Category: Cyber Security
-
Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments
Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish long-term footholds within global telecommunications and government networks. These actors, often identified under monikers such as Salt Typhoon and OPERATOR…
-
Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses
Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses A sprawling network of illicit Internet Protocol Television (IPTV) services has been discovered, operating across more than 1,100 domains and in excess of 10,000 IP addresses. This sprawling infrastructure, which has remained active for several years, delivers unauthorized streams of premium content—including…
-
New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face
New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source…
-
XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust
XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust Emerging quietly in mid-2025, the XWorm backdoor has evolved into a deceptively sophisticated threat that preys on both user confidence and system conventions. Initial reports surfaced when organizations noted a sudden uptick in obscure .lnk-based phishing emails masquerading as benign documents. Security…
-
Threat Actors Attack PayPal Users in New Account Profile Set up Scam
Threat Actors Attack PayPal Users in New Account Profile Set up Scam A sophisticated phishing campaign targeting PayPal’s massive user base has emerged, utilizing deceptive “Set up your account profile” emails to compromise user accounts through an ingenious secondary user addition scheme. The attack leverages advanced email spoofing techniques and psychological manipulation tactics to bypass…
-
CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks
CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177). This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor to manipulate linked device synchronization messages and force a target device to fetch and process content…
-
Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack
Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack In response to the discovery of actively exploited 0-day vulnerabilities, Google has released its September 2025 Android Security Bulletin, rolling out patch level 2025-09-05 to safeguard millions of devices. The bulletin details critical issues in both System and Kernel components, and emphasizes the…
-
Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes
Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes. Originally marketed as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed by malicious operators…
-
New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files
New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide. First detected in late August 2025, TinyLoader installs multiple secondary payloads—most notably RedLine Stealer and DCRat—transforming infected machines…
-
PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability
PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities. The flaw resides in the unsafe deserialization of HTTP header contents in both the msdeployagentservice and msdeploy.axd…
-
MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files
MobSF Security Testing Tool Vulnerability Let Attackers Upload Malicious Files A critical flaw in the Mobile Security Framework (MobSF) has been discovered, allowing authenticated attackers to upload and execute malicious files by exploiting improper path validation. The vulnerability, present in version 4.4.0 and patched in 4.4.1, underscores the importance of rigorous sanitization when handling user‐supplied…
-
HashiCorp Vault Vulnerability Let Attackers to Crash Servers
HashiCorp Vault Vulnerability Let Attackers to Crash Servers A critical denial-of-service vulnerability in HashiCorp Vault could allow malicious actors to overwhelm servers with specially crafted JSON payloads, leading to excessive resource consumption and rendering Vault instances unresponsive. Tracked as CVE-2025-6203 and published on August 28, 2025, the flaw affects both Vault Community and Enterprise editions…
-
Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely
Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code. These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each carry a CVSS score of 9.8 and exploit buffer-corruption weaknesses to compromise device security. Key…
-
New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities
New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities A sophisticated Windows-based keylogger known as TinkyWinkey began surfacing on underground forums in late June 2025, targeting enterprise and individual endpoints with unprecedented stealth. Unlike traditional keylogging tools that rely on simple hooks or user-mode processes, TinkyWinkey leverages dual components—a Windows service and an injected…
-
Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps
Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps A critical security vulnerability has emerged in Azure Active Directory (Azure AD) configurations that exposes sensitive application credentials, providing attackers with unprecedented access to cloud environments. This vulnerability centers around the exposure of appsettings.json files containing ClientId and ClientSecret credentials, effectively handing…
-
Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users
Amazon Dismantles Russian APT 29 Infrastructure Used to Attack Users Amazon’s threat intelligence team uncovered a sophisticated watering hole campaign in late August 2025, which is orchestrated by APT29, also known as Midnight Blizzard, a Russian Foreign Intelligence Service–linked actor. The operation relied on the compromise of legitimate websites to redirect unsuspecting visitors to malicious…
-
Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks
Infostealer Malware is Being Exploited by APT Groups for Targeted Attacks Infostealer malware, initially designed to indiscriminately harvest credentials from compromised hosts, has evolved into a potent weapon for state-sponsored Advanced Persistent Threat (APT) groups. Emerging in early 2023, families such as RedLine, Lumma, and StealC quickly proliferated across phishing campaigns and malicious downloads. These…
-
Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution
Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution Critical vulnerabilities in Sitecore Experience Platform allow attackers to achieve complete system compromise through a sophisticated attack chain combining HTML cache poisoning with remote code execution capabilities. These flaws also enable attackers to enumerate cache keys and configuration details via the exposed ItemServices API, streamlining targeted exploitation.…
-
AI Waifu RAT Attacking Users With Novel Social Engineering Techniques
AI Waifu RAT Attacking Users With Novel Social Engineering Techniques A sophisticated malware campaign targeting niche Large Language Model (LLM) role-playing communities has emerged, leveraging advanced social engineering tactics to distribute a dangerous Remote Access Trojan (RAT). The malware, dubbed “AI Waifu RAT” by security researchers, masquerades as an innovative AI character enhancement tool that…
-
Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents
Hackers Leverage Windows Defender Application Control Policies to Disable EDR Agents Cybercriminals are exploiting Windows Defender Application Control (WDAC) policies to systematically disable Endpoint Detection and Response (EDR) agents, creating a dangerous blind spot in corporate security infrastructure. Real-world threat actors, including ransomware groups like Black Basta, have now adopted a sophisticated attack technique originally…
-
New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files
New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files A new malware campaign, dubbed “Sindoor Dropper,” is targeting Linux systems using sophisticated spear-phishing techniques and a multi-stage infection chain. The campaign leverages lures themed around the recent India-Pakistan conflict, known as Operation Sindoor, to entice victims into executing malicious files. This activity’s standout…
-
Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed
Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed A critical zero-day vulnerability in Citrix NetScaler products, identified as CVE-2025-6543, has been actively exploited by threat actors since at least May 2025, months before a patch was made available. While Citrix initially downplayed the flaw as a “memory overflow vulnerability leading to unintended…
-
Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K
Citrix Netscaler 0-day RCE Vulnerability Patched – Vulnerable Instances Reduced from 28.2K to 12.4K A significant global effort to patch a critical zero-day remote code execution (RCE) vulnerability in Citrix NetScaler devices has seen the number of exposed systems drop from approximately 28,200 to 12,400 in just one week. Data from The Shadowserver Foundation, a…
-
WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users
WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems to compromise devices and access…
-
U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals
U.S. Government Seizes Online Marketplaces Used to Sell Fraudulent Identity Documents to Cybercriminals The U.S. Attorney’s Office for the District of New Mexico announced Thursday that federal authorities have executed a court-authorized seizure of two domain names and one affiliated blog associated with VerifTools, an online marketplace peddling counterfeit driver’s licenses, passports, and other state-…
-
Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach
Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company’s third-party Salesforce systems. The incident, which occurred in June 2025, has…
-
NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads
NodeBB Vulnerability Let Attackers Inject Boolean-Based Blind and PostgreSQL Error-Based Payloads NodeBB, a popular open-source forum platform, has been found vulnerable to a critical SQL injection flaw in version 4.3.0. The flaw, tracked as CVE-2025-50979, resides in the search-categories API endpoint, allowing unauthenticated, remote attackers to inject both boolean-based blind and PostgreSQL error-based payloads. Successful…
-
How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?
How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR? Adversary-in-the-Middle (AiTM) attacks are among the most sophisticated and dangerous phishing techniques in the modern cybersecurity landscape. Unlike traditional phishing attacks that merely collect static credentials, AiTM attacks actively intercept and manipulate communications between users and legitimate services in real-time, enabling attackers to bypass multi-factor authentication (MFA)…
-
TransUnion Hack Exposes 4M+ Customers Personal Information
TransUnion Hack Exposes 4M+ Customers Personal Information TransUnion, one of the nation’s three major credit reporting agencies, has disclosed a significant data breach that exposed the personal information of more than four million U.S. customers. The company is now alerting affected individuals about the cyber incident, which involved unauthorized access to data stored on a…
-
New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware
New Mac Malware Dubbed ‘JSCoreRunner’ Weaponizing PDF Conversion Site to Deliver Malware A sophisticated new Mac malware campaign has emerged, targeting users through a deceptive PDF conversion website that conceals a dangerous two-stage payload. The malware, dubbed “JSCoreRunner,” represents a significant evolution in macOS threats, demonstrating how cybercriminals are adapting their techniques to bypass Apple’s…
-
Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript
Nagios XSS Vulnerability Let Remote Attackers to Execute Arbitrary JavaScript Nagios XI, a widely-deployed network monitoring solution, has addressed a critical cross-site scripting (XSS) vulnerability in its Graph Explorer feature that could enable remote attackers to execute malicious JavaScript code within users’ browsers. The security flaw was patched in version 2024R2.1, released on August 12,…
-
PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input
PhpSpreadsheet Library Vulnerability Enables Attackers to Feed Malicious HTML Input A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the widely used PhpSpreadsheet library, potentially allowing attackers to exploit internal network resources and compromise server security. The vulnerability, tracked as CVE-2025-54370, affects multiple versions of the phpoffice/phpspreadsheet package and carries a CVSS v4.0…
-
New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens
New Malware Attack Exploiting TASPEN’s Legacy to Target Indonesian Senior Citizens A sophisticated malware campaign has emerged, targeting Indonesia’s most vulnerable digital citizens through a calculated exploitation of trust in the nation’s pension fund system. The malicious operation impersonates PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN), the state-owned pension fund managing over $15.9 billion…
-
CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks
CISA Warns of Citrix Netscaler 0-day RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Citrix NetScaler systems, designated as CVE-2025-7775. This memory overflow vulnerability enables remote code execution (RCE) and has been actively exploited by malicious cyber actors, prompting immediate inclusion in CISA’s Known Exploited Vulnerabilities…
-
Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics
Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501. The group has shifted from traditional on-premises ransomware to a more destructive, cloud-native strategy that involves data exfiltration and destruction, fundamentally changing the nature…
-
Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet
Kea DHCP Server Vulnerability Let Remote Attacker Crash With a Single Crafted Packet A newly disclosed vulnerability in the widely used ISC Kea DHCP server poses a significant security risk to network infrastructure worldwide. The flaw, designated CVE-2025-40779, allows remote attackers to crash DHCP services with just a single maliciously crafted packet, potentially disrupting network…
-
TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures
TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures Over the past year, a shadowy threat actor known as TAG-144—also tracked under aliases Blind Eagle and APT-C-36—has intensified operations against South American government institutions. First observed in 2018, this group has adopted an array of commodity remote access trojans (RATs) such as AsyncRAT,…
-
China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled
China-based Threat Actor Mustang Panda’s Tactics, Techniques, and Procedures Unveiled China-based threat actor Mustang Panda has emerged as one of the most sophisticated cyber espionage groups operating in the current threat landscape, with operations dating back to at least 2014. This advanced persistent threat (APT) group has systematically targeted government entities, nonprofit organizations, religious institutions,…
-
Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances
Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances A sophisticated data exfiltration campaign targeting corporate Salesforce instances has exposed sensitive information from multiple organizations through compromised OAuth tokens associated with the Salesloft Drift third-party application. The threat actor, designated as UNC6395, systematically harvested credentials and sensitive data between August 8-18,…
-
Critical Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code
Critical Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code Google has released an emergency security update for Chrome to address a critical use-after-free vulnerability (CVE-2025-9478) in the ANGLE graphics library that could allow attackers to execute arbitrary code on compromised systems. The vulnerability affects Chrome versions prior to 139.0.7258.154/.155 across Windows, Mac, and…
-
New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access
New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections. The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible…
-
DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment
DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment A whistleblower disclosure filed today alleges that the Department of Government Efficiency (DOGE) within the Social Security Administration (SSA) covertly created a live copy of the nation’s entire Social Security dataset in an unsecured cloud environment. Chief Data Officer…
-
Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection
Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection A stealthy espionage campaign emerged in early 2025 targeting diplomats and government entities in Southeast Asia and beyond. At the heart of this operation lies STATICPLUGIN, a downloader meticulously disguised as a legitimate Adobe plugin update. Victims encountered a captive portal hijack that redirected…
-
Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof
Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof Android droppers have evolved from niche installers for heavyweight banking Trojans into universal delivery frameworks, capable of deploying even rudimentary spyware or SMS stealers. Initially, droppers served banking malware families that required elevated Accessibility permissions to harvest credentials. These small applications appeared…
-
Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs
Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs A massive coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with threat actors deploying over 30,000 unique IP addresses to probe for vulnerabilities in Microsoft RD Web Access and RDP Web Client authentication portals. The campaign represents one of the…
-
CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks
CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks CISA has issued a critical alert regarding three newly identified vulnerabilities being actively exploited by threat actors. On August 25, 2025, CISA added these high-risk Common Vulnerabilities and Exposures (CVEs) to its Known Exploited Vulnerabilities (KEV) Catalog, signaling immediate concern for federal agencies…
-
Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database
Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database A sophisticated campaign of cyber sabotage unfolded against Iran’s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids. Rather than targeting each ship individually—a logistical nightmare across international waters—the attackers infiltrated Fanava Group,…
-
Hundreds of Thousands of Users’ Grok Chats Exposed in Google Search Results
Hundreds of Thousands of Users’ Grok Chats Exposed in Google Search Results A significant data exposure has revealed hundreds of thousands of private user conversations with Elon Musk’s AI chatbot, Grok, in public search engine results. The incident, stemming from the platform’s “share” feature, has made sensitive user data freely accessible online, seemingly without the…
-
New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection
New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection Phishing has always been about deceiving people. But in this campaign, the attackers weren’t only targeting users; they also attempted to manipulate AI-based defenses. This is an evolution of the Gmail phishing chain I documented last week. That campaign relied on urgency and redirects,…
-
20 Best Network Monitoring Tools in 2025
20 Best Network Monitoring Tools in 2025 A network monitoring tool is software or hardware that helps businesses monitor their computer networks and learn more about their security, health, and performance. These tools record and examine network traffic, monitor network hardware, and give users immediate access to information on bandwidth usage, latency, packet loss, and…
-
CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks
CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical zero-day vulnerability affecting Apple’s iOS, iPadOS, and macOS operating systems that threat actors are actively exploiting. The vulnerability, tracked as CVE-2025-43300, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling that…
-
Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts
Hackers Abuse VPS Servers To Compromise Software-as-a-service (SaaS) Accounts Cybercriminals are increasingly leveraging Virtual Private Server (VPS) infrastructure to orchestrate sophisticated attacks against Software-as-a-Service (SaaS) platforms, exploiting the anonymity and clean reputation of these hosting services to bypass traditional security controls. A coordinated campaign identified in early 2025 demonstrated how threat actors systematically abuse VPS…
-
Chinese MURKY PANDA Attacking Government and Professional Services Entities
Chinese MURKY PANDA Attacking Government and Professional Services Entities A sophisticated China-nexus threat actor designated MURKY PANDA has emerged as a significant cybersecurity concern, conducting extensive cyberespionage operations against government, technology, academic, legal, and professional services entities across North America since late 2024. This advanced persistent threat group demonstrates exceptional capabilities in cloud environment exploitation…
-
Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection
Hackers Can Exfiltrate Windows Secrets and Credentials Silently by Evading EDR Detection A method to silently exfiltrate Windows secrets and credentials, evading detection from most Endpoint Detection and Response (EDR) solutions. This technique allows attackers who have gained an initial foothold on a Windows machine to harvest credentials for lateral movement across a network without…
-
Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails
Microsoft to Limit Onmicrosoft Domain Usage for Sending Emails Microsoft has announced significant restrictions on email sending capabilities for organizations using default onmicrosoft.com domains, implementing a throttling system that limits external email delivery to 100 recipients per organization every 24 hours. The policy change, announced through the Exchange Team Blog, aims to prevent spam abuse…
-
ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words
ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words A critical vulnerability in OpenAI’s latest flagship model, ChatGPT-5, allows attackers to sidestep its advanced safety features using simple phrases. The flaw, dubbed “PROMISQROUTE” by researchers at Adversa AI, exploits the cost-saving architecture that major AI vendors use to manage the immense…
-
AI Systems Can Generate Working Exploits for Published CVEs in 10-15 Minutes
AI Systems Can Generate Working Exploits for Published CVEs in 10-15 Minutes Artificial intelligence systems can automatically generate functional exploits for newly published Common Vulnerabilities and Exposures (CVEs) in just 10-15 minutes at approximately $1 per exploit. This breakthrough significantly compresses the traditional “grace period” that defenders typically rely on to patch vulnerabilities before working…
-
Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes
Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes The Anatsa banking trojan, also known as TeaBot, continues to evolve as one of the most sophisticated Android malware threats targeting financial institutions worldwide. First discovered in 2020, this malicious software has demonstrated remarkable persistence in infiltrating Android devices through the official Google…
-
New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor
New Linux Malware With Weaponized RAR Archive Deploys VShell Backdoor Linux environments, long considered bastions of security, are facing a sophisticated new threat that challenges traditional assumptions about operating system safety. A recently discovered malware campaign exploits an ingenious attack vector that weaponizes RAR archive filenames to deliver the VShell backdoor, demonstrating how attackers are…
-
Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices
Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices Cybersecurity researchers have identified a sophisticated social engineering technique called ClickFix that has been rapidly gaining traction among threat actors since early 2024. This deceptive attack method targets both Windows and macOS devices, tricking users into executing malicious commands through seemingly legitimate…
-
New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain
New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain A sophisticated attack chain that combines MITM6 with NTLM relay techniques to achieve full Active Directory domain compromise. The attack exploits Windows’ default IPv6 auto-configuration behavior, allowing attackers to escalate from network access to Domain Admin privileges in minutes. Key Takeaways1.…
-
Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine
Microsoft VS Code Remote-SSH Extension Hacked to Execute Malicious Code on Developer’s Machine A critical security vulnerability has been discovered in Microsoft’s VS Code Remote-SSH extension that allows attackers to execute malicious code on developers’ local machines through compromised remote servers. Security researchers have demonstrated how this attack, dubbed “Vibe Hacking,” exploits the inherent trust…
-
New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials
New SHAMOS Malware Attacking macOS Via Fake Help Websites to Steal Login Credentials A sophisticated malware campaign targeting macOS users has emerged between June and August 2025, successfully attempting to compromise over 300 customer environments through deceptive help websites. The malicious operation deploys SHAMOS, a variant of the notorious Atomic macOS Stealer (AMOS), developed by…
-
Serial Hacker Jailed for Hacking and Defacing Organizations’ Websites
Serial Hacker Jailed for Hacking and Defacing Organizations’ Websites A sophisticated cybercriminal operation targeting government institutions and private organizations across multiple continents has culminated in the sentencing of Al-Tahery Al-Mashriky, a 26-year-old hacker from Rotherham, South Yorkshire. The prolific attacker, who operated under multiple aliases within the extremist hacking collective “Yemen Cyber Army,” was sentenced…
-
Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data
Legitimate Chrome VPN With 100,000+ Installs Silently Captures Screenshots and Exfiltrate Sensitive Data A Chrome VPN extension with over 100,000 installations and verified badge status has been discovered operating as sophisticated spyware, continuously capturing user screenshots and exfiltrating sensitive data without consent. The extension, known as FreeVPN.One, masqueraded as a legitimate privacy tool while secretly…
-
Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware
Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware Cybersecurity researchers have uncovered a sophisticated campaign by the Paper Werewolf threat actor group, also known as GOFFEE, targeting Russian organizations through the exploitation of critical vulnerabilities in WinRAR archiving software. The campaign, active since July 2025, demonstrates the group’s advanced capabilities in leveraging both known…
-
New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users
New ClickFix Attack Uses Fake BBC News Page and Fraudulent Cloudflare Verification to Trick Users A sophisticated new cyberthreat campaign has emerged that combines impersonation of trusted news sources with deceptive security verification prompts to trick users into executing malicious commands on their systems. According to a Reddit post, the ClickFix attack masquerades as legitimate BBC news…
-
PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware
PipeMagic Malware Mimic as ChatGPT App Exploits Windows Vulnerability to Deploy Ransomware A sophisticated malware campaign has been identified, utilizing PipeMagic, a highly modular backdoor deployed by the financially motivated threat actor Storm-2460. This advanced malware masquerades as a legitimate open-source ChatGPT Desktop Application while exploiting the zero-day vulnerability CVE-2025-29824 in Windows Common Log File…
-
SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security
SSH Keys Are Crucial for Secure Remote Access but Often Remain a Blind Spot in Enterprise Security Enterprise security strategies have evolved dramatically to address modern threats, yet SSH keys—critical cryptographic credentials that provide direct access to mission-critical systems—remain largely ungoverned and poorly managed across organizations. Despite their fundamental role in securing remote access to…
-
Crypto Developers Attacked With Malicious npm Packages to Steal Login Details
Crypto Developers Attacked With Malicious npm Packages to Steal Login Details A sophisticated new threat campaign has emerged targeting cryptocurrency developers through malicious npm packages designed to steal sensitive credentials and wallet information. The attack, dubbed “Solana-Scan” by researchers, specifically targets the Solana cryptocurrency ecosystem by masquerading as legitimate software development kits and scanning tools.…
-
CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks
CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks CISA has issued a critical warning regarding a high-severity OS command injection vulnerability in Trend Micro Apex One Management Console that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-54948 and classified under CWE-78, poses significant risks…
-
HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM
HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM Workday, a leading provider of enterprise cloud applications for finance and human resources, has confirmed it was the target of a sophisticated social engineering campaign that resulted in a data breach via a third-party Customer Relationship Management (CRM) platform. The company emphasized that the…
-
Hundreds of TeslaMate Installations Leaking Sensitive Vehicle Data in Real Time
Hundreds of TeslaMate Installations Leaking Sensitive Vehicle Data in Real Time A cybersecurity researcher has discovered that hundreds of publicly accessible TeslaMate installations are exposing sensitive Tesla vehicle data without authentication, revealing GPS coordinates, charging patterns, and personal driving habits to anyone on the internet. The vulnerability stems from misconfigured deployments of the popular open-source…
-
Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption
Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption A significant security update rolled out by Microsoft with the Windows 11 24H2 (KB5063878) release is causing widespread issues for users, with reports surfacing that the update can render SSDs and HDDs inaccessible and may potentially corrupt user data. Last week’s Patch Tuesday…
-
North Korean Hackers Stealthy Linux Malware Leaked Online
North Korean Hackers Stealthy Linux Malware Leaked Online In a significant breach of both cybersecurity defenses and secrecy, a trove of sensitive hacking tools and technical documentation, believed to originate from a North Korean threat actor, has recently been leaked online. The dump, revealed through an extensive article in Phrack Magazine, includes advanced exploit tactics,…
-
Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext
Threat Actor Allegedly Claiming Access to 15.8 Million PayPal Email and Passwords in Plaintext A threat actor operating under the alias “Chucky_BF” has posted a concerning advertisement on a well-known cybercrime forum, claiming to possess and sell a “Global PayPal Credential Dump 2025” containing over 15.8 million email and plaintext password pairs. The dataset, measuring…
-
New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD
New Elastic EDR 0-Day Vulnerability Allows Attackers to Bypass Detection, Execute Malware, and Cause BSOD A newly discovered zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution allows attackers to bypass security measures, execute malicious code, and trigger a BSOD system crash, according to the Ashes Cybersecurity research. The vulnerability resides in a core…
-
CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure
CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure CISA in collaboration with international partners, has released comprehensive guidance, titled “Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators,” to strengthen cybersecurity defenses across critical infrastructure sectors. The document emphasizes the critical importance of maintaining accurate operational technology (OT)…
-
Google Awards $250,000 Bounty for Chrome RCE Vulnerability Discovery
Google Awards $250,000 Bounty for Chrome RCE Vulnerability Discovery Google has awarded a record-breaking $250,000 bounty to security researcher “Micky” for discovering a critical remote code execution vulnerability in Chrome’s browser architecture. The vulnerability allowed malicious websites to escape Chrome’s sandbox protection and execute arbitrary code on victim systems. Key Takeaways1.Google paid researcher “Micky” a…
-
Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code
Microsoft IIS Web Deploy Vulnerability Let Attackers Execute Remote Code A critical vulnerability in the Microsoft Web Deploy tool could allow authenticated attackers to execute remote code on affected systems. The vulnerability, tracked as CVE-2025-53772, was disclosed on August 12, 2025, and carries a CVSS score of 8.8, indicating high severity. The flaw stems from…
-
New Gmail Phishing Attack With Weaponized Login Flow Steals Credentials
New Gmail Phishing Attack With Weaponized Login Flow Steals Credentials A sophisticated new phishing campaign targeting Gmail users through a multi-layered attack that uses legitimate Microsoft Dynamics infrastructure to bypass security measures and steal login credentials. The attack begins with deceptive “New Voice Notification” emails that appear to come from legitimate voicemail services. These emails…
-
Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) – Technical Details Revealed
Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) – Technical Details Revealed Cybersecurity researchers from watchTowr Labs have published a comprehensive technical analysis of a critical pre-authentication command injection vulnerability affecting Fortinet FortiSIEM systems, designated as CVE-2025-25256. The vulnerability carries a maximum CVSS score of 9.8 and has already been exploited in the wild, making it one…
-
Palo Alto Networks Released A Mega Malware Analysis Tutorials Useful for Every Malware Analyst
Palo Alto Networks Released A Mega Malware Analysis Tutorials Useful for Every Malware Analyst Palo Alto Networks has published an extensive malware analysis tutorial detailing the dissection of a sophisticated .NET-based threat that delivers the Remcos remote access trojan (RAT). The malware’s emergence highlights a trend in which threat actors increasingly abuse legitimate development environments…
-
Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection
Ransomware Actors Blending Legitimate Tools with Custom Malware to Evade Detection The cybersecurity landscape faces a new sophisticated threat as the Crypto24 ransomware group demonstrates an alarming evolution in attack methodology, seamlessly blending legitimate administrative tools with custom-developed malware to execute precision strikes against high-value targets. This emerging ransomware operation has successfully compromised organizations across…
-
Google Requires Crypto App Developers to Have License or Certification From Relevant Authorities
Google Requires Crypto App Developers to Have License or Certification From Relevant Authorities Google Play has implemented comprehensive licensing requirements for cryptocurrency exchanges and software wallets, fundamentally reshaping the mobile app ecosystem for digital asset services. The policy mandates that developers seeking to publish cryptocurrency applications must obtain specific licenses and certifications from relevant financial…
-
Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS
Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS A sophisticated threat campaign has emerged that leverages CrossC2, an unofficial extension tool that expands Cobalt Strike’s notorious capabilities beyond Windows systems to target Linux and macOS environments. Between September and December 2024, cybersecurity incidents involving this cross-platform malware have…
-
HexStrike AI Connects ChatGPT, Claude, Copilot with 150+ Security Tools like Burp Suite and Nmap
HexStrike AI Connects ChatGPT, Claude, Copilot with 150+ Security Tools like Burp Suite and Nmap A new AI tool named HexStrike AI has been launched, designed to bridge the gap between large language models (LLMs) and practical cybersecurity operations. The latest release, v6.0, equips AI agents like OpenAI’s GPT, Anthropic’s Claude, and GitHub’s Copilot with…
-
Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks
Cisco Secure Firewall Snort 3 Detection Engine Vulnerability Enables DoS Attacks Critical security flaw CVE-2025-20217 allows unauthenticated attackers to trigger denial-of-service conditions in Cisco’s widely deployed firewall systems Cisco has disclosed a high-severity vulnerability in its Secure Firewall Threat Defense (FTD) Software that could allow remote attackers to cause denial-of-service conditions through the Snort 3…
-
10 Best Deception Tools in 2025
10 Best Deception Tools in 2025 The goal of deception technology, which uses some of the best deception tools, is to trick attackers by dispersing a variety of traps and dummy assets throughout a system’s infrastructure to mimic real assets. There is always a possibility that cybercriminals will breach your network, regardless of how effective…
-
CVE-2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware
CVE-2025-8088 – WinRAR 0-Day Path Traversal Vulnerability Exploited to Execute Malware A zero-day vulnerability in WinRAR allows malware to be deployed on unsuspecting users’ systems, highlighting the ongoing threats to popular software. Tracked as CVE-2025-8088, this path traversal flaw affects the Windows version of the widely used file archiving tool, enabling attackers to execute arbitrary…
-
Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot
Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot A sophisticated new malware campaign targeting Windows systems has emerged, employing a multi-stage framework dubbed “PS1Bot” that combines PowerShell and C# components to conduct extensive information theft operations. The malware represents a significant evolution in attack methodologies, utilizing modular architecture and in-memory execution techniques…
-
ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns
ShinyHunters Possibly Collaborates With Scattered Spider in Salesforce Attack Campaigns The notorious ShinyHunters cybercriminal group has emerged from a year-long hiatus with a sophisticated new wave of attacks targeting Salesforce platforms across major organizations, including high-profile victims like Google. This resurgence marks a significant tactical evolution for the financially motivated threat actors, who have traditionally…
-
“AI-Induced Destruction” – New Attack Vector Where Helpful Tools Become Accidental Weapons
“AI-Induced Destruction” – New Attack Vector Where Helpful Tools Become Accidental Weapons Artificial intelligence coding assistants, designed to boost developer productivity, are inadvertently causing massive system destruction. Researchers report a significant spike in what they term “AI-induced destruction” incidents, where helpful AI tools become accidental weapons against the very systems they’re meant to improve. Key…
-
Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025
Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025 The cybersecurity landscape experienced an unprecedented escalation in digital threats during the first half of 2025, with Web Distributed Denial of Service (DDoS) attacks surging by 39% compared to the second half of 2024. The second quarter alone witnessed a staggering…
-
What Is Out-of-Bounds Read and Write Vulnerability?
What Is Out-of-Bounds Read and Write Vulnerability? Out-of-bounds read and write vulnerabilities represent critical security vulnerabilities that occur when software accesses memory locations beyond the allocated boundaries of data structures such as arrays, buffers, or other memory regions. These vulnerabilities can lead to information disclosure, system crashes, and in severe cases, arbitrary code execution that…
-
VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store
VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store A sophisticated cybercriminal organization known as VexTrio has been orchestrating a massive fraud empire through deceptive CAPTCHA robots and malicious applications distributed across Google Play and the App Store. This criminal network, operating for over 15 years, has…
-
Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data
Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data A sophisticated cybercriminal operation disguised as a Ukrainian Web3 development team has been targeting job seekers through weaponized NPM packages, security researchers warn. The attack leverages fake interview processes to trick unsuspecting candidates into downloading and executing malicious code that steals cryptocurrency…
-
What is MCP Server – How it is Powering AI-Driven Cyber Defense
What is MCP Server – How it is Powering AI-Driven Cyber Defense MCP (Model Control Plane) Server is a centralized platform that orchestrates, manages, and secures the lifecycle of AI models deployed across an organization’s infrastructure. By providing integration, management, and real-time monitoring of models, MCP servers enable enterprises to defend against sophisticated, AI-powered cyberattacks.…
-
New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch
New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch A critical zero-click NTLM credential leakage vulnerability that circumvents Microsoft’s recent patch for CVE-2025-24054. The newly identified flaw, assigned CVE-2025-50154, allows attackers to extract NTLM hashes from fully patched Windows systems without any user interaction, demonstrating that Microsoft’s April security update was incomplete. Key Takeaways1.…
-
FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control
FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control A high-severity authentication bypass vulnerability affecting multiple Fortinet security products, including FortiOS, FortiProxy, and FortiPAM systems. The flaw, designated as CVE-2024-26009 with a CVSS score of 7.9, enables unauthenticated attackers to seize complete control of managed devices through exploitation of the FortiGate-to-FortiManager…