Category: TheHackersNews

  • Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

    Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub Cybersecurity researchers have discovered a new cryptojacking campaign that’s targeting publicly accessible DevOps web servers such as those associated with Docker, Gitea, and HashiCorp Consul and Nomad to illicitly mine cryptocurrencies. Cloud security firm Wiz, which is tracking the activity under the name JINX-0132, said…

  • New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch

    New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild. The high-severity flaw is being tracked as CVE-2025-5419, and has been flagged as an out-of-bounds read and…

  • ⚡ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More

    ⚡ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More If this had been a security drill, someone would’ve said it went too far. But it wasn’t a drill—it was real. The access? Everything looked normal. The tools? Easy to find. The detection? Came too late. This is how attacks happen now—quiet,…

  • Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU

    Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU Qualcomm has shipped security updates to address three zero-day vulnerabilities that it said have been exploited in limited, targeted attacks in the wild. The flaws in question, which were responsibly disclosed to the company by the Google Android Security team, are listed below…

  • Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN

    Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN Three security vulnerabilities have been disclosed in preloaded Android applications on smartphones from Ulefone and Krüger&Matz that could enable any app installed on the device to perform a factory reset and encrypt an application. A brief description of the three flaws is…

  • Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions

    Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions Cybersecurity researchers have warned of a new spear-phishing campaign that uses a legitimate remote access tool called Netbird to target Chief Financial Officers (CFOs) and financial executives at banks, energy companies, insurers, and investment firms across Europe, Africa, Canada, the Middle East,…

  • U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation

    U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation A multinational law enforcement operation has resulted in the takedown of an online cybercrime syndicate that offered services to threat actors to ensure that their malicious software stayed undetected from security software. To that effect, the U.S. Department of Justice (DoJ) said it…

  • New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora

    New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora Two information disclosure flaws have been identified in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise Linux, and Fedora, according to the Qualys Threat Research Unit (TRU). Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition…

  • From the “Department of No” to a “Culture of Yes”: A Healthcare CISO’s Journey to Enabling Modern Care

    From the “Department of No” to a “Culture of Yes”: A Healthcare CISO’s Journey to Enabling Modern Care Breaking Out of the Security Mosh Pit When Jason Elrod, CISO of MultiCare Health System, describes legacy healthcare IT environments, he doesn’t mince words: “Healthcare loves to walk backwards into the future. And this is how we…

  • China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil

    China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil The China-linked threat actor behind the recent in-the-wild exploitation of a critical security flaw in SAP NetWeaver has been attributed to a broader set of attacks targeting organizations in Brazil, India, and Southeast Asia since 2023. “The threat actor mainly targets…

  • New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data

    New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data A new malware campaign is distributing a novel Rust-based information stealer dubbed EDDIESTEALER using the popular ClickFix social engineering tactic initiated via fake CAPTCHA verification pages. “This campaign leverages deceptive CAPTCHA verification pages that trick users into executing a malicious PowerShell script, which ultimately…

  • U.S. Sanctions Funnull for $200M Romance Baiting Scams Tied to Crypto Fraud

    U.S. Sanctions Funnull for $200M Romance Baiting Scams Tied to Crypto Fraud The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) has levied sanctions against a Philippines-based company named Funnull Technology Inc. and its administrator Liu Lizhi for providing infrastructure to conduct romance baiting scams that led to massive cryptocurrency losses. The Treasury…

  • DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints

    DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints The threat actors behind the DragonForce ransomware gained access to an unnamed Managed Service Provider’s (MSP) SimpleHelp remote monitoring and management (RMM) tool, and then leveraged it to exfiltrate data and drop the locker on multiple endpoints. It’s believed that the attackers exploited a trio…

  • New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers

    New Windows RAT Evades Detection for Weeks Using Corrupted DOS and PE Headers Cybersecurity researchers have taken the wraps off an unusual cyber attack that leveraged malware with corrupted DOS and PE headers, according to new findings from Fortinet. The DOS (Disk Operating System) and PE (Portable Executable) headers are essential parts of a Windows…

  • Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools

    Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools Fake installers for popular artificial intelligence (AI) tools like OpenAI ChatGPT and InVideo AI are being used as lures to propagate various threats, such as the CyberLock and Lucky_Gh0$t ransomware families, and a new malware dubbed Numero. “CyberLock ransomware, developed using PowerShell, primarily focuses…

  • Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas

    Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas Meta on Thursday revealed that it disrupted three covert influence operations originating from Iran, China, and Romania during the first quarter of 2025. “We detected and removed these campaigns before they were able to build authentic audiences on our apps,” the social media…

  • ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach

    ConnectWise Hit by Cyberattack; Nation-State Actor Suspected in Targeted Breach ConnectWise, the developer of remote access and support software ScreenConnect, has disclosed that it was the victim of a cyber attack that it said was likely perpetrated by a nation-state threat actor. “ConnectWise recently learned of suspicious activity within our environment that we believe was…

  • New PumaBot Botnet Targets Linux IoT Devices to Steal SSH Credentials and Mine Crypto

    New PumaBot Botnet Targets Linux IoT Devices to Steal SSH Credentials and Mine Crypto Embedded Linux-based Internet of Things (IoT) devices have become the target of a new botnet dubbed PumaBot. Written in Go, the botnet is designed to conduct brute-force attacks against SSH instances to expand in size and scale and deliver additional malware…

  • Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File

    Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File Cybersecurity researchers have discovered a security flaw in Microsoft’s OneDrive File Picker that, if successfully exploited, could allow websites to access a user’s entire cloud storage content, as opposed to just the files selected for upload via the…

  • Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack

    Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack The Czech Republic on Wednesday formally accused a threat actor associated with the People’s Republic of China (PRC) of targeting its Ministry of Foreign Affairs. In a public statement, the government said it identified China as the culprit behind a malicious campaign targeting one of the…

  • Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore

    Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore An Iranian national has pleaded guilty in the U.S. over his involvement in an international ransomware and extortion scheme involving the Robbinhood ransomware. Sina Gholinejad (aka Sina Ghaaf), 37, and his co-conspirators are said to have breached the computer networks of various organizations…

  • Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin

    Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin Cybersecurity researchers have disclosed a critical unpatched security flaw impacting TI WooCommerce Wishlist plugin for WordPress that could be exploited by unauthenticated attackers to upload arbitrary files. TI WooCommerce Wishlist, which has over 100,000 active installations, is a tool to allow…

  • Apple Blocks $9 Billion in Fraud Over 5 Years Amid Rising App Store Threats

    Apple Blocks $9 Billion in Fraud Over 5 Years Amid Rising App Store Threats Apple on Tuesday revealed that it prevented over $9 billion in fraudulent transactions in the last five years, including more than $2 billion in 2024 alone. The company said the App Store is confronted by a wide range of threats that…

  • AI Agents and the Non‑Human Identity Crisis: How to Deploy AI More Securely at Scale

    AI Agents and the Non‑Human Identity Crisis: How to Deploy AI More Securely at Scale Artificial intelligence is driving a massive shift in enterprise productivity, from GitHub Copilot’s code completions to chatbots that mine internal knowledge bases for instant answers. Each new agent must authenticate to other services, quietly swelling the population of non‑human identities (NHIs) across corporate clouds.…

  • Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages

    Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages Microsoft has shed light on a previously undocumented cluster of malicious activity originating from a Russia-affiliated threat actor dubbed Void Blizzard (aka Laundry Bear) that it said is attributed to “worldwide cloud abuse.” Active since at least April 2024, the hacking group…

  • Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets

    Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets Cybersecurity researchers have disclosed a new malicious campaign that uses a fake website advertising antivirus software from Bitdefender to dupe victims into downloading a remote access trojan called Venom RAT. The campaign indicates a “clear intent to target individuals for financial gain by…

  • New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency

    New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency Misconfigured Docker API instances have become the target of a new malware campaign that transforms them into a cryptocurrency mining botnet. The attacks, designed to mine for Dero currency, is notable for its worm-like capabilities to propagate the malware to other exposed Docker instances and…

  • Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

    Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto As many as 60 malicious npm packages have been discovered in the package registry with malicious functionality to harvest hostnames, IP addresses, DNS servers, and user directories to a Discord-controlled endpoint. The packages, published under three different accounts, come with an install‑time…

  • ⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs

    ⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs Cyber threats don’t show up one at a time anymore. They’re layered, planned, and often stay hidden until it’s too late. For cybersecurity teams, the key isn’t just reacting to alerts—it’s spotting early signs of trouble before they become real threats.…

  • CISO’s Guide To Web Privacy Validation And Why It’s Important

    CISO’s Guide To Web Privacy Validation And Why It’s Important Are your web privacy controls protecting your users, or just a box-ticking exercise? This CISO’s guide provides a practical roadmap for continuous web privacy validation that’s aligned with real-world practices. – Download the full guide here. Web Privacy: From Legal Requirement to Business Essential As…

  • Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware

    Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware Cybersecurity researchers have disclosed a malware campaign that uses fake software installers masquerading as popular tools like LetsVPN and QQ Browser to deliver the Winos 4.0 framework. The campaign, first detected by Rapid7 in February 2025, involves the use of a multi-stage,…

  • Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

    Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique The malware known as Latrodectus has become the latest to embrace the widely-used social engineering technique called ClickFix as a distribution vector. “The ClickFix technique is particularly risky because it allows the malware to execute in memory rather than being written to…

  • U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

    U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation The U.S. Department of Justice (DoJ) on Thursday announced the disruption of the online infrastructure associated with DanaBot (aka DanaTools) and unsealed charges against 16 individuals for their alleged involvement in the development and deployment of the malware, which it said was controlled…

  • SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

    SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection From zero-day exploits to large-scale bot attacks — the demand for a powerful, self-hosted, and user-friendly web application security solution has never been greater. SafeLine is currently the most starred open-source Web Application Firewall (WAF) on GitHub, with over 16.4K stars and…

  • 300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

    300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide As part of the latest “season” of Operation Endgame, a coalition of law enforcement agencies have taken down about 300 servers worldwide, neutralized 650 domains, and issued arrest warrants against 20 targets. Operation Endgame, first launched in May 2024, is an ongoing law enforcement…

  • ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

    ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices Cybersecurity researchers have disclosed that a threat actor codenamed ViciousTrap has compromised nearly 5,300 unique network edge devices across 84 countries and turned them into a honeypot-like network. The threat actor has been observed exploiting a critical security flaw impacting Cisco Small Business…

  • Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

    Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise A privilege escalation flaw has been demonstrated in Windows Server 2025 that makes it possible for attackers to compromise any user in Active Directory (AD). “The attack exploits the delegated Managed Service Account (dMSA) feature that was introduced in Windows Server 2025, works with the…

  • Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

    Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks A Chinese-speaking threat actor tracked as UAT-6382 has been linked to the exploitation of a now-patched remote-code-execution vulnerability in Trimble Cityworks to deliver Cobalt Strike and VShell. “UAT-6382 successfully exploited CVE-2025-0944, conducted reconnaissance, and rapidly deployed a variety of web shells and custom-made malware…

  • GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

    GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab’s artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into its responses, which could then be used to direct victims to malicious websites.…

  • CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

    CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday revealed that Commvault is monitoring cyber threat activity targeting applications hosted in their Microsoft Azure cloud environment. “Threat actors may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 (M365) backup software-as-a-service…

  • Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

    Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks A recently patched pair of security flaws affecting Ivanti Endpoint Manager Mobile (EPMM) software has been exploited by a China-nexus threat actor to target a wide range of sectors across Europe, North America, and the Asia-Pacific region. The vulnerabilities, tracked as CVE-2025-4427 (CVSS score:…

  • PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms

    PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms Russian organizations have become the target of a phishing campaign that distributes malware called PureRAT, according to new findings from Kaspersky. “The campaign aimed at Russian business began back in March 2023, but in the first third of 2025 the number of attacks…

  • Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

    Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics Russian cyber threat actors have been attributed to a state-sponsored campaign targeting Western logistics entities and technology companies since 2022. The activity has been assessed to be orchestrated by APT28 (aka BlueDelta, Fancy Bear, or Forest Blizzard), which is linked to the…

  • Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims

    Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims Counterfeit Facebook pages and sponsored ads on the social media platform are being employed to direct users to fake websites masquerading as Kling AI with the goal of tricking victims into downloading malware. Kling AI is an artificial intelligence (AI)-powered platform…

  • How to Detect Phishing Attacks Faster: Tycoon2FA Example

    How to Detect Phishing Attacks Faster: Tycoon2FA Example It takes just one email to compromise an entire system. A single well-crafted message can bypass filters, trick employees, and give attackers the access they need. Left undetected, these threats can lead to credential theft, unauthorized access, and even full-scale breaches. As phishing techniques become more evasive,…

  • Securing CI/CD workflows with Wazuh

    Securing CI/CD workflows with Wazuh Continuous Integration and Continuous Delivery/Deployment (CI/CD) refers to practices that automate how code is developed and released to different environments. CI/CD pipelines are fundamental in modern software development, ensuring code is consistently tested, built, and deployed quickly and efficiently. While CI/CD automation accelerates software delivery, it can also introduce security…

  • South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware

    South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder. “The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims…

  • The Crowded Battle: Key Insights from the 2025 State of Pentesting Report

    The Crowded Battle: Key Insights from the 2025 State of Pentesting Report In the newly released 2025 State of Pentesting Report, Pentera surveyed 500 CISOs from global enterprises (200 from within the USA) to understand the strategies, tactics, and tools they use to cope with the thousands of security alerts, the persisting breaches and the…

  • AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation

    AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation Cybersecurity researchers have discovered risky default identity and access management (IAM) roles impacting Amazon Web Services that could open the door for attackers to escalate privileges, manipulate other AWS services, and, in some cases, even fully compromise AWS accounts. “These roles, often created…

  • 100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads

    100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads An unknown threat actor has been attributed to creating several malicious Chrome Browser extensions since February 2024 that masquerade as seemingly benign utilities but incorporate covert functionality to exfiltrate data, receive commands, and execute arbitrary code. “The actor creates websites that masquerade as legitimate…

  • Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

    Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery A threat actor known as Hazy Hawk has been observed hijacking abandoned cloud resources of high-profile organizations, including Amazon S3 buckets and Microsoft Azure endpoints, by leveraging misconfigurations in the Domain Name System (DNS) records. The hijacked domains are then used to…

  • Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards

    Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards Mozilla has released security updates to address two critical security flaws in its Firefox browser that could be potentially exploited to access sensitive data or achieve code execution. The vulnerabilities, both of which were exploited as a zero-day at Pwn2Own Berlin, are listed…

  • Why CTEM is the Winning Bet for CISOs in 2025

    Why CTEM is the Winning Bet for CISOs in 2025 Continuous Threat Exposure Management (CTEM) has moved from concept to cornerstone, solidifying its role as a strategic enabler for CISOs. No longer a theoretical framework, CTEM now anchors today’s cybersecurity programs by continuously aligning security efforts with real-world risk. At the heart of CTEM is…

  • Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access

    Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access Several ransomware actors are using a malware called Skitnet as part of their post-exploitation efforts to steal sensitive data and establish remote control over compromised hosts. “Skitnet has been sold on underground forums like RAMP since April 2024,” Swiss cybersecurity company PRODAFT told…

  • RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer

    RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer The official site for RVTools has been hacked to serve a compromised installer for the popular VMware environment reporting utility. “Robware.net and RVTools.com are currently offline. We are working expeditiously to restore service and appreciate your patience,” the company said in a statement posted…

  • Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts

    Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts Cybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to validate stolen email addresses against TikTok and Instagram APIs. All three packages are no longer available on PyPI. The names of the Python…

  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications

    [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications Modern apps move fast—faster than most security teams can keep up. As businesses rush to build in the cloud, security often lags behind. Teams scan code in isolation, react late to cloud threats, and monitor SOC alerts only after damage…

  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks

    Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks Researchers at ETH Zürich have discovered yet another security flaw that they say impacts all modern Intel CPUs and causes them to leak sensitive data from memory, showing that the vulnerability known as Spectre continues to haunt computer systems after more than…

  • Top 10 Best Practices for Effective Data Protection

    Top 10 Best Practices for Effective Data Protection Data is the lifeblood of productivity, and protecting sensitive data is more critical than ever. With cyber threats evolving rapidly and data privacy regulations tightening, organizations must stay vigilant and proactive to safeguard their most valuable assets. But how do you build an effective data protection framework?…

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors

    New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors Cybersecurity researchers are calling attention to a new botnet malware called HTTPBot that has been used to primarily single out the gaming industry, as well as technology companies and educational institutions in China. “Over the past few months, it has expanded aggressively,…

  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks

    Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks Cybersecurity researchers have shed light on a new malware campaign that makes use of a PowerShell-based shellcode loader to deploy a remote access trojan called Remcos RAT. “Threat actors delivered malicious LNK files embedded within ZIP archives, often disguised as Office documents,” Qualys…

  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit

    Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit Austrian privacy non-profit noyb (none of your business) has sent Meta’s Irish headquarters a cease-and-desist letter, threatening the company with a class action lawsuit if it proceeds with its plans to train users’ data for training its artificial intelligence…

  • Pen Testing for Compliance Only? It’s Time to Change Your Approach

    Pen Testing for Compliance Only? It’s Time to Change Your Approach Imagine this: Your organization completed its annual penetration test in January, earning high marks for security compliance. In February, your development team deployed a routine software update. By April, attackers had already exploited a vulnerability introduced in that February update, gaining access to customer…

  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails

    Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails Cryptocurrency exchange Coinbase has disclosed that unknown cyber actors broke into its systems and stole account data for a small subset of its customers. “Criminals targeted our customer support agents overseas,” the company said in a statement. “They used cash offers to convince…

  • CTM360 Identifies Surge in Phishing Attacks Targeting Meta Business Users

    CTM360 Identifies Surge in Phishing Attacks Targeting Meta Business Users A new global phishing threat called “Meta Mirage” has been uncovered, targeting businesses using Meta’s Business Suite. This campaign specifically aims at hijacking high-value accounts, including those managing advertising and official brand pages. Cybersecurity researchers at CTM360 revealed that attackers behind Meta Mirage impersonate official…

  • Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering

    Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering A Chinese-language, Telegram-based marketplace called Xinbi Guarantee has facilitated no less than $8.4 billion in transactions since 2022, making it the second major black market to be exposed after HuiOne Guarantee. According to a report published by blockchain analytics firm Elliptic,…

  • BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan

    BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan At least two different cybercrime groups BianLian and RansomExx are said to have exploited a recently disclosed security flaw in SAP NetWeaver tracked as CVE-2025-31324, indicating that multiple threat actors are taking advantage of the bug. Cybersecurity firm ReliaQuest, in a new update published…

  • Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit

    Samsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit Samsung has released software updates to address a critical security flaw in MagicINFO 9 Server that has been actively exploited in the wild. The vulnerability, tracked as CVE-2025-4632 (CVSS score: 9.8), has been described as a path traversal flaw. “Improper limitation of a…

  • New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

    New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy Google on Wednesday released updates to address four security issues in its Chrome web browser, including one for which it said there exists an exploit in the wild. The high-severity vulnerability, tracked as CVE-2025-4664 (CVSS score: 4.3), has been characterized as a case of…

  • Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks

    Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks Ivanti has released security updates to address two security flaws in Endpoint Manager Mobile (EPMM) software that have been chained in attacks to gain remote code execution. The vulnerabilities in question are listed below – CVE-2025-4427 (CVSS score: 5.3) – An authentication bypass…

  • Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems

    Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems Fortinet has patched a critical security flaw that it said has been exploited as a zero-day in attacks targeting FortiVoice enterprise phone systems. The vulnerability, tracked as CVE-2025-32756, carries a CVSS score of 9.6 out of 10.0. “A stack-based overflow vulnerability [CWE-121] in FortiVoice, FortiMail,…

  • Deepfake Defense in the Age of AI

    Deepfake Defense in the Age of AI The cybersecurity landscape has been dramatically reshaped by the advent of generative AI. Attackers now leverage large language models (LLMs) to impersonate trusted individuals and automate these social engineering tactics at scale.  Let’s review the status of these rising attacks, what’s fueling them, and how to actually prevent,…

  • Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads

    Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that purports to be an application related to the Solana blockchain, but contains malicious functionality to steal source code and developer secrets. The package, named solana-token, is no…

  • China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

    China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. “Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that enables remote code execution (RCE),” EclecticIQ researcher Arda Büyükkaya said in an analysis…

  • ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files

    ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files ASUS has released updates to address two security flaws impacting ASUS DriverHub that, if successfully exploited, could enable an attacker to leverage the software in order to achieve remote code execution. DriverHub is a tool that’s designed to automatically detect the motherboard model…

  • Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers

    Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers A Türkiye-affiliated threat actor exploited a zero-day security flaw in an Indian enterprise communication platform called Output Messenger as part of a cyber espionage attack campaign since April 2024. “These exploits have resulted in a collection of related user data from targets…

  • The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That

    The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That Detecting leaked credentials is only half the battle. The real challenge—and often the neglected half of the equation—is what happens after detection. New research from GitGuardian’s State of Secrets Sprawl 2025 report reveals a disturbing trend: the vast majority of exposed company secrets…

  • ⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams

    ⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams What do a source code editor, a smart billboard, and a web server have in common? They’ve all become launchpads for attacks—because cybercriminals are rethinking what counts as “infrastructure.” Instead of chasing high-value targets directly, threat actors are now quietly taking over the…

  • Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures

    Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures Threat actors have been observed leveraging fake artificial intelligence (AI)-powered tools as a lure to entice users into downloading an information stealer malware dubbed Noodlophile. “Instead of relying on traditional phishing or cracked software sites, they build convincing AI-themed platforms – often…

  • Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data

    Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data Germany’s Federal Criminal Police Office (aka Bundeskriminalamt or BKA) has seized the online infrastructure and shutdown linked to the eXch cryptocurrency exchange over allegations of money laundering and operating a criminal trading platform. The operation was carried out on April…

  • Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection

    Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection Google has agreed to pay the U.S. state of Texas nearly $1.4 billion to settle two lawsuits that accused the company of tracking users’ personal location and maintaining their facial recognition data without consent. The $1.375 billion payment dwarfs the fines the…

  • Beyond Vulnerability Management – Can You CVE What I CVE?

    Beyond Vulnerability Management – Can You CVE What I CVE? The Vulnerability Treadmill The reactive nature of vulnerability management, combined with delays from policy and process, strains security teams. Capacity is limited and patching everything immediately is a struggle. Our Vulnerability Operation Center (VOC) dataset analysis identified 1,337,797 unique findings (security issues) across 68,500 unique…

  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business

    Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business AI agents are changing the way businesses work. They can answer questions, automate tasks, and create better user experiences. But with this power comes new risks — like data leaks, identity theft, and malicious misuse. If your company is exploring or already using…

  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

    Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials Cybersecurity researchers are warning of a new campaign that’s targeting Portuguese-speaking users in Brazil with trial versions of commercial remote monitoring and management (RMM) software since January 2025. “The spam message uses the Brazilian electronic invoice system, NF-e, as a lure to…

  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities

    OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities The North Korean threat actors behind the Contagious Interview campaign have been observed using updated versions of a cross-platform malware called OtterCookie with capabilities to steal credentials from web browsers and other files. NTT Security Holdings, which detailed the new findings, said the attackers…

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation

    BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation A joint law enforcement operation undertaken by Dutch and U.S. authorities has dismantled a criminal proxy network that’s powered by thousands of infected Internet of Things (IoT) and end-of-life (EoL) devices, enlisting them into a botnet for providing anonymity to malicious…

  • Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures

    Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures Threat actors with ties to the Qilin ransomware family have leveraged malware known as SmokeLoader along with a previously undocumented .NET compiled loader codenamed NETXLOADER as part of a campaign observed in November 2024. “NETXLOADER is a new .NET-based loader that plays a…

  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

    SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access (SMA) appliances that could be fashioned to result in remote code execution. The vulnerabilities are listed below – CVE-2025-32819 (CVSS score: 8.8) – A vulnerability…

  • Security Tools Alone Don’t Protect You — Control Effectiveness Does

    Security Tools Alone Don’t Protect You — Control Effectiveness Does 61% of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This is despite having an average of 43 cybersecurity tools in place. This massive rate of security failure is clearly not a security investment problem. It…

  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases

    38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases Cybersecurity researchers have exposed what they say is an “industrial-scale, global cryptocurrency phishing operation” engineered to steal digital assets from cryptocurrency wallets for several years. The campaign has been codenamed FreeDrain by threat intelligence firms SentinelOne and Validin. “FreeDrain uses SEO manipulation, free-tier…

  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

    Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published today, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since…

  • Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware

    Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware The Russia-linked threat actor known as COLDRIVER has been observed distributing a new malware called LOSTKEYS as part of an espionage-focused campaign using ClickFix-like social engineering lures. “LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending…

  • SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version

    SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, have all been described as XML External…

  • OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws

    OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws A second security flaw impacting the OttoKit (formerly SureTriggers) WordPress plugin has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-27007 (CVSS score: 9.8), is a privilege escalation bug impacting all versions of the plugin prior to and including version…

  • Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks

    Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks Europol has announced the takedown of distributed denial of service (DDoS)-for-hire services that were used to launch thousands of cyber-attacks across the world. In connection with the operation, Polish authorities have arrested four individuals aged between 19 and 22 and the United States has seized…

  • Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT

    Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT Cisco has released software fixes to address a maximum-severity security flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files to a susceptible system. The vulnerability, tracked as CVE-2025-20188, has been rated 10.0…

  • Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet

    Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet Threat actors have been observed actively exploiting security flaws in GeoVision end-of-life (EoL) Internet of Things (IoT) devices to corral them into a Mirai botnet for conducting distributed denial-of-service (DDoS) attacks. The activity, first observed by the Akamai Security Intelligence and Response Team (SIRT)…

  • NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware

    NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware A federal jury on Tuesday decided that NSO Group must pay Meta-owned WhatsApp WhatsApp approximately $168 million in monetary damages, more than four months after a federal judge ruled that the Israeli company violated U.S. laws by exploiting WhatsApp servers to deploy Pegasus…

  • Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks

    Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks Microsoft has warned that using pre-made templates, such as out-of-the-box Helm charts, during Kubernetes deployments could open the door to misconfigurations and leak valuable data. “While these ‘plug-and-play’ options greatly simplify the setup process, they often prioritize ease of use over security,”…

  • Third Parties and Machine Credentials: The Silent Drivers Behind 2025’s Worst Breaches

    Third Parties and Machine Credentials: The Silent Drivers Behind 2025’s Worst Breaches It wasn’t ransomware headlines or zero-day exploits that stood out most in this year’s Verizon 2025 Data Breach Investigations Report (DBIR) — it was what fueled them. Quietly, yet consistently, two underlying factors played a role in some of the worst breaches: third-party…