Category: Cyber Security
-
Threat Actors Attacking Job Seekers With Three New Unique Adversaries
Threat Actors Attacking Job Seekers With Three New Unique Adversaries A significant surge in sophisticated recruitment scams has emerged, with cybercriminals exploiting economic vulnerabilities and the competitive job market to target desperate job seekers. These scams employ increasingly refined social engineering tactics that blend legitimate recruitment practices with fraudulent schemes, making them particularly effective at…
-
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Cybersecurity experts have uncovered a sophisticated attack campaign targeting IT administrators through search engine optimization (SEO) poisoning tactics. Threat actors are leveraging advanced SEO techniques to push malicious versions of commonly used administrative tools to the top of search engine…
-
Beyond DDoS: The New Breed Of Layer 7 Attacks And How SMEs Can Outmaneuver Them
Beyond DDoS: The New Breed Of Layer 7 Attacks And How SMEs Can Outmaneuver Them When most people think of DDoS attacks, they envision tsunami-like floods of traffic overwhelming servers. That’s the classic Layer 3/4 strategy brute force attacks meant to crash services by clogging up bandwidth. But over the last quarter, I’ve seen a…
-
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware A sophisticated new attack method that disables endpoint security protection has been identified by security researchers, enabling threat actors to deploy ransomware undetected. The technique, dubbed “Bring Your Own Installer,” was recently discovered by Aon’s Stroz Friedberg Incident Response team during an investigation of a Babuk…
-
UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes
UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes A newly discovered vulnerability in Microsoft’s Windows Deployment Services (WDS) allows attackers to remotely crash servers with zero user interaction or authentication. The flaw, which targets the UDP-based TFTP service at the WDS, could allow even low-skilled attackers to paralyze enterprise OS deployment infrastructure in…
-
PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test
PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test Most executives still treat PCI DSS like paperwork something to file away after a quarterly scan. But that mindset is dangerous. PCI compliance isn’t just a checklist it’s a survival test. Every rule in PCI exists because someone got breached. These aren’t hypotheticals;…
-
Apache ActiveMQ Vulnerability Allows Remote Attackers to Execute Arbitrary Code
Apache ActiveMQ Vulnerability Allows Remote Attackers to Execute Arbitrary Code A critical security vulnerability (CVE-2025-29953) in Apache ActiveMQ’s NMS OpenWire Client has been disclosed, enabling remote attackers to execute arbitrary code on vulnerable systems. The flaw, rooted in unsafe deserialization of untrusted data, affects versions prior to 2.1.1 and poses significant risks to organizations using…
-
Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data
Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data A critical Cross-Site Request Forgery (CSRF) vulnerability in Zimbra Collaboration Server (ZCS) versions 9.0 through 10.1, tracked as CVE-2025-32354, allows attackers to execute unauthorized GraphQL operations and access sensitive user data. The flaw resides in Zimbra’s webmail interface’s GraphQL endpoint (/service/extension/graphql), where improper CSRF token validation…
-
PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition
PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation. The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8…
-
Docker Registry Vulnerability Lets MacOS Users Pull Images from Any Registry
Docker Registry Vulnerability Lets MacOS Users Pull Images from Any Registry A newly disclosed vulnerability in Docker Desktop’s Registry Access Management (RAM) feature has left macOS users vulnerable to unauthorized image pulls, undermining critical container security controls. Designated CVE-2025-4095, the flaw allows developers to bypass registry restrictions enforced by administrators, potentially exposing organizations to malicious…
-
XDR In Penetration Testing: Leveraging Advanced Detection To Find Vulnerabilities
XDR In Penetration Testing: Leveraging Advanced Detection To Find Vulnerabilities Extended Detection and Response (XDR) has emerged as a transformative security technology that unifies visibility across multiple security layers. When applied to penetration testing methodologies, XDR offers unprecedented capabilities for identifying vulnerabilities that might otherwise remain hidden. This article explores how security professionals can leverage…
-
Social Engineering Awareness: How CISOs And SOC Heads Can Protect The Organization
Social Engineering Awareness: How CISOs And SOC Heads Can Protect The Organization Social engineering has become the dominant attack vector in the modern cybersecurity landscape. As technical defenses evolve and strengthen, attackers have shifted their focus to the human element, exploiting psychological vulnerabilities to bypass even the most robust security systems. Studies indicate that social…
-
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands A sophisticated phishing campaign dubbed “Power Parasites” has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week. The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy,…
-
Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid
Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid A serious vulnerability related to information exposure (CVE-2025-22234) impacts several versions of the spring-security-crypto package. The flaw enables attackers to determine valid usernames through timing attacks, undermining a key security feature designed to prevent user enumeration. The vulnerability affects Spring Security versions 5.7.16, 5.8.18, 6.0.16,…
-
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability A recent Microsoft security update, intended to patch a critical privilege escalation vulnerability, has inadvertently introduced a new and significant flaw. The fix now enables non-administrative users to effectively block all future Windows security updates, creating a denial-of-service condition. This unintended consequence of the patch highlights the…
-
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations North Korea’s cybercrime operations have significantly expanded beyond the limited 1,024 IP addresses assigned to their national network through an elaborate scheme involving Russian infrastructure. According to recent findings, five Russian IP ranges, primarily located in the border towns of Khasan and Khabarovsk,…
-
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites Phishing campaigns have evolved significantly in 2025, with threat actors increasingly leveraging unconventional file formats to bypass security solutions. A particularly concerning trend involves the weaponization of Scalable Vector Graphics (SVG) files, which are being embedded with malicious JavaScript code designed to redirect…
-
Blue Shield Leaked Health Info of 4.7M patients with Google Ads
Blue Shield Leaked Health Info of 4.7M patients with Google Ads Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, representing the majority of its nearly 6 million customers. The health insurance provider revealed that protected health information (PHI) was inadvertently shared with Google’s advertising platforms over a nearly three-year…
-
SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances
SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances SonicWall has disclosed a critical security vulnerability in its SSLVPN service that allows unauthenticated remote attackers to crash affected firewall appliances, potentially causing significant disruptions to enterprise networks. The vulnerability, tracked as CVE-2025-32818, received a high severity CVSS score of 7.5 and affects numerous SonicWall firewall…
-
1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities
1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities A significant increase in suspicious scanning activity targeting Ivanti Connect Secure (ICS) and Ivanti Pulse Secure (IPS) VPN systems, signaling a potential coordinated reconnaissance effort by threat actors. The spike, registering more than 230 unique IP addresses probing ICS/IPS endpoints in a single day,…
-
Microsoft to Offer Rewards Up to $30,000 for AI Vulnerabilities
Microsoft to Offer Rewards Up to $30,000 for AI Vulnerabilities Microsoft has launched an expanded bug bounty program offering rewards of up to $30,000 for researchers who identify critical vulnerabilities in AI systems within its Dynamics 365 and Power Platform products. The initiative, announced by Microsoft Security Response, aims to strengthen security in enterprise AI…
-
CISA Releases Five Advisories Covering ICS Vulnerabilities & Exploits
CISA Releases Five Advisories Covering ICS Vulnerabilities & Exploits The Cybersecurity and Infrastructure Security Agency (CISA) has released five new advisories addressing critical vulnerabilities in Industrial Control Systems (ICS) from Siemens, Schneider Electric, and ABB. These advisories, published on April 22, 2025, provide detailed information on security flaws, associated Common Vulnerabilities and Exposures (CVEs), and…
-
Zyxel Patches Privilege Management Vulnerabilities in USG FLEX H Series Firewalls
Zyxel Patches Privilege Management Vulnerabilities in USG FLEX H Series Firewalls Zyxel Networks has released critical security patches to address two high-severity vulnerabilities in its USG FLEX H series firewalls that could potentially allow attackers to escalate privileges and gain unauthorized access to affected devices. The security advisory, published on April 22, 2025, details the…
-
Hackers Attacking Organization With New Malware Mimic as Networking Software Updates
Hackers Attacking Organization With New Malware Mimic as Networking Software Updates A sophisticated backdoor targeting various large Russian organizations across government, finance, and industrial sectors has been uncovered during a cybersecurity investigation in April 2025. The malware, which masquerades as legitimate updates for ViPNet secure networking software, enables attackers to steal sensitive data and deploy…
-
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN A server briefly linked to the notorious KeyPlug malware has inadvertently exposed a comprehensive arsenal of exploitation tools specifically designed to target Fortinet firewall and VPN appliances. The infrastructure, which security researchers have attributed to the RedGolf threat group (overlapping with APT41),…
-
Detecting And Responding To New Nation-State Persistence Techniques
Detecting And Responding To New Nation-State Persistence Techniques Nation-state cyber threats have evolved dramatically over the past decade, with attackers employing increasingly sophisticated persistence techniques to maintain long-term access within targeted environments. These advanced persistent threats (APTs) are often orchestrated by government-backed groups with significant resources, making them particularly dangerous for critical infrastructure, government agencies,…
-
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC In today’s rapidly evolving cyber threat landscape, Security Operations Centers (SOCs) face an unprecedented challenge: efficiently managing and prioritizing the overwhelming volume of security alerts they receive daily. SOC analysts often can’t read and respond to a significant portion of the alerts they see every…
-
How to Implementing SOAR To Reduce Incident Response Time Effectively
How to Implementing SOAR To Reduce Incident Response Time Effectively In the modern digital landscape, organizations are constantly challenged by an ever-increasing volume of security alerts, sophisticated cyber threats, and the ongoing shortage of skilled cybersecurity professionals. Security Orchestration, Automation, and Response (SOAR) platforms have emerged as a transformative solution to these challenges, enabling security…
-
Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities
Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities Microsoft has warned organizations worldwide that threat actors are ramping up their exploitation of critical vulnerabilities in on-premises Exchange Server and SharePoint Server. These attacks, observed in recent months, have enabled cybercriminals to gain persistent and privileged access to targeted environments, leading to remote code execution,…
-
100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure
100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure A severe vulnerability in the popular WordPress plugin SureTriggers has been actively exploited within just four hours of its public disclosure on April 10, 2025. The critical authentication bypass flaw affects all versions of the plugin up to 1.0.78, which has over 100,000…
-
Why Security Leaders Are Turning to AI for Threat Detection
Why Security Leaders Are Turning to AI for Threat Detection In today’s rapidly evolving digital landscape, cybersecurity threats are becoming increasingly sophisticated and harder to detect using traditional methods. Security leaders across industries are recognizing artificial intelligence as a transformative force in strengthening defensive capabilities. This paradigm shift is prompting security leaders to integrate AI-powered…
-
Apache Roller Vulnerability Let Attackers Gain Unauthorized Access
Apache Roller Vulnerability Let Attackers Gain Unauthorized Access A critical security vulnerability in Apache Roller has been discovered, allowing attackers to maintain unauthorized access to blog systems even after password changes. The vulnerability, CVE-2025-24859, has received the highest possible CVSS v4 score of 10, indicating severe risk to affected systems. The security flaw stems from…
-
Why Every CISO Needs a Crisis Communications Plan in 2025
Why Every CISO Needs a Crisis Communications Plan in 2025 In an era defined by escalating cyber threats and regulatory scrutiny, the role of the Chief Information Security Officer (CISO) has expanded far beyond technical oversight. By 2025, cyberattacks will not only test an organization’s technical defenses but also its ability to maintain stakeholder trust…
-
Google Groups File Attachment Restrictions Bypassed via Email Posting
Google Groups File Attachment Restrictions Bypassed via Email Posting A significant security vulnerability has been identified in Google Groups, allowing users to circumvent file attachment restrictions by simply sending emails to group addresses. This broken access control issue potentially impacts thousands of organizations that rely on Google Groups for controlled information sharing and collaboration. Ph.Hitachi…
-
Chinese Hackers Exploit Ivanti VPN Vulnerabilities to Infiltrate Organizations
Chinese Hackers Exploit Ivanti VPN Vulnerabilities to Infiltrate Organizations A China-linked advanced persistent threat (APT) group has exploited critical vulnerabilities in Ivanti Connect Secure VPN appliances to infiltrate organizations across 12 countries and 20 industries, cybersecurity firm TeamT5 revealed in a report shared with Cyber Security News. The campaign, active since late March 2025, leverages…
-
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data Shells provide crucial command-line interfaces to operating systems. While legitimate for system administration tasks, when weaponized by threat actors, shells transform into dangerous avenues for unauthorized access, system control, and data theft across organizational networks. The misuse of these tools has become increasingly sophisticated,…
-
VMware ESXi 8.0 Update 3e Released for Free, What’s New!
VMware ESXi 8.0 Update 3e Released for Free, What’s New! Broadcom has officially reintroduced the free version of VMware ESXi with the release of ESXi 8.0 Update 3e (Build 24674464) on April 10, 2025. This marks a significant policy reversal after Broadcom discontinued the free ESXi offering following its acquisition of VMware, a move that…
-
Hackers Allegedly Leaked 1.59 Million Rows of Indian Insurance User’s Sensitive Data
Hackers Allegedly Leaked 1.59 Million Rows of Indian Insurance User’s Sensitive Data Hackers allegedly claim that a software company based in India was compromised on December 19, 2024, by a hacker identified as @303. The breach exposed approximately 1,590,798 rows of sensitive data, including customer information and administrative credentials. The dataset, initially leaked on the…
-
Cybersecurity Leadership in Crisis? CISO Resignations Spike After Major Breaches
Cybersecurity Leadership in Crisis? CISO Resignations Spike After Major Breaches The cybersecurity landscape is witnessing an alarming trend, Chief Information Security Officers (CISOs) are leaving their positions at unprecedented rates. Nearly half of CISOs globally are expected to change jobs by 2025, with a significant portion quitting entirely due to work-related stress. This exodus comes…
-
Beware Developers! Malicious NPM Packages Targeting PayPal Users to Steal Sensitive Data
Beware Developers! Malicious NPM Packages Targeting PayPal Users to Steal Sensitive Data FortiGuard Labs, Fortinet’s AI-driven threat intelligence arm, has uncovered a series of malicious NPM packages designed to steal sensitive information from developers and target PayPal users. Detected between March 5 and March 14, 2025, these packages were published by a threat actor using…
-
NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data
NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data A critical vulnerability in NVIDIA’s Container Toolkit, CVE-2024-0132, remains exploitable due to an incomplete patch, endangering AI infrastructure and sensitive data. Coupled with a newly discovered denial-of-service (DoS) flaw in Docker on Linux, these issues could allow attackers to breach systems, steal proprietary…
-
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies Cybersecurity experts have detected a sophisticated campaign targeting energy sector companies, as the threat actor known as Sapphire Werewolf deploys an enhanced version of the Amethyst stealer malware. The campaign represents a significant evolution in the group’s capabilities, featuring advanced evasion techniques and…
-
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows Google has announced the launch of Agent2Agent Protocol (A2A), a groundbreaking open protocol designed to enable AI agents to communicate with each other, securely exchange information, and coordinate actions across enterprise platforms. Revealed on April 9, 2025, the protocol marks a significant advancement…
-
Critical pgAdmin Vulnerability Let Attackers Execute Remote Code
Critical pgAdmin Vulnerability Let Attackers Execute Remote Code A critical security vulnerability discovered in pgAdmin 4, the most widely used management tool for PostgreSQL databases, is allowing attackers to execute arbitrary code on affected systems. Security researchers have disclosed details of CVE-2025-2945, a severe Remote Code Execution (RCE) vulnerability with a CVSS score of 9.9,…
-
CISA Releases NICE Workforce Framework Version 2.0.0 Released – What’s New
CISA Releases NICE Workforce Framework Version 2.0.0 Released – What’s New The US Cybersecurity and Infrastructure Security Agency (CISA) has officially released Version 2.0.0 of the NICE Workforce Framework for Cybersecurity, marking a significant update to this nationally focused resource. Released on March 5, 2025, this major update introduces substantial changes aimed at enhancing the…
-
Bitdefender GravityZone Console PHP Vulnerability Let Attackers Execute Arbitrary Commands
Bitdefender GravityZone Console PHP Vulnerability Let Attackers Execute Arbitrary Commands A critical security vulnerability has been discovered in Bitdefender GravityZone Console that could allow remote attackers to execute arbitrary commands on affected systems. The flaw tracked as CVE-2025-2244 has a CVSS score of 9.5. It stems from an insecure PHP deserialization issue that poses significant…
-
Top 10 Programming Languages For Cyber Security – 2025
Top 10 Programming Languages For Cyber Security – 2025 Communication is the key in all areas, and the cyber world is no different. To communicate in the cyber world, you must learn the language used here: programming languages. This will help you command the machines to act according to you. In cybersecurity, programming languages allow…
-
10 Best Kubernetes Container Scanners In 2025
10 Best Kubernetes Container Scanners In 2025 Kubernetes container scanners are essential tools for ensuring the security of containerized applications and Kubernetes clusters. These scanners analyze vulnerabilities, misconfigurations, and compliance issues within container images, Kubernetes manifests, and runtime environments. Popular tools like Kube Bench focus on compliance by auditing Kubernetes clusters against CIS benchmarks, while…
-
10 Best Ransomware File Decryptor Tools – 2025
10 Best Ransomware File Decryptor Tools – 2025 Ransomware file decryptor tools are essential for recovering data encrypted by malicious software without paying ransoms. These tools help victims regain access to their files by using decryption keys or algorithms to unlock the encrypted data. The No More Ransom project is a collaborative effort that offers…
-
Microsoft Strengthens Outlook’s Email Ecosystem to Protect Inboxes
Microsoft Strengthens Outlook’s Email Ecosystem to Protect Inboxes Microsoft Outlook will enforce stricter authentication requirements for high-volume senders, impacting domains that send over 5,000 emails daily. These changes, which will take effect on May 5, 2025, aim to enhance inbox protection and maintain trust in digital communication. Outlook’s updated policy will mandate compliance with SPF…
-
“Clipboard Hijacking” A Fake CAPTCHA Leverage Pastejacking Script Via Hacked Sites To Steal Clipboard Data
“Clipboard Hijacking” A Fake CAPTCHA Leverage Pastejacking Script Via Hacked Sites To Steal Clipboard Data A sophisticated new cyberattack chain dubbed “KongTuke” has been uncovered by cybersecurity researchers, targeting unsuspecting internet users through compromised legitimate websites. Detailed in a report by Bradley Duncan of Palo Alto Networks’ Unit 42 team, this attack leverages malicious scripts…
-
“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control
“IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control A recently discovered set of vulnerabilities, dubbed “IngressNightmare,” found in Ingress NGINX Controller, exposing clusters to unauthenticated remote code execution (RCE). Kubernetes dominates container orchestration, but its prominence has made it a target for exploitation. In Kubernetes, Ingress serves as a sophisticated…
-
Sec-Gemini v1 – Google Released a New AI Model for Cybersecurity
Sec-Gemini v1 – Google Released a New AI Model for Cybersecurity Google has made a big move to fight cyber threats by announcing Sec-Gemini v1, an experimental AI model designed to revolutionize cybersecurity. Elie Burzstein and Marianna Tishchenko from the Sec-Gemini team unveiled a new AI model designed to help cybersecurity defenders tackle the growing…
-
CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog
CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-22457, a critical vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, to its Known Exploited Vulnerabilities (KEV) Catalog. This stack-based buffer overflow, actively exploited since mid-March 2025, allows remote unauthenticated attackers…
-
Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild – Apply Patch Now!
Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild – Apply Patch Now! Ivanti has disclosed a critical vulnerability, CVE-2025-22457, affecting its Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways products that are actively exploited in the wild. This stack-based buffer overflow flaw, with a CVSS score of 9.0, has been…
-
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring Frida 16.7.0, the latest version of the popular dynamic instrumentation toolkit, has powerful new APIs specifically designed for advanced threat monitoring and security analysis. This major update, announced on March 13, 2025, introduces groundbreaking capabilities that significantly enhance the toolkit’s utility for security…
-
Apache Traffic Server Vulnerability Let Attackers Smuggle Requests
Apache Traffic Server Vulnerability Let Attackers Smuggle Requests A critical security vulnerability in Apache Traffic Server (ATS) has been discovered. By exploiting how the server processes chunked messages, attackers can perform request smuggling attacks. The vulnerability, tracked as CVE-2024-53868, affects multiple versions of this high-performance HTTP proxy server and requires system administrators’ immediate attention. According…
-
OpenVPN Vulnerability Let Attackers Crash Servers & Execute Remote Code
OpenVPN Vulnerability Let Attackers Crash Servers & Execute Remote Code A critical security vulnerability in OpenVPN has been discovered that could allow attackers to crash servers, potentially disrupting secure communications for thousands of users worldwide. The vulnerability, identified as CVE-2025-2704, affects OpenVPN versions 2.6.1 through 2.6.13 when configured with the –tls-crypt-v2 option, a feature commonly…
-
Hackers Leveraging Fast Flux Technique to Evade Detection & Hide Malicious Servers
Hackers Leveraging Fast Flux Technique to Evade Detection & Hide Malicious Servers CISA warns of threat actors’ increasing adoption of the fast flux technique to evade detection and conceal malicious server infrastructures. As cybercriminal operations grow increasingly sophisticated, threat actors adopt advanced techniques like fast flux to mask malicious infrastructure, evade defensive measures, and maintain persistent access…
-
Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks
Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085 that have been actively exploited in sophisticated attacks. These vulnerabilities affect a wide range of Apple devices, including iPhones, iPads, Macs, and other platforms. Users are strongly advised to…
-
CrushFTP Vulnerability Exploited in Attacks Following PoC Release
CrushFTP Vulnerability Exploited in Attacks Following PoC Release Security researchers have confirmed active exploitation attempts targeting the critical authentication bypass vulnerability in CrushFTP (CVE-2025-2825) following the public release of proof-of-concept exploit code. Based on Shadowserver Foundation’s most recent monitoring data, approximately 1,512 unpatched instances remain vulnerable globally as of March 30, 2025, with North America…
-
CISA Warns of Cisco Smart Licensing Utility Credential Vulnerability Exploited in Attacks
CISA Warns of Cisco Smart Licensing Utility Credential Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Cisco vulnerability to its Known Exploited Vulnerabilities (KEV) catalog following confirmation of active exploitation in the wild. The flaw, identified as CVE-2024-20439, affects the Cisco Smart Licensing Utility (CSLU) and allows unauthenticated,…
-
Hackers Scanning From 24,000 IPs to Gain Access to Palo Alto Networks GlobalProtect Portals
Hackers Scanning From 24,000 IPs to Gain Access to Palo Alto Networks GlobalProtect Portals Researchers have detected an alarming surge in malicious scanning activity targeting Palo Alto Networks’ GlobalProtect VPN portals. Over a 30-day period, nearly 24,000 unique IP addresses have attempted to access these critical security gateways, suggesting a coordinated effort to probe network…
-
Lotus Blossom APT Exploits WMI for Post-Exploitation Activities
Lotus Blossom APT Exploits WMI for Post-Exploitation Activities The Lotus Blossom Advanced Persistent Threat (APT) group, also known as Lotus Panda, Billbug, and Spring Dragon, has intensified its cyberespionage efforts with new variants of the Sagerunex backdoor. These developments highlight the group’s evolving tactics, including leveraging Windows Management Instrumentation (WMI) for post-exploitation activities and employing…
-
CISA Warns of ESURGE Malware Exploiting Ivanti RCE Vulnerability
CISA Warns of ESURGE Malware Exploiting Ivanti RCE Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Malware Analysis Report (MAR-25993211-r1.v1) detailing the exploitation of a critical vulnerability in Ivanti Connect Secure devices (CVE-2025-0282). This vulnerability allows attackers to gain unauthorized access and deploy sophisticated malware variants, including the newly identified RESURGE and…
-
RamiGPT – AI Tool To Escalate Privilege & Gain Root Access Within a Minute
RamiGPT – AI Tool To Escalate Privilege & Gain Root Access Within a Minute A new AI-driven offensive security tool, RamiGPT, is known for its ability to autonomously escalate privileges and gain root access to vulnerable systems in under a minute. Developed by GitHub user M507, the tool leverages OpenAI’s API. It integrates proven penetration…
-
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows A sophisticated social engineering technique has recently emerged in the cybersecurity landscape, rapidly gaining traction among threat actors seeking to distribute trojans, ransomware, and particularly Quakbot malware. This technique, known as ClickFix Captcha, exploits users’ trust in familiar web elements…
-
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows A sophisticated cyber espionage campaign targeting Ukrainian entities has been uncovered, revealing the latest tactics of the Russia-linked Gamaredon threat actor group. The attackers are leveraging weaponized LNK files disguised as Office documents to deliver the Remcos backdoor malware, utilizing themes related to…
-
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models In an era where deep learning models increasingly power critical systems from self-driving cars to medical devices, security researchers have unveiled DeBackdoor, an innovative framework designed to detect stealthy backdoor attacks before deployment. Backdoor attacks, among the most effective and covert threats to deep learning,…
-
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence Artificial intelligence has dramatically transformed the cybersecurity landscape, with red team activities increasingly leveraging sophisticated AI-driven techniques to simulate advanced persistent threats. These AI-enhanced red teams can now automate the process of penetrating targets and collecting sensitive data at unprecedented speeds. The evolution…
-
Appsmith Developer Tool Vulnerability Let Attackers Execute Remote Code
Appsmith Developer Tool Vulnerability Let Attackers Execute Remote Code Security researchers have uncovered multiple critical vulnerabilities in Appsmith, a popular open-source developer platform for building internal applications. Most concerning is CVE-2024-55963, which allows unauthenticated attackers to execute arbitrary system commands on servers running default installations of Appsmith versions 1.20 through 1.51. CVE-2024-55963 – Remote Code…
-
CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS
CISA Warns of Four Vulnerabilities, and Exploits Surrounding ICS The Cybersecurity and Infrastructure Security Agency (CISA) released four Industrial Control System (ICS) advisories on March 25, 2025, detailing significant vulnerabilities in products from ABB, Rockwell Automation, and Inaba Denki Sangyo. These vulnerabilities, with CVSS v4 scores ranging from 5.1 to 9.3, could allow attackers to…
-
New Windows 0-Day Vulnerability Let Remote Attackers Steal NTLM Credentials – Unofficial Patch
New Windows 0-Day Vulnerability Let Remote Attackers Steal NTLM Credentials – Unofficial Patch A critical vulnerability affecting all Windows operating systems from Windows 7 and Server 2008 R2 through the latest Windows 11 v24H2 and Server 2025. This zero-day flaw enables attackers to capture users’ NTLM authentication credentials simply by having them view a malicious…
-
Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild
Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild Google has released an urgent security update for its Chrome browser after cybersecurity researchers at Kaspersky discovered a zero-day vulnerability being actively exploited by sophisticated threat actors. The vulnerability, identified as CVE-2025-2783, allowed attackers to bypass Chrome’s sandbox protection through a logical error at the…
-
Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code
Critical Synology Vulnerability Let Attackers Remote Execute Arbitrary Code A severe vulnerability in Synology’s DiskStation Manager (DSM) allows remote attackers to execute arbitrary code with no user interaction. The flaw, disclosed during PWN2OWN 2024, received a Critical severity rating with a CVSS score of 9.8, indicating its potential for widespread exploitation. The primary vulnerability, identified…
-
Microsoft Windows File Explorer Vulnerability Let Attackers Perform Network Spoofing – PoC Released
Microsoft Windows File Explorer Vulnerability Let Attackers Perform Network Spoofing – PoC Released A critical vulnerability in Windows File Explorer, identified as CVE-2025-24071, enables attackers to steal NTLM hashed passwords without any user interaction beyond simply extracting a compressed file. Security researchers have released a proof-of-concept exploit demonstrating this high-severity flaw, which Microsoft patched in…
-
Hackers Allegedly Selling Firewall Access to Canon Inc on Hacking Forums
Hackers Allegedly Selling Firewall Access to Canon Inc on Hacking Forums Threat actors are allegedly offering root access to Canon Inc.’s internal firewall systems on underground hacking forums. According to security monitoring firm ThreatMon, the advertisement appeared on a popular dark web marketplace, claiming to provide administrator-level access to the Japanese camera giant’s network infrastructure.…
-
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT A sophisticated phishing campaign is leveraging virtual hard disk (.vhd) files to distribute the dangerous VenomRAT malware. The attack begins with purchase order-themed emails containing archive attachments that, when extracted, reveal hard disk image files designed to evade traditional security measures. Batch file inside .vhd file…
-
CISA Warns of Fortinet FortiOS Authentication Bypass Vulnerability Exploited in Wild
CISA Warns of Fortinet FortiOS Authentication Bypass Vulnerability Exploited in Wild The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert highlighting a significant vulnerability in Fortinet’s FortiOS and FortiProxy systems, which threat actors are actively exploiting. The authentication bypass vulnerability, tracked as CVE-2025-24472, has been added to CISA’s Known Exploited Vulnerabilities…
-
Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning
Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning Google has officially launched OSV-Scanner V2.0.0, a major upgrade to its open-source vulnerability scanning tool. Released on March 17, 2025, this new version represents a significant evolution in helping developers identify and fix security vulnerabilities in their software dependencies. The V2 release builds upon…
-
Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit
Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit Security researchers have confirmed that a critical remote code execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813, is being actively exploited in the wild. The vulnerability, which enables attackers to take control of servers with a simple PUT request, was disclosed last…
-
Beware of Free File Word To PDF Converter That Delivers Malware
Beware of Free File Word To PDF Converter That Delivers Malware The FBI has issued an urgent warning about the rising threat of malicious file conversion tools that are being used to spread malware across the United States. Cybercriminals are targeting users searching for free utilities to convert documents from one format to another, with…
-
Kentico Xperience CMS Authentication Bypass Vulnerability Allow Attackers Execute Arbitrary Code Remotely
Kentico Xperience CMS Authentication Bypass Vulnerability Allow Attackers Execute Arbitrary Code Remotely Researchers discovered critical vulnerabilities in Kentico’s Xperience CMS that could allow attackers to completely compromise affected systems. The vulnerabilities, identified as WT-2025-0006, WT-2025-0007, and WT-2025-0011, can be chained together to achieve unauthenticated remote code execution on systems with common configurations. Researchers at watchTowr…
-
Hackers Allegedly Selling 3.17 Million Records of Honda Cars India Customers
Hackers Allegedly Selling 3.17 Million Records of Honda Cars India Customers A hacker operating under the pseudonym “Empire” has allegedly listed a database containing 3,176,958 records from Honda Cars India Ltd for sale on a notorious cybercrime forum. The leaked data reportedly includes sensitive customer information such as names, aliases, addresses, customer IDs, and contact…
-
Cisco Warns of IOS XR Software Vulnerability That Let Attackers Trigger DoS condition
Cisco Warns of IOS XR Software Vulnerability That Let Attackers Trigger DoS condition Cisco has issued security advisories for multiple vulnerabilities affecting its IOS XR Software, with particular emphasis on a significant memory corruption vulnerability in the Border Gateway Protocol (BGP) confederation implementation. The vulnerability tracked as CVE-2025-20115, with a CVSS score of 8.6, could…
-
Critical ruby-saml Vulnerabilities Let Attackers Bypass Authentication
Critical ruby-saml Vulnerabilities Let Attackers Bypass Authentication Two critical authentication bypass vulnerabilities have been discovered in the ruby-saml library, potentially exposing numerous web applications to account takeover attacks. Security researchers from GitHub Security Lab have identified parser differential vulnerabilities (CVE-2025-25291 and CVE-2025-25292) affecting ruby-saml versions up to 1.17.0, which could allow attackers to impersonate any…
-
Microsoft365 Themed Attack Leveraging OAuth Redirection for Account Takeover
Microsoft365 Themed Attack Leveraging OAuth Redirection for Account Takeover Two sophisticated phishing campaigns were observed targeting Microsoft 365 users by exploiting OAuth redirection vulnerabilities combined with brand impersonation techniques. Threat researchers are warning organizations about these highly targeted attacks designed to bypass traditional security controls and achieve account takeover (ATO). The malicious campaigns leverage familiar…
-
New Campaign Attacking PyPI Users to Steal Sensitive Data Including Cloud Tokens
New Campaign Attacking PyPI Users to Steal Sensitive Data Including Cloud Tokens Security researchers have uncovered a sophisticated malware campaign targeting users of the Python Package Index (PyPI), Python’s official third-party software repository. This latest attack vector involves several malicious packages disguised as time-related utilities, which are actually designed to steal sensitive information including cloud…
-
Decrypting Linux/ESXi Akira Ransomware Files Without Paying Ransomware
Decrypting Linux/ESXi Akira Ransomware Files Without Paying Ransomware A cybersecurity researcher has successfully broken the encryption used by the Linux/ESXI variant of the Akira ransomware, enabling data recovery without paying the ransom demand. The breakthrough exploits a critical weakness in the ransomware’s encryption methodology. According to the researcher, the malware uses the current time in…
-
SuperBlack Actors Exploiting Two Fortinet Vulnerabilities to Deploy Ransomware
SuperBlack Actors Exploiting Two Fortinet Vulnerabilities to Deploy Ransomware Between late January and early March 2025, cybersecurity researchers at Forescout’s Vedere Labs uncovered a series of sophisticated intrusions leveraging critical Fortinet vulnerabilities. The attacks, attributed to a newly identified threat actor tracked as “Mora_001,” culminated in the deployment of a custom ransomware strain dubbed “SuperBlack.”…
-
Microsoft March 2025 Patch Tuesday: Fixes for 57 Vulnerabilities & 6 Actively Exploited Zero-Days
Microsoft March 2025 Patch Tuesday: Fixes for 57 Vulnerabilities & 6 Actively Exploited Zero-Days Microsoft’s March 2025 Patch Tuesday addresses 57 vulnerabilities, including six zero-day vulnerabilities that are currently being exploited. The security update includes fixes for Windows, Microsoft Office, Azure, and other components. The March patch tuesday update included fixes for: In addition to…
-
CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild
CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding an actively exploited vulnerability in Microsoft Windows Management Console (MMC), tracked as CVE-2025-26633. This improper neutralization flaw (CWE-707) enables remote attackers to execute arbitrary code over a network, posing significant…
-
Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks
Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks Apple has released emergency security updates addressing a critical zero-day vulnerability in its WebKit browser engine, identified as CVE-2025-24201, which has been actively exploited in targeted attacks. The flaw, described as an out-of-bounds write issue, could enable attackers to craft malicious web content capable…
-
Enabling Incognito Mode in RDP to Hide All the Traces
Enabling Incognito Mode in RDP to Hide All the Traces Microsoft’s Remote Desktop Protocol (RDP) has introduced a lesser-known but critical security feature colloquially referred to as “incognito mode” through its /public command-line parameter. This functionality, formally called public mode, prevents the client from storing sensitive session artifacts—a development with significant implications for cybersecurity, digital…
-
GitHub Details How Security Professionals Can Use Copilot to Analyze Logs
GitHub Details How Security Professionals Can Use Copilot to Analyze Logs GitHub has unveiled groundbreaking applications of its AI-powered coding assistant, Copilot, specifically tailored for security professionals analyzing system logs and operational data. The tool now demonstrates unprecedented capabilities in parsing security event information, identifying anomalies, and accelerating incident response workflows through intelligent code suggestions…
-
North Korean IT Workers Using GitHub To Attack Organization Globally
North Korean IT Workers Using GitHub To Attack Organization Globally Cybersecurity research firm NISOS has uncovered a network of suspected North Korean IT workers who are leveraging GitHub to create elaborate fake personas aimed at securing employment with companies in Japan and the United States. These individuals pose as Vietnamese, Japanese, and Singaporean nationals while…
-
CISA Warns of Edimax IC-7100 IP Camera 0-Day Vulnerability Exploited in Attacks
CISA Warns of Edimax IC-7100 IP Camera 0-Day Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding a severe vulnerability in the Edimax IC-7100 IP Camera. This vulnerability, CVE-2025-1316, allows attackers to execute remote code on the device by sending specially crafted requests, exploiting an improper neutralization…
-
AMD Microcode Signature Verification Vulnerability Let Attackers Load Malicious Patches
AMD Microcode Signature Verification Vulnerability Let Attackers Load Malicious Patches Security researchers have uncovered a critical vulnerability in AMD Zen CPUs that allows attackers with elevated privileges to load malicious microcode patches, bypassing cryptographic signature checks. Dubbed “EntrySign,” this flaw stems from AMD’s use of the AES-CMAC algorithm as a hash function during microcode validation—a…
-
Google Silently Tracks Android Device Even No Apps Opened by User
Google Silently Tracks Android Device Even No Apps Opened by User Google collects and stores significant amounts of user data on Android devices, even when users haven’t opened any Google apps. The study by Professor D.J. Leith from Trinity College Dublin, documents for the first time how pre-installed Google apps silently track users without seeking…
-
Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k
Two Hackers Arrested for Stealing Taylor Swift Era Concert Tickets Worth $600k Two individuals were arrested this week in a sophisticated cybercrime operation targeting high-demand events. They were accused of orchestrating a $600,000 ticket theft scheme involving Taylor Swift’s Eras Tour and other major concerts. Queens District Attorney Melinda Katz revealed that Tyrone Rose, 34,…