending legitimate administrative tools with custom-developed malware to execute precision strikes against high-value targets. This emerging ransomware operation has successfully compromised organizations across…

  • Google Requires Crypto App Developers to Have License or Certification From Relevant Authorities

    Google Requires Crypto App Developers to Have License or Certification From Relevant Authorities Google Play has implemented comprehensive licensing requirements for cryptocurrency exchanges and software wallets, fundamentally reshaping the mobile app ecosystem for digital asset services. The policy mandates that developers seeking to publish cryptocurrency applications must obtain specific licenses and certifications from relevant financial…

  • Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS

    Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS A sophisticated threat campaign has emerged that leverages CrossC2, an unofficial extension tool that expands Cobalt Strike’s notorious capabilities beyond Windows systems to target Linux and macOS environments. Between September and December 2024, cybersecurity incidents involving this cross-platform malware have…

  • HexStrike AI Connects ChatGPT, Claude, Copilot with 150+ Security Tools like Burp Suite and Nmap

    HexStrike AI Connects ChatGPT, Claude, Copilot with 150+ Security Tools like Burp Suite and Nmap A new AI tool named HexStrike AI has been launched, designed to bridge the gap between large language models (LLMs) and practical cybersecurity operations. The latest release, v6.0, equips AI agents like OpenAI’s GPT, Anthropic’s Claude, and GitHub’s Copilot with…

  • Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks

    Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks Critical security flaw CVE-2025-20217 allows unauthenticated attackers to trigger denial-of-service conditions in Cisco’s widely deployed firewall systems Cisco has disclosed a high-severity vulnerability in its Secure Firewall Threat Defense (FTD) Software that could allow remote attackers to cause denial-of-service conditions through the Snort 3…

  • 10 Best Deception Tools in 2025

    10 Best Deception Tools in 2025 The goal of deception technology, which uses some of the best deception tools, is to trick attackers by dispersing a variety of traps and dummy assets throughout a system’s infrastructure to mimic real assets. There is always a possibility that cybercriminals will breach your network, regardless of how effective…

  • CVE-2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware

    CVE-2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware A zero-day vulnerability in WinRAR allows malware to be deployed on unsuspecting users’ systems, highlighting the ongoing threats to popular software. Tracked as CVE-2025-8088, this path traversal flaw affects the Windows version of the widely used file archiving tool, enabling attackers to execute arbitrary…

  • Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot

    Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot A sophisticated new malware campaign targeting Windows systems has emerged, employing a multi-stage framework dubbed “PS1Bot” that combines PowerShell and C# components to conduct extensive information theft operations. The malware represents a significant evolution in attack methodologies, utilizing modular architecture and in-memory execution techniques…

  • ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns

    ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns The notorious ShinyHunters cybercriminal group has emerged from a year-long hiatus with a sophisticated new wave of attacks targeting Salesforce platforms across major organizations, including high-profile victims like Google. This resurgence marks a significant tactical evolution for the financially motivated threat actors, who have traditionally…

  • “AI-Induced Destruction” – New Attack Vector Where Helpful Tools Become Accidental Weapons

    “AI-Induced Destruction” – New Attack Vector Where Helpful Tools Become Accidental Weapons Artificial intelligence coding assistants, designed to boost developer productivity, are inadvertently causing massive system destruction.  Researchers report a significant spike in what they term “AI-induced destruction” incidents, where helpful AI tools become accidental weapons against the very systems they’re meant to improve. Key…

  • Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025

    Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025 The cybersecurity landscape experienced an unprecedented escalation in digital threats during the first half of 2025, with Web Distributed Denial of Service (DDoS) attacks surging by 39% compared to the second half of 2024. The second quarter alone witnessed a staggering…

  • What Is Out-of-Bounds Read and Write Vulnerability?

    What Is Out-of-Bounds Read and Write Vulnerability? Out-of-bounds read and write vulnerabilities represent critical security vulnerabilities that occur when software accesses memory locations beyond the allocated boundaries of data structures such as arrays, buffers, or other memory regions. These vulnerabilities can lead to information disclosure, system crashes, and in severe cases, arbitrary code execution that…

  • VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store

    VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store A sophisticated cybercriminal organization known as VexTrio has been orchestrating a massive fraud empire through deceptive CAPTCHA robots and malicious applications distributed across Google Play and the App Store. This criminal network, operating for over 15 years, has…

  • Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data

    Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data A sophisticated cybercriminal operation disguised as a Ukrainian Web3 development team has been targeting job seekers through weaponized NPM packages, security researchers warn. The attack leverages fake interview processes to trick unsuspecting candidates into downloading and executing malicious code that steals cryptocurrency…

  • What is MCP Server – How it is Powering AI-Driven Cyber Defense

    What is MCP Server – How it is Powering AI-Driven Cyber Defense MCP (Model Control Plane) Server is a centralized platform that orchestrates, manages, and secures the lifecycle of AI models deployed across an organization’s infrastructure. By providing integration, management, and real-time monitoring of models, MCP servers enable enterprises to defend against sophisticated, AI-powered cyberattacks.…

  • New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch

    New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch A critical zero-click NTLM credential leakage vulnerability that circumvents Microsoft’s recent patch for CVE-2025-24054.  The newly identified flaw, assigned CVE-2025-50154, allows attackers to extract NTLM hashes from fully patched Windows systems without any user interaction, demonstrating that Microsoft’s April security update was incomplete. Key Takeaways1.…

  • FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control

    FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control A high-severity authentication bypass vulnerability affecting multiple Fortinet security products, including FortiOS, FortiProxy, and FortiPAM systems.  The flaw, designated as CVE-2024-26009 with a CVSS score of 7.9, enables unauthenticated attackers to seize complete control of managed devices through exploitation of the FortiGate-to-FortiManager…

  • Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code

    Multiple Chrome High-Severity Vulnerabilities Let Attackers Execute Arbitrary Code Google Chrome has released a critical security update addressing six vulnerabilities that could potentially enable arbitrary code execution on affected systems.  The stable channel update to version 139.0.7258.127/.128 for Windows and Mac, and 139.0.7258.127 for Linux, contains patches for multiple high-severity security flaws that pose significant…

  • Reddit to Block Internet Archive as AI Companies Have Scraped Data From Wayback Machine

    Reddit to Block Internet Archive as AI Companies Have Scraped Data From Wayback Machine Reddit has announced plans to significantly restrict the Internet Archive’s Wayback Machine from indexing its platform, citing concerns that AI companies have been exploiting the archival service to circumvent Reddit’s data protection policies.  The move represents another escalation in Reddit’s ongoing…

  • Apache bRPC Vulnerability Allows Attackers to Crash the Service via Network

    Apache bRPC Vulnerability Allows Attackers to Crash the Service via Network A severe vulnerability in Apache bRPC has been discovered that allows attackers to crash services through network exploitation, affecting all versions prior to 1.14.1.  The vulnerability, identified as CVE-2025-54472 with “important” severity classification, stems from unlimited memory allocation in the Redis protocol parser component.…

  • Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations

    Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations Wikipedia has suffered a significant legal defeat in its attempt to avoid being classified under the UK’s stringent Online Safety Act regulations. The High Court ruled against the Wikimedia Foundation and a Wikipedia user, known only as “BLN,” who challenged the Secretary of State’s…

  • Scattered Spider With New Telegram Channel List Organizations It Attacked

    Scattered Spider With New Telegram Channel List Organizations It Attacked In early August 2025, a previously quiet cybercrime collective known as Scattered Spider resurfaced with a striking new Telegram channel that aggregates proof of its intrusions and data exfiltration operations. The channel name fuses ShinyHunters, Scattered Spider, and Lapsus$, signaling a collaboration—or at least a…

  • DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files

    DarkBit Hackers Attacking VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files A newly discovered ransomware campaign has targeted enterprise VMware ESXi environments with military precision, deploying custom-built encryption tools that specifically hunt for virtual machine disk files across VMFS datastores.  Security researchers have successfully reverse-engineered the attack methodology and developed breakthrough decryption techniques,…

  • INE Named to Training Industry’s 2025 Top 20 Online Learning Library List

    INE Named to Training Industry’s 2025 Top 20 Online Learning Library List Cary, United States, August 11th, 2025, CyberNewsWire Hands-on cybersecurity and IT training leader recognized for innovation in practical, work-ready education INE has been selected for Training Industry’s 2025 Top 20 Online Learning Library Companies list, recognizing the company’s leadership in cybersecurity training, cybersecurity certifications,…

  • WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware

    WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware A critical zero-day vulnerability has been identified in WinRAR that cybercriminals are actively exploiting through sophisticated phishing campaigns to distribute RomCom malware.  The flaw, designated as CVE-2025-8088, represents a significant security threat with a CVSS v3.1 score of 8.4, enabling attackers to execute arbitrary code on…

  • GPT-5 Jailbreaked With Echo Chamber and Storytelling Attacks

    GPT-5 Jailbreaked With Echo Chamber and Storytelling Attacks Researchers have compromised OpenAI’s latest GPT-5 model using sophisticated echo chamber and storytelling attack vectors, revealing critical vulnerabilities in the company’s most advanced AI system.  The breakthrough demonstrates how adversarial prompt engineering can bypass even the most robust safety mechanisms, raising serious concerns about enterprise deployment readiness…

  • 7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code

    7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code A newly disclosed security vulnerability in the popular 7-Zip file compression software has raised significant concerns in the cybersecurity community. CVE-2025-55188, discovered and reported by security researcher Landon on August 9, 2025, allows attackers to perform arbitrary file writes during archive extraction, potentially leading to…

  • New ‘Win-DoS’ Zero-Click Vulnerabilities Turns Windows Server/Endpoint, Domain Controllers Into DDoS Botnet

    New ‘Win-DoS’ Zero-Click Vulnerabilities Turns Windows Server/Endpoint, Domain Controllers Into DDoS Botnet LAS VEGAS — At the DEF CON 33 security conference, researchers Yair and Shahak Morag of SafeBreach Labs unveiled a new class of denial-of-service (DoS) attacks, dubbed the “Win-DoS Epidemic.” The duo presented their findings, which include four new Windows DoS vulnerabilities and…

  • Google Confirms Data Breach – Notifying Users Affected By the Cyberattack

    Google Confirms Data Breach – Notifying Users Affected By the Cyberattack Tech giant Google has officially acknowledged a significant data breach affecting its corporate Salesforce database, with the company completing email notifications to affected users as of August 8, 2025. Google revealed on August 5 that one of its corporate Salesforce instances was compromised in…

  • Darknet Market Escrow Systems is Vulnerable to Administrator Exit Scams

    Darknet Market Escrow Systems is Vulnerable to Administrator Exit Scams Darknet markets, operating beyond the reach of traditional payment processors and legal systems, rely on escrow systems to secure cryptocurrency transactions between buyers and vendors.  These systems, using multisignature wallets and automated release mechanisms, aim to ensure transaction security and facilitate dispute resolution. However, vulnerabilities…

  • ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive

    ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive A critical vulnerability in OpenAI’s ChatGPT Connectors feature allows attackers to exfiltrate sensitive data from connected Google Drive accounts without any user interaction beyond the initial file sharing. The attack, dubbed “AgentFlayer,” represents a new class of zero-click exploits targeting AI-powered enterprise tools. The…

  • New Linux Kernel Vulnerability Directly Exploited from Chrome Renderer Sandbox Via Rare Linux Socket Feature

    New Linux Kernel Vulnerability Directly Exploited from Chrome Renderer Sandbox Via Rare Linux Socket Feature A critical vulnerability in the Linux kernel, identified as CVE-2025-38236, has exposed a flaw that could allow attackers to escalate privileges from within the Chrome renderer sandbox on Linux systems.  Google Project Zero researcher Jann Horn discovered the bug affects…

  • Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets

    Threat Actors Using Typosquatted PyPI Packages to Steal Cryptocurrency from Bittensor Wallets A sophisticated cryptocurrency theft campaign has emerged targeting the Bittensor ecosystem through malicious Python packages distributed via the Python Package Index (PyPI). The attack leverages typosquatting techniques to deceive developers and users into installing compromised versions of legitimate Bittensor packages, ultimately resulting in…

  • Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email

    Huge Wave of Malicious Efimer Malicious Script Attack Users via WordPress Sites, Malicious Torrents, and Email A sophisticated malware campaign dubbed “Efimer” has emerged as a significant threat to cryptocurrency users worldwide, employing a multi-vector approach that combines compromised WordPress websites, malicious torrents, and deceptive email campaigns. First detected in October 2024, this ClipBanker-type Trojan…

  • 5,000+ Fake Online Pharmacies Websites Selling Counterfeit Medicines

    5,000+ Fake Online Pharmacies Websites Selling Counterfeit Medicines A sophisticated cybercriminal enterprise operating over 5,000 fraudulent online pharmacy websites has been exposed in a comprehensive investigation, revealing one of the largest pharmaceutical fraud networks ever documented. This massive operation, orchestrated by a single threat actor group, targets vulnerable individuals seeking prescription medications through deceptive digital…

  • BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data

    BitUnlocker – Multiple 0-days to Bypass BitLocker and Extract All Protected Data Researchers have disclosed a series of critical zero-day vulnerabilities that completely bypass Windows BitLocker encryption, allowing attackers with physical access to extract all protected data from encrypted devices in a matter of minutes. The research, conducted by Alon Leviev and Netanel Ben Simon…

  • DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation

    DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation A sophisticated information-stealing malware campaign has emerged, utilizing advanced obfuscation techniques and multiple infection vectors to evade traditional security controls. The DarkCloud Stealer, first documented in recent threat intelligence reports, represents a significant evolution in cybercriminal tactics, employing a complex multi-stage delivery mechanism that begins with…

  • ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials

    ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials A sophisticated technique dubbed “ECScape” that allows malicious containers running on Amazon Elastic Container Service (ECS) to steal AWS credentials from other containers sharing the same EC2 instance. The discovery highlights critical isolation weaknesses in multi-tenant ECS deployments and underscores the…

  • Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims

    Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims A sophisticated cybercriminal operation known as GreedyBear has orchestrated one of the most extensive cryptocurrency theft campaigns to date, deploying over 650 malicious tools across multiple attack vectors to steal more than $1 million from unsuspecting victims. Unlike traditional threat groups that…

  • ChatGPT-5 Released: What’s New With the Next-Generation AI Agent

    ChatGPT-5 Released: What’s New With the Next-Generation AI Agent OpenAI has officially launched ChatGPT-5, a new generation of its AI agent that introduces a sophisticated, unified system designed to be faster, more intelligent, and significantly more useful for real-world applications. This release marks a significant evolution from its predecessors, offering a suite of models tailored…

  • CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday

    CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday CISA has issued an emergency advisory directing all Federal Civilian Executive Branch agencies to mitigate a newly disclosed Microsoft Exchange urgently hybrid-joined vulnerability, tracked as CVE-2025-53786, by 9:00 AM EDT on Monday, August 11, 2025. The flaw enables attackers who have already…

  • Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands

    Flipper Zero ‘DarkWeb’ Firmware Bypasses Rolling Code Security on Major Vehicle Brands A new and custom firmware for the popular Flipper Zero multi-tool device is reportedly capable of bypassing the rolling code security systems used in most modern vehicles, potentially putting millions of cars at risk of theft. Demonstrations by the YouTube channel “Talking Sasquach”…

  • HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code

    HashiCorp Vault 0-Day Vulnerabilities Let Attackers Execute Remote Code Security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault in early August 2025, the widely adopted secrets management solution. These flaws, spanning authentication bypasses, policy enforcement inconsistencies, and audit-log abuse, create end-to-end attack paths that culminate in remote code execution (RCE) on Vault…

  • 1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure

    1.2 Million Healthcare Devices and Systems Data Leaked Online – Patient Records at Risk of Exposure Over 1.2 million internet-connected healthcare devices and systems with exposure that endanger patient data shown in new research by European cybersecurity company Modat. Global findings showing Top 10 Regions (most results are across Europe, the USA, and South Africa):  United States…

  • HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover

    HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme ambiguity about where one request ends and the next begins, enabling attackers to manipulate web…

  • Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices

    Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices A sophisticated attack method exploits Google’s Gemini AI assistant through seemingly innocent calendar invitations and emails.  The attack, dubbed “Targeted Promptware Attacks,” demonstrates how indirect prompt injection can compromise users’ digital privacy and even control physical devices in their…

  • Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

    Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and Incident Response (DFIR) team, demonstrates how cybercriminals are weaponizing trusted business applications to…

  • Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild

    Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild Critical command injection remote code execution (RCE) vulnerabilities in Trend Micro Apex One Management Console are currently being actively exploited by threat actors.  The company confirmed observing at least one instance of attempted exploitation in production environments, prompting the immediate release of…

  • Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data

    Threat Actors Weaponizing RMM Tools to Take Control of The Machine and Steal Data Cybercriminals are increasingly exploiting Remote Monitoring and Management (RMM) software to gain unauthorized access to corporate systems, with a sophisticated new attack campaign demonstrating how legitimate IT tools can become powerful weapons in the wrong hands. This emerging threat leverages the…

  • CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

    CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS CISA released two urgent Industrial Control Systems (ICS) advisories on August 5, 2025, addressing significant security vulnerabilities in critical manufacturing and energy sector systems.  These advisories detail exploitable flaws that could compromise industrial operations and potentially disrupt essential services across multiple sectors. Key Takeaways1. CISA…

  • Bing Search Poisoned to Deliver Bumblebee Malware for ‘ManageEngine OpManager’ Searches

    Bing Search Poisoned to Deliver Bumblebee Malware for ‘ManageEngine OpManager’ Searches A sophisticated search engine optimization (SEO) poisoning campaign that exploited Bing search results to distribute Bumblebee malware, ultimately leading to devastating Akira ransomware attacks. The campaign, active throughout July 2025, specifically targeted users searching for legitimate IT management software, demonstrating how threat actors continue…

  • Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks

    Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks A wide range of vulnerabilities affects millions of Dell laptops used by government agencies, cybersecurity professionals, and enterprises worldwide. The vulnerabilities, collectively dubbed “ReVault,” target the Broadcom BCM5820X security chip embedded in Dell’s ControlVault3 firmware, creating opportunities for attackers to steal passwords, biometric…

  • Fashion Giant Chanel Hacked in Wave of Salesforce Attacks

    Fashion Giant Chanel Hacked in Wave of Salesforce Attacks French luxury fashion house Chanel has become the latest victim in a sophisticated cybercrime campaign targeting major corporations through their Salesforce customer relationship management systems. The company confirmed on July 25, 2025, that unauthorized threat actors had breached a database containing personal information of U.S. customers…

  • Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction

    Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction Google released its August 2025 Android Security Bulletin on August 4, revealing a critical vulnerability that poses significant risks to Android device users worldwide.  The most severe flaw, designated CVE-2025-48530, affects the core System component and could enable remote code execution without requiring…

  • New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data

    New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data A sophisticated new Android malware campaign has emerged targeting Indian banking customers through convincing impersonations of popular financial applications. The malicious software masquerades as legitimate apps from major Indian financial institutions, including SBI Card, Axis Bank, Indusind Bank, ICICI, and…

  • NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control

    NVIDIA Triton Vulnerability Chain Let Attackers Take Over AI Server Control A critical vulnerability chain in NVIDIA’s Triton Inference Server that allows unauthenticated attackers to achieve complete remote code execution (RCE) and gain full control over AI servers.  The vulnerability chain, identified as CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334, exploits the server’s Python backend through a sophisticated…