Category: cyber-security-news

  • WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution

    WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution A sophisticated method to bypass Web Application Firewall (WAF) protections using HTTP Parameter Pollution techniques combined with JavaScript injection.  The research, conducted by Bruno Mendes across 17 different WAF configurations from major vendors including AWS, Google Cloud, Azure, and Cloudflare, revealed alarming…

  • AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

    AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as CVE-2025-54135 with a high severity score of 8.6, affects all Cursor IDE versions prior to…

  • NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

    NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the @nestjs/devtools-integration package and allows malicious websites to execute arbitrary code on developers’ local machines…

  • Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online

    Microsoft PlayReady DRM Used by Netflix, Amazon, and Disney+ Leaked Online A significant security breach has compromised Microsoft’s PlayReady Digital Rights Management (DRM) system, exposing critical certificates that protect premium streaming content across major platforms including Netflix, Amazon Prime Video, and Disney+. The leak, which surfaced on GitHub through an account named “Widevineleak,” has triggered…

  • Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines

    Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines The cybersecurity landscape continues to evolve as threat actors develop increasingly sophisticated methods to compromise Windows systems. A new ransomware variant known as Interlock has emerged as a significant threat, leveraging the deceptive ClickFix social engineering technique to execute malicious commands on victim…

  • APT37 Hackers Weaponizes JPEG Files to Attack Windows Systems Leveraging “mspaint.exe”

    APT37 Hackers Weaponizes JPEG Files to Attack Windows Systems Leveraging “mspaint.exe” A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems, signaling a dangerous evolution in evasion tactics and fileless attack techniques. Security researchers at Genians Security…

  • New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access

    New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access A sophisticated Linux backdoor dubbed Plague has emerged as an unprecedented threat to enterprise security, evading detection across all major antivirus engines while establishing persistent SSH access through manipulation of core authentication mechanisms. Discovered by cybersecurity researchers at Nextron Systems, this malware represents…

  • SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware

    SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware A suspected zero-day vulnerability in SonicWall firewall devices that the Akira ransomware group is actively exploiting. The flaw allows attackers to gain initial access to corporate networks through SonicWall’s SSL VPN feature, leading to subsequent ransomware deployment. In late July 2025, security researchers observed a…

  • Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers

    Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages across npm and PyPI ecosystems. Between January and July 2025, this state-sponsored operation…

  • SafePay Ransomware Infected 260+ Victims Across Multiple Countries

    SafePay Ransomware Infected 260+ Victims Across Multiple Countries A new ransomware threat has emerged as one of the most aggressive cybercriminal operations of 2025, with SafePay ransomware claiming responsibility for over 265 successful attacks spanning multiple continents. The group, which first appeared in September 2024 with limited activity targeting just over 20 victims, has dramatically…

  • Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS

    Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse of RansomHub, previously the most prolific ransomware-as-a-service operation. This transition has reshaped the cybercriminal ecosystem, with Qilin capitalizing on the…

  • LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One

    LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One LockBit ransomware operators have adopted an increasingly sophisticated approach to evade detection by leveraging DLL sideloading techniques that exploit the inherent trust placed in legitimate applications. This stealthy method involves tricking legitimate, digitally signed applications into loading malicious Dynamic Link Libraries…

  • Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research

    Search Engines are Indexing ChatGPT Conversations! – Here is our OSINT Research ChatGPT shared conversations are being indexed by major search engines, effectively turning private exchanges into publicly discoverable content accessible to millions of users worldwide. The issue first came to light through investigative reporting by Fast Company, which revealed that nearly 4,500 ChatGPT conversations…

  • Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections

    Hackers Weaponizing Free Trials of EDR to Disable Existing EDR Protections A sophisticated attack technique was uncovered where cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems.  This method, dubbed BYOEDR (Bring Your Own EDR), represents a concerning evolution in defense evasion tactics that leverage…

  • Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity

    Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity Palo Alto Networks’ Unit 42 threat research team has introduced a groundbreaking systematic approach to threat actor attribution, addressing longstanding challenges in cybersecurity intelligence analysis. The Unit 42 Attribution Framework, unveiled on July 31, 2025, transforms what has traditionally been considered “more art…

  • Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations

    Threat Actors Embed Malicious RMM Tools to Gain Silent Initial Access to Organizations A sophisticated cyber campaign leveraging legitimate Remote Monitoring and Management (RMM) tools has emerged as a significant threat to European organizations, particularly those in France and Luxembourg. Since November 2024, threat actors have been deploying carefully crafted PDF documents containing embedded links…

  • Navigating APTs – Singapore’s Cautious Response to State-Linked Cyber Attacks

    Navigating APTs – Singapore’s Cautious Response to State-Linked Cyber Attacks Singapore’s cybersecurity landscape faced a significant challenge in July 2025 when Coordinating Minister K. Shanmugam disclosed that the nation was actively defending against UNC3886, a highly sophisticated Advanced Persistent Threat (APT) group targeting critical infrastructure. The revelation, announced during the Cyber Security Agency’s 10th anniversary…

  • APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks

    APT Hackers Attacking Maritime and Shipping Industry to Launch Ransomware Attacks The maritime industry, which facilitates approximately 90% of global trade, has emerged as a critical battleground for advanced persistent threat (APT) groups deploying sophisticated ransomware campaigns. This surge in cyber warfare represents a paradigm shift where state-sponsored hackers and financially motivated threat actors are…

  • Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released

    Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.  The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP’s…

  • OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters

    OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters A critical security vulnerability has been identified in OAuth2-Proxy, a widely-used reverse proxy that provides authentication services for Google, Azure, OpenID Connect, and numerous other identity providers.  The vulnerability, designated as CVE-2025-54576, enables attackers to bypass authentication mechanisms by manipulating query parameters in crafted URLs, potentially…

  • Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature

    Gunra Ransomware New Linux Variant Runs Up To 100 Encryption Threads With New Partial Encryption Feature A sophisticated new Linux variant of Gunra ransomware has emerged, marking a significant escalation in the threat group’s cross-platform capabilities since its initial discovery in April 2025. The ransomware, which drew inspiration from the notorious Conti ransomware techniques, has…

  • Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures

    Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into their attack arsenal, enabling them…

  • ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks

    ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks ChatGPT agents demonstrate the ability to autonomously bypass Cloudflare’s CAPTCHA verification systems, specifically the ubiquitous “I am not a robot” checkbox.  This development, first documented in a viral Reddit post on the r/OpenAI community, showcases the evolving sophistication of AI agents in navigating web…

  • Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

    Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.  In April 2025, cybersecurity firm Darktrace successfully detected…

  • Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches

    Enterprise LLMs Under Risk: How Simple Prompts Can Lead to Major Breaches Enterprise applications integrating Large Language Models (LLMs) face unprecedented security vulnerabilities that can be exploited through deceptively simple prompt injection attacks.  Recent security assessments reveal that attackers can bypass authentication systems, extract sensitive data, and execute unauthorized commands using nothing more than carefully…

  • Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks

    Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks Microsoft has unveiled a comprehensive defense-in-depth strategy to combat indirect prompt injection attacks, one of the most significant security threats facing large language model (LLM) implementations in enterprise environments.  The company’s multi-layered approach combines preventative techniques, detection tools, and impact mitigation strategies to protect against attackers…

  • Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web

    Lionishackers Threat Actors Exfiltrating and Selling Corporate Databases on Dark Web A financially motivated threat actor known as Lionishackers has emerged as a significant player in the illicit marketplace for corporate data in recent months. Leveraging opportunistic targeting and a preference for Asian-based victims, the group employs automated SQL injection tools to breach database servers,…

  • 10 Best Virtual Machine (VM) Monitoring Tools in 2025

    10 Best Virtual Machine (VM) Monitoring Tools in 2025 VM (Virtual Machine) monitoring tools are essential for maintaining the performance, availability, and security of virtualized environments. These tools provide real-time visibility into VM health and performance, enabling administrators to track key metrics such as CPU usage, memory utilization, disk I/O, and network traffic. VM monitoring…

  • CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks

    CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical vulnerability in PaperCut NG/MF print management software that threat actors are actively exploiting in ransomware campaigns.  The vulnerability, tracked as CVE-2023-2533, represents a significant security risk to organizations worldwide using the affected software versions. Key Takeaways1. CVE-2023-2533…

  • Apple’s New Containerization Feature Allows Kali Linux Integration on macOS

    Apple’s New Containerization Feature Allows Kali Linux Integration on macOS Apple quietly slipped a game-changing developer feature into its WWDC 25 announcements: a native containerization stack that lets Macs run Open Container Initiative (OCI) images inside ultra-lightweight virtual machines. In practice, that means you can launch a full Kali Linux environment on macOS “Sequoia” 15…

  • 10 Best Anti-Phishing Tools in 2025

    10 Best Anti-Phishing Tools in 2025 Anti-phishing tools are essential cybersecurity solutions designed to detect and prevent phishing attacks. These tools identify and block malicious emails, websites, and messages that attempt to deceive users into disclosing sensitive information such as passwords, credit card numbers, and personal details. They use advanced algorithms, machine learning, and threat…

  • Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC

    Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC A critical macOS vulnerability enables attackers to bypass Transparency, Consent, and Control (TCC) protections and steal sensitive user data, including files from protected directories and Apple Intelligence caches.  The vulnerability, dubbed “Sploitlight,” exploits Spotlight plugins to access normally protected information without user consent,…

  • LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access

    LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access A serious security vulnerability has been discovered in LG Innotek’s LNV5110R camera model that could allow cybercriminals to gain complete administrative control over affected devices.  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on July 24, 2025, warning of a remotely exploitable flaw…

  • 10 Best Cloud Monitoring Tools in 2025

    10 Best Cloud Monitoring Tools in 2025 Cloud monitoring tools are essential for maintaining cloud-based services and applications’ performance, availability, and security. These tools provide real-time visibility into cloud infrastructure, enabling monitoring metrics such as resource utilization, application performance, and network traffic. Cloud monitoring tools help identify and resolve issues quickly by offering customizable dashboards…

  • Arizona Woman Sentenced for Helping North Korean IT Workers by Operating Laptop Farm

    Arizona Woman Sentenced for Helping North Korean IT Workers by Operating Laptop Farm An Arizona woman received a significant federal prison sentence for orchestrating a sophisticated cybercrime operation that enabled North Korean Information Technology (IT) workers to infiltrate hundreds of American companies while generating millions in revenue for the Democratic People’s Republic of Korea (DPRK). …

  • Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely

    Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely Multiple critical security vulnerabilities affecting Salesforce’s Tableau Server that could allow attackers to execute remote code, bypass authorization controls, and access sensitive production databases.  The vulnerabilities, revealed through a security advisory published on June 26, 2025, impact Tableau Server versions before 2025.1.3, before 2024.2.12, and before…

  • Weekly Cybersecurity News Recap : Sharepoint 0-day, Vmware Exploitation, Threats and Cyber Attacks

    Weekly Cybersecurity News Recap : Sharepoint 0-day, Vmware Exploitation, Threats and Cyber Attacks Welcome to this week’s Cybersecurity Recap. We’re looking at important updates from July 21-27, 2025, in the world of digital threats and defenses. This week has seen significant developments that highlight the ongoing risks of cyber attacks and the need for constant…

  • Allianz Life Insurance Data Breach – 1.4 Million Customers Data at Risk

    Allianz Life Insurance Data Breach – 1.4 Million Customers Data at Risk Major U.S. insurance provider Allianz Life Insurance Company confirmed on Saturday that hackers compromised the personal information of the “majority” of its 1.4 million customers following a sophisticated cyberattack on July 16, 2025. The breach, disclosed in a mandatory filing with Maine’s attorney…

  • 15 Best Docker Monitoring Tools in 2025

    15 Best Docker Monitoring Tools in 2025 Docker monitoring is the process of keeping tabs on the functionality, state, and resource usage of Docker containers as well as the entire Docker ecosystem. With the help of the well-known containerization technology Docker, programmers may bundle their apps and their dependencies into independent, lightweight containers that can…

  • 20 Best SNMP Monitoring Tools in 2025

    20 Best SNMP Monitoring Tools in 2025 SNMP (Simple Network Management Protocol) monitoring tools are essential for managing and monitoring network devices. They collect and organize information from various network devices, such as routers, switches, servers, and printers. These tools provide real-time data on device performance, network traffic, and operational status, enabling network administrators to…

  • Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware

    Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company’s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June…

  • Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored

    Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored BreachForums, the notorious cybercrime discussion board that vanished from the clearnet after a law-enforcement seizure in, quietly re-opened this week under its original administrators and with the entire historical archive of user accounts, posts, and private messages intact. The unexpected reemergence has alarmed…

  • Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities

    Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities Microsoft Corp. is investigating whether a leak from its Microsoft Active Protections Program (MAPP) enabled Chinese state-sponsored hackers to exploit critical SharePoint vulnerabilities before patches were fully deployed, according to a Bloomberg report. The investigation comes as cyber espionage attacks have compromised…

  • New VOIP-Based Botnet Attacking Routers Configured With Default Password

    New VOIP-Based Botnet Attacking Routers Configured With Default Password A sophisticated global botnet campaign targeting VOIP-enabled routers and devices configured with default credentials.  The discovery began when analysts noticed an unusual cluster of malicious IP addresses concentrated in rural New Mexico, leading to the identification of approximately 500 compromised devices worldwide. Key Takeaways1. Hackers are…

  • Web-to-App Funnels: Pros And Cons

    Web-to-App Funnels: Pros And Cons In today’s mobile-first world, companies often struggle to bridge the gap between their websites and mobile apps. This is where web-to-app funnels come into play. These funnels are designed to guide users from a web touchpoint (such as an ad or landing page) into a mobile application, where deeper engagement…

  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide

    Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide Microsoft is currently facing an outage that affects the Microsoft 365 Admin Center, preventing administrators from accessing essential management tools. The issue, which emerged prominently on July 24, 2025, has persisted into the following day, marking the second such incident this week and raising concerns…

  • 10 Best API Monitoring Tools in 2025

    10 Best API Monitoring Tools in 2025 API monitoring tools ensure the performance, availability, and reliability of application programming interfaces (APIs) that connect different software systems. These tools continuously track and analyze API requests and responses to detect slow response times, errors, and downtime. By providing real-time insights, alerts, and detailed analytics, API monitoring tools…

  • Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials

    Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials Attackers are weaponizing India’s appetite for mobile banking by circulating counterfeit Android apps that mimic the interfaces and icons of public-sector and private banks. Surfacing in telemetry logs on 3 April 2025, the impostors travel through smishing texts, QR codes and search-engine poisoning,…

  • Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations

    Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations A sophisticated espionage campaign dubbed “Fire Ant” demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure.  Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint security solutions. …

  • New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer

    New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer A newly uncovered campaign is exploiting gamers’ enthusiasm for off-beat indie titles to plant credential-stealing malware on machines. Branded installers for nonexistent games such as “Baruda Quest,” “Warstorm Fire,” and “Dire Talon” are pushed through slick YouTube trailers and Discord download links…

  • xonPlus Launches Real-Time Breach Alerting Platform For Enterprise Credential Exposure

    xonPlus Launches Real-Time Breach Alerting Platform For Enterprise Credential Exposure Chennai, India, July 25th, 2025, CyberNewsWire xonPlus, a real-time digital risk alerting system, officially launches today to help security teams detect credential exposures before attackers exploit them. The platform detects data breaches and alerts teams and systems to respond instantly. Built by the team behind…

  • Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware

    Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying Warlock ransomware in compromised environments.  The vulnerabilities affect on-premises SharePoint Server 2016, 2019, and Subscription Edition, with exploitation…

  • Windows 11 Gets New Black Screen of Death With Auto Recovery Tool

    Windows 11 Gets New Black Screen of Death With Auto Recovery Tool Microsoft has unveiled significant improvements to Windows 11’s system recovery capabilities, introducing a redesigned Black Screen of Death restart screen alongside an automated Quick Machine Recovery (QMR) tool.  These enhancements are part of the broader Windows Resiliency Initiative (WRI), designed to minimize downtime…

  • CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild

    CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.  The vulnerabilities, designated as CVE-2025-49704 and CVE-2025-49706, pose significant risks to organizations running on-premises SharePoint servers and have been added to…

  • Kali Linux Unveils Two New Tools to Boost Wi-Fi Performance for Raspberry Pi Users

    Kali Linux Unveils Two New Tools to Boost Wi-Fi Performance for Raspberry Pi Users Kali Linux has announced the release of two groundbreaking packages that significantly enhance wireless penetration testing capabilities for Raspberry Pi users. The new brcmfmac-nexmon-dkms and firmware-nexmon packages, introduced in Kali Linux 2025.1, enable the onboard Wi-Fi interface on supported Raspberry Pi…

  • Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild

    Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild Microsoft has confirmed that Chinese state-sponsored threat actors are actively exploiting critical zero-day vulnerabilities in on-premises SharePoint servers, prompting urgent security warnings for organizations worldwide.  The tech giant’s Security Response Center reported coordinated attacks targeting internet-facing SharePoint installations using newly disclosed vulnerabilities that enable…

  • Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code Google has released an urgent security update for its Chrome browser, addressing three critical vulnerabilities that could enable attackers to execute arbitrary code on users’ systems. The Stable channel update to version 138.0.7204.168/.169 for Windows and Mac, and 138.0.7204.168 for Linux, is currently rolling out to…

  • GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments

    GLOBAL GROUP’s Golang Ransomware Attacks Windows, Linux, and macOS Environments A sophisticated new ransomware threat has emerged from the cybercriminal underground, targeting organizations across multiple operating systems with advanced cross-platform capabilities. In June 2025, a ransomware actor operating under the alias “Dollar Dollar Dollar” introduced GLOBAL GROUP on the Ramp4u cybercrime forum, marketing it as…

  • Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support

    Wireshark 4.4.8 Released With Bug Fixes and Updated Protocol Support Wireshark Foundation has announced the availability of Wireshark 4.4.8, the latest maintenance release of the world’s most widely used network-protocol analyzer. Although the update does not introduce brand-new protocols, it delivers a focused package of stability improvements, expanded dissector capabilities, and quality-of-life fixes that will…

  • Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack

    Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack Christian Dior Couture, the luxury fashion house owned by Louis Vuitton, has begun notifying customers of a major cybersecurity incident that exposed sensitive personal information of clients.  The breach, discovered in May 2025, involved unauthorized access to customer databases containing personal data including names, addresses,…

  • Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

    Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors are actively exploiting two zero-day vulnerabilities in on-premises SharePoint servers, designated CVE-2025-53770 and CVE-2025-53771. The…

  • Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT

    Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT A financially motivated threat group dubbed Greedy Sponge has been systematically targeting Mexican financial institutions and organizations since 2021 with a heavily modified version of the AllaKore remote access trojan (RAT). The campaign represents a sophisticated evolution of cybercriminal tactics, combining traditional social…

  • Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

    Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.  The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key Takeaways1. Active zero-day attacks…

  • New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator

    New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator A sophisticated new attack technique compromises Fast IDentity Online (FIDO) key authentication by exploiting cross-device sign-in features.  The PoisonSeed attack group has developed a method to downgrade FIDO key protections through adversary-in-the-middle (AitM) phishing campaigns that trick users into…

  • PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability

    PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. Dubbed “NVIDIAScape” and tracked as CVE-2025-23266, this flaw carries a maximum CVSS score of 9.0, representing one of the most severe threats to cloud-based AI…

  • New 7-Zip Vulnerability Enables Weaponized RAR5 File to Crash Your System

    New 7-Zip Vulnerability Enables Weaponized RAR5 File to Crash Your System A critical memory corruption vulnerability in the popular file archiver 7-Zip has been discovered that allows attackers to trigger denial of service conditions by crafting malicious RAR5 archive files. The vulnerability, tracked as CVE-2025-53816 and designated GHSL-2025-058, affects all versions of 7-Zip prior to…

  • Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More

    Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More It’s been a busy seven days for security alerts. Google is addressing another actively exploited zero-day in Chrome, and VMware has rolled out key patches for its own set of vulnerabilities. We’ll also break down the methods behind a new FortiWeb…

  • SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access

    SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed “ToolShell,” enabling attackers to gain complete remote control over vulnerable systems without authentication. Eye Security, a Dutch cybersecurity firm, identified the active exploitation…

  • Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards

    Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.  The vulnerabilities, identified as CVE-2025-6023 and CVE-2025-6197, affect multiple versions of Grafana, including 12.0.x, 11.6.x, 11.5.x, 11.4.x, and 11.3.x branches.  Both security flaws…

  • New Veeam Themed Phishing Attack Using Weaponized Wav File to Attack users

    New Veeam Themed Phishing Attack Using Weaponized Wav File to Attack users A sophisticated phishing campaign targeting organizations has emerged, exploiting the trusted reputation of Veeam Software through weaponized WAV audio files delivered via email. The attack represents an evolution in social engineering tactics, combining traditional phishing techniques with audio-based deception to bypass conventional security…

  • Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware

    Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware A sophisticated Chinese threat actor campaign has emerged as one of the most persistent malware distribution operations targeting Chinese-speaking communities worldwide. Since June 2023, this ongoing campaign has established an extensive infrastructure comprising more than 2,800 malicious domains specifically designed to deliver Windows-targeted malware…

  • Snake Keylogger Evades Windows Defender and Scheduled Tasks to Harvest Login Credentials

    Snake Keylogger Evades Windows Defender and Scheduled Tasks to Harvest Login Credentials A sophisticated phishing campaign targeting Turkish defense and aerospace enterprises has emerged, delivering a highly evasive variant of the Snake Keylogger malware through fraudulent emails impersonating TUSAŞ (Turkish Aerospace Industries). The malicious campaign distributes files disguised as contractual documents, specifically using the filename…

  • CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of the SQL injection flaw in cyberattacks worldwide. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s FortiWeb web application firewall…

  • Lumma Infostealer Steal All Data Stored in Browsers and Selling Them in Underground Markets as Logs

    Lumma Infostealer Steal All Data Stored in Browsers and Selling Them in Underground Markets as Logs The cybersecurity landscape continues to face significant threats from sophisticated information stealers, with Lumma emerging as one of the most prevalent and dangerous malware families targeting both consumer and enterprise environments. This malicious software systematically harvests enormous volumes of…

  • Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices

    Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices Google has filed a lawsuit in New York federal court against the operators of the BadBox 2.0 botnet, marking a significant escalation in the tech giant’s fight against cybercriminal networks. The malware campaign represents the largest known botnet of internet-connected television devices, compromising…

  • Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools

    Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools The notorious Russian cyberespionage group Fancy Bear, also known as APT28, has intensified its operations against governments and military entities worldwide using an arsenal of sophisticated new tools and techniques. Active since 2007, this state-sponsored threat actor has established itself as one of the…

  • New Wave of Crypto-Hijacking Infects 3,500+ Websites

    New Wave of Crypto-Hijacking Infects 3,500+ Websites A stealth Monero-mining campaign has quietly compromised more than 3,500 websites by embedding an innocuous-looking JavaScript file called karma.js. The operation leverages WebAssembly, Web Workers, and WebSockets to siphon CPU cycles while keeping resource usage low enough to avoid user suspicion. Cside.dev analysts first noted the anomaly after…

  • Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike

    Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike A sophisticated Chinese state-sponsored cyber espionage campaign has emerged targeting Taiwan’s critical semiconductor industry, employing weaponized Cobalt Strike beacons and advanced social engineering tactics. Between March and June 2025, multiple threat actors launched coordinated attacks against semiconductor manufacturing, design, and supply chain organizations, reflecting China’s…

  • Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier

    Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier Last week, Ukraine’s Main Intelligence Directorate (GUR) orchestrated a sophisticated cyberattack against Gaskar Integration, a leading Russian drone manufacturer. The operation began with reconnaissance of the company’s public-facing infrastructure, where threat actors identified vulnerable remote desktop services and outdated VPN gateways. Leveraging a zero-day in a…

  • Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role

    Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role A critical vulnerability in Microsoft Entra ID allows attackers to escalate privileges to the Global Administrator role through the exploitation of first-party applications.  The vulnerability, reported to Microsoft Security Response Center (MSRC) in January 2025, affects organizations using hybrid Active Directory environments with…

  • H2Miner Attacking Linux, Windows, and Containers to Mine Monero

    H2Miner Attacking Linux, Windows, and Containers to Mine Monero The H2Miner botnet, first observed in late 2019, has resurfaced with an expanded arsenal that blurs the line between cryptojacking and ransomware. The latest campaign leverages inexpensive virtual private servers (VPS) and a grab-bag of commodity malware to compromise Linux hosts, Windows workstations, and container workloads…

  • Researchers Uncover on How Hacktivist Groups Gaining Attention and Selecting Targets

    Researchers Uncover on How Hacktivist Groups Gaining Attention and Selecting Targets The global hacktivist landscape has undergone a dramatic transformation since 2022, evolving from primarily ideologically motivated actors into a complex ecosystem where attention-seeking behavior and monetization strategies drive operational decisions. This shift has fundamentally altered how these groups select targets and conduct campaigns, creating…

  • Cisco Unified Intelligence Center Vulnerability Allows Remote Attackers to Upload Arbitrary Files

    Cisco Unified Intelligence Center Vulnerability Allows Remote Attackers to Upload Arbitrary Files A critical vulnerability in Cisco’s Unified Intelligence Center (CUIC) web-based management interface has been classified with high severity, allowing authenticated remote attackers with Report Designer privileges to upload arbitrary files to affected systems.  Tracked as CVE-2025-20274 and assigned a CVSS Base Score of…

  • Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript

    Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Threat actors are quietly turning Scalable Vector Graphics (SVG) files into precision-guided malware. In a surge of phishing campaigns, seemingly innocuous .svg attachments slip past secure email gateways because mail filters regard them as static images. Once the recipient merely previews the file, hidden JavaScript executes…

  • Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025

    Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025 The cybersecurity landscape in June 2025 was dominated by a surge of Infostealer malware masked as cracked or key-generated software, catapulting this tactic to the month’s most prevalent attack vector. Fraudulent download portals advertising “free” versions of popular tools lured victims through…

  • SonicWall SMA Devices 0-Day RCE Vulnerability Exploited to Deploy OVERSTEP Ransomware

    SonicWall SMA Devices 0-Day RCE Vulnerability Exploited to Deploy OVERSTEP Ransomware SonicWall’s end-of-life SMA 100 series appliances are again on the front line after investigators unearthed a covert campaign that couples a suspected zero-day remote-code-execution flaw with a sophisticated backdoor called OVERSTEP. The operation, attributed to the financially motivated group UNC6148, first steals administrator credentials…

  • Microsoft Congratulates MSRC’s Most Valuable Security Researchers

    Microsoft Congratulates MSRC’s Most Valuable Security Researchers Microsoft has officially announced its 2025 Most Valuable Security Researchers, recognizing the top 100 security researchers worldwide who have made significant contributions to protecting Microsoft customers through the Microsoft Security Response Center (MSRC) program.  The recognition is based on a comprehensive point system that evaluates researchers’ valid vulnerability…

  • Microsoft Details on How Security Copilot in Intune and Entra Helps Security and IT Teams

    Microsoft Details on How Security Copilot in Intune and Entra Helps Security and IT Teams Microsoft has announced significant enhancements to its AI-powered security platform, marking the general availability of Microsoft Security Copilot capabilities within Microsoft Intune and Microsoft Entra. This development represents a critical milestone in the evolution of enterprise security management, as organizations…

  • Dark 101 Ransomware With Weaponized .NET Binary Disables Recovery Mode and Task Manager

    Dark 101 Ransomware With Weaponized .NET Binary Disables Recovery Mode and Task Manager A sophisticated new ransomware strain has emerged in the cybersecurity landscape, demonstrating advanced evasion techniques and destructive capabilities that pose significant risks to organizations worldwide. The Dark 101 ransomware represents a concerning evolution in malware design, utilizing an obfuscated .NET binary to…

  • Authorities Dismantled “Diskstation” Ransomware Attacking Synology NAS Devices Worldwide

    Authorities Dismantled “Diskstation” Ransomware Attacking Synology NAS Devices Worldwide Italian State Police, in collaboration with French and Romanian law enforcement agencies, have successfully dismantled the dangerous “Diskstation” ransomware group that specifically targeted Synology Network-Attached Storage (NAS) devices across multiple countries.  The operation, coordinated through EUROPOL, resulted in the arrest of several Romanian nationals and exposed…

  • Albemarle County Hit By Ransomware Attack – Hackers Accessed Residents Personal Details

    Albemarle County Hit By Ransomware Attack – Hackers Accessed Residents Personal Details Albemarle County, Virginia, has fallen victim to a sophisticated ransomware attack that compromised the personal information of county residents, local government employees, and public school staff. The cybercriminal operation successfully infiltrated the county’s network infrastructure, forcing officials to launch an extensive incident response…

  • Node.js Vulnerabilities Exposes Windows App to Path Traversal and HashDoS Attacks

    Node.js Vulnerabilities Exposes Windows App to Path Traversal and HashDoS Attacks The Node.js project has released critical security updates across multiple release lines to address two high-severity vulnerabilities affecting Windows applications and V8 engine implementations.  Security releases are now available for Node.js versions 20.x, 22.x, and 24.x, with patches addressing a path traversal bypass and…

  • Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000

    Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000 A threat actor using the handle “zeroplayer” advertised a previously unknown remote-code-execution (RCE) exploit for WinRAR on an underground forum.  The post, titled “WINRAR RCE 0DAY – 80,000$,” claims the flaw works “fully on the latest version of WinRAR and below,” is not…

  • 10 Best Cloud VPN Providers – 2025

    10 Best Cloud VPN Providers – 2025 Cloud VPNs have become essential for both businesses and individuals seeking secure, private, and reliable internet access in 2025. As cyber threats evolve and remote work becomes the norm, choosing the right cloud VPN provider is crucial for safeguarding sensitive data and ensuring seamless connectivity across the globe.…

  • Cybersecurity Isn’t Just For Experts Anymore: Why You Should Care

    Cybersecurity Isn’t Just For Experts Anymore: Why You Should Care Let’s face it cybersecurity used to sound like a topic only for programmers in hoodies or government agencies trying to fend off foreign hackers. But in the current day and age, everyone is affected. If you are a gamer, a business owner, or casually browsing…

  • 11 Best Cloud Access Security Broker Software (CASB) – 2025

    11 Best Cloud Access Security Broker Software (CASB) – 2025 As organizations accelerate digital transformation, the need for robust cloud security has never been greater. Cloud Access Security Broker (CASB) software stands at the forefront, acting as the critical gatekeeper between users and cloud service providers. With the explosion of SaaS, IaaS, and PaaS platforms,…

  • Top 10 Cyber Attack Maps to See Digital Threats In 2025

    Top 10 Cyber Attack Maps to See Digital Threats In 2025 In 2025, the digital threat landscape is more dynamic and complex than ever. Cyber attacks are escalating in frequency, sophistication, and impact, targeting businesses, governments, and individuals worldwide. Real-time visibility into these threats is essential for proactive defense, strategic planning, and rapid incident response.…

  • Meta’s Llama Firewall Bypassed Using Prompt Injection Vulnerability

    Meta’s Llama Firewall Bypassed Using Prompt Injection Vulnerability Trendyol’s application security team uncovered a series of bypasses that render Meta’s Llama Firewall protections unreliable against sophisticated prompt injection attacks. The findings raise fresh concerns about the readiness of existing LLM security measures and underscore the urgent need for more robust defenses as enterprises increasingly embed…

  • OpenAI is to Launch a AI Web Browser in Coming Weeks

    OpenAI is to Launch a AI Web Browser in Coming Weeks OpenAI is reportedly preparing to release an artificial intelligence-enhanced web browser within the coming weeks, marking the company’s latest expansion beyond its popular ChatGPT platform. The new browser will feature integrated AI agent capabilities designed to autonomously handle various online tasks, positioning OpenAI as…

  • WordPress GravityForms Plugin Hacked to Include Malicious Code

    WordPress GravityForms Plugin Hacked to Include Malicious Code A sophisticated supply chain attack has compromised the official GravityForms WordPress plugin, allowing attackers to inject malicious code that enables remote code execution on affected websites. The attack, discovered on July 11, 2025, represents a significant security breach affecting one of WordPress’s most popular form-building plugins, with…