Category: TheHackersNews

  • Microsoft Patches Actively Exploited Power Pages Privilege Escalation Vulnerability

    Microsoft Patches Actively Exploited Power Pages Privilege Escalation Vulnerability Microsoft has released security updates to address two Critical-rated flaws impacting Bing and Power Pages, including one that has come under active exploitation in the wild. The vulnerabilities are listed below – CVE-2025-21355 (CVSS score: 8.6) – Microsoft Bing Remote Code Execution Vulnerability CVE-2025-24989 (CVSS score:…

  • Citrix Releases Security Fix for NetScaler Console Privilege Escalation Vulnerability

    Citrix Releases Security Fix for NetScaler Console Privilege Escalation Vulnerability Citrix has released security updates for a high-severity security flaw impacting NetScaler Console (formerly NetScaler ADM) and NetScaler Agent that could lead to privilege escalation under certain conditions. The vulnerability, tracked as CVE-2024-12284, has been given a CVSS v4 score of 8.8 out of a…

  • New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now

    New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now Two security vulnerabilities have been discovered in the OpenSSH secure networking utility suite that, if successfully exploited, could result in an active machine-in-the-middle (MitM) and a denial-of-service (DoS) attack, respectively, under certain conditions. The vulnerabilities, detailed by the Qualys Threat Research Unit (TRU), are…

  • CISA Adds Palo Alto Networks and SonicWall Flaws to Exploited Vulnerabilities List

    CISA Adds Palo Alto Networks and SonicWall Flaws to Exploited Vulnerabilities List The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting Palo Alto Networks PAN-OS and SonicWall SonicOS SSLVPN to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The flaws are listed below – CVE-2025-0108…

  • New FrigidStealer Malware Targets macOS Users via Fake Browser Updates

    New FrigidStealer Malware Targets macOS Users via Fake Browser Updates Cybersecurity researchers are alerting to a new campaign that leverages web injects to deliver a new Apple macOS malware known as FrigidStealer. The activity has been attributed to a previously undocumented threat actor known as TA2727, with the information stealers for other platforms such as…

  • Chinese Hackers Exploit MAVInject.exe to Evade Detection in Targeted Cyber Attacks

    Chinese Hackers Exploit MAVInject.exe to Evade Detection in Targeted Cyber Attacks The Chinese state-sponsored threat actor known as Mustang Panda has been observed employing a novel technique to evade detection and maintain control over infected systems. This involves the use of a legitimate Microsoft Windows utility called Microsoft Application Virtualization Injector (MAVInject.exe) to inject the…

  • Debunking the AI Hype: Inside Real Hacker Tactics

    Debunking the AI Hype: Inside Real Hacker Tactics Is AI really reshaping the cyber threat landscape, or is the constant drumbeat of hype drowning out actual, more tangible, real-world dangers? According to Picus Labs’ Red Report 2025 which analyzed over one million malware samples, there’s been no significant surge, so far, in AI-driven attacks. Yes,…

  • ⚡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More

    ⚡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More Welcome to this week’s Cybersecurity News Recap. Discover how cyber attackers are using clever tricks like fake codes and sneaky emails to gain access to sensitive data. We cover everything from device code phishing to cloud exploits, breaking down the technical…

  • CISO’s Expert Guide To CTEM And Why It Matters

    CISO’s Expert Guide To CTEM And Why It Matters Cyber threats evolve—has your defense strategy kept up? A new free guide available here explains why Continuous Threat Exposure Management (CTEM) is the smart approach for proactive cybersecurity. This concise report makes a clear business case for why CTEM’s comprehensive approach is the best overall strategy…

  • South Korea Suspends DeepSeek AI Downloads Over Privacy Violations

    South Korea Suspends DeepSeek AI Downloads Over Privacy Violations South Korea has formally suspended new downloads of Chinese artificial intelligence (AI) chatbot DeepSeek in the country until the service makes changes to its mobile apps to comply with data protection regulations. Downloads have been paused as of February 15, 2025, 6:00 p.m. local time, the…

  • Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics

    Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics Microsoft said it has discovered a new variant of a known Apple macOS malware called XCSSET as part of limited attacks in the wild. “Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection…

  • Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers

    Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers Cybersecurity researchers have flagged a credit card stealing malware campaign that has been observed targeting e-commerce sites running Magento by disguising the malicious content within image tags in HTML code in order to stay under the radar. MageCart is the name given to a…

  • Android’s New Feature Blocks Fraudsters from Sideloading Apps During Calls

    Android’s New Feature Blocks Fraudsters from Sideloading Apps During Calls Google is working on a new security feature for Android that blocks device owners from changing sensitive settings when a phone call is in progress. Specifically, the in-call anti-scammer protections include preventing users from turning on settings to install apps from unknown sources and granting…

  • Lazarus Group Deploys Marstech1 JavaScript Implant in Targeted Developer Attacks

    Lazarus Group Deploys Marstech1 JavaScript Implant in Targeted Developer Attacks The North Korean threat actor known as the Lazarus Group has been linked to a previously undocumented JavaScript implant named Marstech1 as part of limited targeted attacks against developers. The active operation has been dubbed Marstech Mayhem by SecurityScorecard, with the malware delivered by means…

  • New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution

    New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution Cybersecurity researchers have disclosed a new type of name confusion attack called whoAMI that allows anyone who publishes an Amazon Machine Image (AMI) with a specific name to gain code execution within the Amazon Web Services (AWS) account. “If executed at scale, this…

  • RansomHub Becomes 2024’s Top Ransomware Group, Hitting 600+ Organizations Globally

    RansomHub Becomes 2024’s Top Ransomware Group, Hitting 600+ Organizations Globally The threat actors behind the RansomHub ransomware-as-a-service (RaaS) scheme have been observed leveraging now-patched security flaws in Microsoft Active Directory and the Netlogon protocol to escalate privileges and gain unauthorized access to a victim network’s domain controller as part of their post-compromise strategy. “RansomHub has…

  • Microsoft: Russian-Linked Hackers Using ‘Device Code Phishing’ to Hijack Accounts

    Microsoft: Russian-Linked Hackers Using ‘Device Code Phishing’ to Hijack Accounts Microsoft is calling attention to an emerging threat cluster it calls Storm-2372 that has been attributed to a new set of cyber attacks aimed at a variety of sectors since August 2024. The attacks have targeted government, non-governmental organizations (NGOs), information technology (IT) services and…

  • AI-Powered Social Engineering: Ancillary Tools and Techniques

    AI-Powered Social Engineering: Ancillary Tools and Techniques Social engineering is advancing fast, at the speed of generative AI. This is offering bad actors multiple new tools and techniques for researching, scoping, and exploiting organizations. In a recent communication, the FBI pointed out: ‘As technology continues to evolve, so do cybercriminals’ tactics.’ This article explores some…

  • Fast Deployments, Secure Code: Watch this Learn to Sync Dev and Sec Teams

    Fast Deployments, Secure Code: Watch this Learn to Sync Dev and Sec Teams Ever felt like your team is stuck in a constant battle? Developers rush to add new features, while security folks worry about vulnerabilities. What if you could bring both sides together without sacrificing one for the other? We invite you to our…

  • North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks

    North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks A nation-state threat actor with ties to North Korea has been linked to an ongoing campaign targeting South Korean business, government, and cryptocurrency sectors. The attack campaign, dubbed DEEP#DRIVE by Securonix, has been attributed to a hacking group known as Kimsuky, which is…

  • Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners

    Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud. “The attacker targets victims searching for documents on search engines, resulting in…

  • PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks

    PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024 likely also exploited a previously unknown SQL injection flaw in PostgreSQL, according to findings from Rapid7. The vulnerability, tracked as CVE-2025-1094…

  • RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset

    RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset An RA World ransomware attack in November 2024 targeting an unnamed Asian software and services company involved the use of a malicious tool exclusively used by China-based cyber espionage groups, raising the possibility that the threat actor may be moonlighting as a ransomware…

  • How to Steer AI Adoption: A CISO Guide

    How to Steer AI Adoption: A CISO Guide CISOs are finding themselves more involved in AI teams, often leading the cross-functional effort and AI strategy. But there aren’t many resources to guide them on what their role should look like or what they should bring to these meetings.  We’ve pulled together a framework for security…

  • Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability

    Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability Cybersecurity researchers have discovered a bypass for a now-patched security vulnerability in the NVIDIA Container Toolkit that could be exploited to break out of a container’s isolation protections and gain complete access to the underlying host. The new vulnerability is being tracked as CVE-2025-23359 (CVSS…

  • Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries

    Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries A subgroup within the infamous Russian state-sponsored hacking group known as Sandworm has been attributed to a multi-year initial access operation dubbed BadPilot that stretched across the globe. “This subgroup has conducted globally diverse compromises of Internet-facing infrastructure to enable Seashell Blizzard to persist on…

  • Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation

    Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation Microsoft on Tuesday released fixes for 63 security flaws impacting its software products, including two vulnerabilities that it said has come under active exploitation in the wild. Of the 63 vulnerabilities, three are rated Critical, 57 are rated Important, one is rated Moderate, and…

  • North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack

    North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack The North Korea-linked threat actor known as Kimsuky has been observed using a new tactic that involves deceiving targets into running PowerShell as an administrator and then instructing them to paste and run malicious code provided by them. “To execute this tactic, the…

  • Gcore DDoS Radar Reveals 56% YoY Increase in DDoS Attacks

    Gcore DDoS Radar Reveals 56% YoY Increase in DDoS Attacks Gcore’s latest DDoS Radar report analyzes attack data from Q3–Q4 2024, revealing a 56% YoY rise in the total number of DDoS attacks with the largest attack peaking at a record 2 Tbps. The financial services sector saw the most dramatic increase, with a 117%…

  • Progress Software Patches High-Severity LoadMaster Flaws Affecting Multiple Versions

    Progress Software Patches High-Severity LoadMaster Flaws Affecting Multiple Versions Progress Software has addressed multiple high-severity security flaws in its LoadMaster software that could be exploited by malicious actors to execute arbitrary system commands or download any file from the system. Kemp LoadMaster is a high-performance application delivery controller (ADC) and load balancer that provides availability,…

  • 4 Ways to Keep MFA From Becoming too Much of a Good Thing

    4 Ways to Keep MFA From Becoming too Much of a Good Thing Multi-factor authentication (MFA) has quickly become the standard for securing business accounts. Once a niche security measure, adoption is on the rise across industries. But while it’s undeniably effective at keeping bad actors out, the implementation of MFA solutions can be a…

  • Google Confirms Android SafetyCore Enables AI-Powered On-Device Content Classification

    Google Confirms Android SafetyCore Enables AI-Powered On-Device Content Classification Google has stepped in to clarify that a newly introduced Android System SafetyCore app does not perform any client-side scanning of content. “Android provides many on-device protections that safeguard users against threats like malware, messaging spam and abuse protections, and phone scam protections, while preserving user…

  • Ivanti Patches Critical Flaws in Connect Secure and Policy Secure – Update Now

    Ivanti Patches Critical Flaws in Connect Secure and Policy Secure – Update Now Ivanti has released security updates to address multiple security flaws impacting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA) that could be exploited to achieve arbitrary code execution. The list of vulnerabilities is below – CVE-2024-38657 (CVSS score: 9.1)…

  • Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update

    Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update Apple on Monday released out-of-band security updates to address a security flaw in iOS and iPadOS that it said has been exploited in the wild. Assigned the CVE identifier CVE-2025-24200, the vulnerability has been described as an authorization issue that could make it possible for…

  • DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling Redirects

    DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling Redirects Threat actors have been observed targeting Internet Information Services (IIS) servers in Asia as part of a search engine optimization (SEO) manipulation campaign designed to install BadIIS malware. “It is likely that the campaign is financially motivated since redirecting users to illegal…

  • Don’t Overlook These 6 Critical Okta Security Configurations

    Don’t Overlook These 6 Critical Okta Security Configurations Given Okta’s role as a critical part of identity infrastructure, strengthening Okta security is essential. This article covers six key Okta security settings that provide a strong starting point, along with recommendations for implementing continuous monitoring of your Okta security posture. With over 18,000 customers, Okta serves…

  • ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February]

    ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February] In cybersecurity, the smallest crack can lead to the biggest breaches. A leaked encryption key, an unpatched software bug, or an abandoned cloud storage bucket—each one seems minor until it becomes the entry point for an attack. This week, we’ve seen cybercriminals turn…

  • Hackers Exploit Google Tag Manager to Deploy Credit Card Skimmers on Magento Stores

    Hackers Exploit Google Tag Manager to Deploy Credit Card Skimmers on Magento Stores Threat actors have been observed leveraging Google Tag Manager (GTM) to deliver credit card skimmer malware targeting Magento-based e-commerce websites. Website security company Sucuri said the code, while appearing to be a typical GTM and Google Analytics script used for website analytics…

  • XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells

    XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells Threat actors have been observed exploiting multiple security flaws in various software products, including Progress Telerik UI for ASP.NET AJAX and Advantive VeraCore, to drop reverse shells and web shells, and maintain persistent remote access to compromised systems. The zero-day exploitation of security flaws…

  • Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks

    Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks Microsoft is warning of an insecure practice wherein software developers are incorporating publicly disclosed ASP.NET machine keys from publicly accessible resources, thereby putting their applications in attackers’ pathway. The tech giant’s threat intelligence team said it observed limited activity in December 2024 that involved an…

  • AI-Powered Social Engineering: Reinvented Threats

    AI-Powered Social Engineering: Reinvented Threats The foundations for social engineering attacks – manipulating humans – might not have changed much over the years. It’s the vectors – how these techniques are deployed – that are evolving. And like most industries these days, AI is accelerating its evolution.  This article explores how these changes are impacting…

  • CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability

    CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a security flaw impacting Trimble Cityworks GIS-centric asset management software has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0994 (CVSS v4 score: 8.6), a deserialization of untrusted data bug that…

  • DeepSeek App Transmits Sensitive User and Device Data Without Encryption

    DeepSeek App Transmits Sensitive User and Device Data Without Encryption A new audit of DeepSeek’s mobile app for the Apple iOS operating system has found glaring security issues, the foremost being that it sends sensitive data over the internet sans any encryption, exposing it to interception and manipulation attacks. The assessment comes from NowSecure, which…

  • Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection

    Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection Cybersecurity researchers have uncovered two malicious machine learning (ML) models on Hugging Face that leveraged an unusual technique of “broken” pickle files to evade detection. “The pickle files extracted from the mentioned PyTorch archives revealed the malicious Python content at the beginning…

  • The Evolving Role of PAM in Cybersecurity Leadership Agendas for 2025

    The Evolving Role of PAM in Cybersecurity Leadership Agendas for 2025 Privileged Access Management (PAM) has emerged as a cornerstone of modern cybersecurity strategies, shifting from a technical necessity to a critical pillar in leadership agendas. With the PAM market projected to reach $42.96 billion by 2037 (according to Research Nester), organizations invest heavily in…

  • SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images

    SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images A new malware campaign dubbed SparkCat has leveraged a suit of bogus apps on both Apple’s and Google’s respective app stores to steal victims’ mnemonic phrases associated with cryptocurrency wallets.  The attacks leverage an optical character recognition (OCR) model to exfiltrate select images…

  • Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023

    Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023 Ransomware attacks netted cybercrime groups a total of $813.5 million in 2024, a decline from $1.25 billion in 2023. The total amount extorted during the first half of 2024 stood at $459.8 million, blockchain intelligence firm Chainalysis said, adding payment activity slumped after…

  • Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking

    Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking Bogus websites advertising Google Chrome have been used to distribute malicious installers for a remote access trojan called ValleyRAT. The malware, first detected in 2023, is attributed to a threat actor tracked as Silver Fox, with prior attack campaigns primarily targeting Chinese-speaking regions like Hong…

  • Hackers Exploiting SimpleHelp RMM Flaws for Persistent Access and Ransomware

    Hackers Exploiting SimpleHelp RMM Flaws for Persistent Access and Ransomware Threat actors have been observed exploiting recently disclosed security flaws in SimpleHelp’s Remote Monitoring and Management (RMM) software as a precursor for what appears to be a ransomware attack. The intrusion leveraged the now-patched vulnerabilities to gain initial access and maintain persistent remote access to…

  • Navigating the Future: Key IT Vulnerability Management Trends 

    Navigating the Future: Key IT Vulnerability Management Trends  As the cybersecurity landscape continues to evolve, proactive vulnerability management has become a critical priority for managed service providers (MSPs) and IT teams. Recent trends indicate that organizations increasingly prioritize more frequent IT security vulnerability assessments to identify and address potential security flaws. Staying informed on these…

  • New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack

    New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack Veeam has released patches to address a critical security flaw impacting its Backup software that could allow an attacker to execute arbitrary code on susceptible systems. The vulnerability, tracked as CVE-2025-23114, carries a CVSS score of 9.0 out of 10.0. “A vulnerability within the Veeam…

  • Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks

    Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks A previously undocumented threat actor known as Silent Lynx has been linked to cyber attacks targeting various entities in Kyrgyzstan and Turkmenistan. “This threat group has previously targeted entities around Eastern Europe and Central Asian government think tanks involved in economic decision making and…

  • Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

    Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts Cybercriminals are increasingly leveraging legitimate HTTP client tools to facilitate account takeover (ATO) attacks on Microsoft 365 environments. Enterprise security company Proofpoint said it observed campaigns using HTTP clients Axios and Node Fetch to send HTTP requests and receive HTTP responses from…

  • Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign

    Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign The North Korea-linked Lazarus Group has been linked to an active campaign that leverages fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malware capable of infecting Windows, macOS, and Linux operating systems. According to cybersecurity company Bitdefender, the scam begins…

  • North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS

    North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS The North Korean threat actors behind the Contagious Interview campaign have been observed delivering a collection of Apple macOS malware strains dubbed FERRET as part of a supposed job interview process. “Targets are typically asked to communicate with an interviewer through a link…

  • Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections

    Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections A recently patched security vulnerability in the 7-Zip archiver tool was exploited in the wild to deliver the SmokeLoader malware. The flaw, CVE-2025-0411 (CVSS score: 7.0), allows remote attackers to circumvent mark-of-the-web (MotW) protections and execute arbitrary code in the context of the current…

  • Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access

    Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access Cybersecurity researchers have called attention to a software supply chain attack targeting the Go ecosystem that involves a malicious package capable of granting the adversary remote access to infected systems. The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt),…

  • CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25

    CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2024-45195 (CVSS score: 7.5/9.8)…

  • Watch Out For These 8 Cloud Security Shifts in 2025

    Watch Out For These 8 Cloud Security Shifts in 2025 As cloud security evolves in 2025 and beyond, organizations must adapt to both new and evolving realities, including the increasing reliance on cloud infrastructure for AI-driven workflows and the vast quantities of data being migrated to the cloud. But there are other developments that could…

  • Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform

    Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform Cybersecurity researchers have disclosed details of a now-patched vulnerability impacting the Microsoft SharePoint connector on Power Platform that, if successfully exploited, could allow threat actors to harvest a user’s credentials and stage follow-on attacks. This could manifest in the form of post-exploitation actions that…

  • Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104

    Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104 Google has shipped patches to address 47 security flaws in its Android operating system, including one it said has come under active exploitation in the wild. The vulnerability in question is CVE-2024-53104 (CVSS score: 7.8), which has been described as a case of privilege escalation…

  • Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score

    Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges under certain conditions. The flaws are listed below – CVE-2025-21396 (CVSS score: 7.5) – Microsoft…

  • PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages

    PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages The maintainers of the Python Package Index (PyPI) registry have announced a new feature that allows package developers to archive a project as part of efforts to improve supply chain security. “Maintainers can now archive a project to let users know that the project…

  • 768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023

    768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023 As many as 768 vulnerabilities with designated CVE identifiers were reported as exploited in the wild in 2024, up from 639 CVEs in 2023, registering a 20% increase year-over-year. Describing 2024 as “another banner year for threat actors targeting the exploitation of…

  • Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware

    Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware A Russian-speaking cybercrime gang known as Crazy Evil has been linked to over 10 active social media scams that leverage a wide range of tailored lures to deceive victims and trick them into installing malware such as StealC, Atomic macOS Stealer (aka AMOS),…

  • U.S. and Dutch Authorities Dismantle 39 Domains Linked to BEC Fraud Network

    U.S. and Dutch Authorities Dismantle 39 Domains Linked to BEC Fraud Network U.S. and Dutch law enforcement agencies have announced that they have dismantled 39 domains and their associated servers as part of efforts to disrupt a network of online marketplaces originating from Pakistan. The action, which took place on January 29, 2025, has been…

  • Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists

    Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists Meta-owned WhatsApp on Friday said it disrupted a campaign that involved the use of spyware to target journalists and civil society members. The campaign, which targeted around 90 members, involved the use of spyware from an Israeli company known as Paragon Solutions. The attackers were…

  • BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key

    BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key BeyondTrust has revealed it completed an investigation into a recent cybersecurity incident that targeted some of the company’s Remote Support SaaS instances by making use of a compromised API key. The company said the breach involved 17 Remote Support SaaS customers and that the…

  • CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors

    CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Food and Drug Administration (FDA) have issued alerts about the presence of hidden functionality in Contec CMS8000 patient monitors and Epsimed MN-120 patient monitors. The vulnerability, tracked as CVE-2025-0626, carries a CVSS v4…

  • Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts

    Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts Cybersecurity researchers have discovered a malvertising campaign that’s targeting Microsoft advertisers with bogus Google ads that aim to take them to phishing pages that are capable of harvesting their credentials. “These malicious ads, appearing on Google Search, are designed to steal the login information…

  • Top 5 AI-Powered Social Engineering Attacks

    Top 5 AI-Powered Social Engineering Attacks Social engineering has long been an effective tactic because of how it focuses on human vulnerabilities. There’s no brute-force ‘spray and pray’ password guessing. No scouring systems for unpatched software. Instead, it simply relies on manipulating emotions such as trust, fear, and respect for authority, usually with the goal…

  • SOC Analysts – Reimagining Their Role Using AI

    SOC Analysts – Reimagining Their Role Using AI The job of a SOC analyst has never been easy. Faced with an overwhelming flood of daily alerts, analysts (and sometimes IT teams who are doubling as SecOps) must try and triage thousands of security alerts—often false positives—just to identify a handful of real threats. This relentless,…

  • Lightning AI Studio Vulnerability Could’ve Allowed RCE via Hidden URL Parameter

    Lightning AI Studio Vulnerability Could’ve Allowed RCE via Hidden URL Parameter Cybersecurity researchers have disclosed a critical security flaw in the Lightning AI Studio development platform that, if successfully exploited, could have allowed for remote code execution. The vulnerability, rated a CVSS score of 9.4, enables “attackers to potentially execute arbitrary commands with root privileges”…

  • Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown

    Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown An international law enforcement operation has dismantled the domains associated with various online platforms linked to cybercrime such as Cracked, Nulled, Sellix, and StarkRDP. The effort, which took place between January 28 and 30, 2025, targeted the following domains – www.cracked.io www.nulled.to www.mysellix.io www.sellix.io…

  • Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations

    Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations Over 57 distinct threat actors with ties to China, Iran, North Korea, and Russia have been observed using artificial intelligence (AI) technology powered by Google to further enable their malicious cyber and information operations. “Threat actors are experimenting with Gemini to enable their operations,…

  • Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft

    Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information. The list of identified flaws, which impact versions 8.x…

  • New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits

    New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits A team of security researchers from Georgia Institute of Technology and Ruhr University Bochum has demonstrated two new side-channel attacks targeting Apple silicon that could be exploited to leak sensitive information from web browsers like Safari and Google Chrome. The attacks have…

  • AI in Cybersecurity: What’s Effective and What’s Not – Insights from 200 Experts

    AI in Cybersecurity: What’s Effective and What’s Not – Insights from 200 Experts Curious about the buzz around AI in cybersecurity? Wonder if it’s just a shiny new toy in the tech world or a serious game changer? Let’s unpack this together in a not-to-be-missed webinar that goes beyond the hype to explore the real…

  • Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks

    Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks The North Korean threat actor known as the Lazarus Group has been observed leveraging a “web-based administrative platform” to oversee its command-and-control (C2) infrastructure, giving the adversary the ability to centrally supervise all aspects of their campaigns. “Each C2 server hosted a web-based administrative…

  • Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution

    Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution A critical security flaw has been disclosed in the Cacti open-source network monitoring and fault management framework that could allow an authenticated attacker to achieve remote code execution on susceptible instances. The flaw, tracked as CVE-2025-22604, carries a CVSS score of 9.1 out of a maximum…

  • How Interlock Ransomware Infects Healthcare Organizations

    How Interlock Ransomware Infects Healthcare Organizations Ransomware attacks have reached an unprecedented scale in the healthcare sector, exposing vulnerabilities that put millions at risk. Recently, UnitedHealth revealed that 190 million Americans had their personal and healthcare data stolen during the Change Healthcare ransomware attack, a figure that nearly doubles the previously disclosed total.  This breach…

  • OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking

    OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals. “By exploiting this flaw, attackers can gain unauthorized access to any user’s account within the system, effectively allowing them to impersonate…

  • PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks

    PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks A financially motivated threat actor has been linked to an ongoing phishing email campaign that has been ongoing since at least July 2024 specifically targeting users in Poland and Germany. The attacks have led to the deployment of various payloads, such as Agent Tesla,…

  • Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability

    Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability Cybersecurity researchers are warning that a critical zero-day vulnerability impacting Zyxel CPE Series devices is seeing active exploitation attempts in the wild. “Attackers can leverage this vulnerability to execute arbitrary commands on affected devices, leading to complete system compromise, data exfiltration, or network infiltration,”…

  • Broadcom Warns of High-Severity SQL Injection Flaw in VMware Avi Load Balancer

    Broadcom Warns of High-Severity SQL Injection Flaw in VMware Avi Load Balancer Broadcom has alerted of a high-severity security flaw in VMware Avi Load Balancer that could be weaponized by malicious actors to gain entrenched database access. The vulnerability, tracked as CVE-2025-22217 (CVSS score: 8.6), has been described as an unauthenticated blind SQL injection. “A…

  • UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents

    UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents The advanced persistent threat (APT) group known as UAC-0063 has been observed leveraging legitimate documents obtained by infiltrating one victim to attack another target with the goal of delivering a known malware dubbed HATVIBE. “This research focuses on completing the picture of UAC-0063’s operations, particularly…

  • ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]

    ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January] Welcome to your weekly cybersecurity scoop! Ever thought about how the same AI meant to protect our hospitals could also compromise them? This week, we’re breaking down the sophisticated world of AI-driven threats, key updates in regulations, and some urgent vulnerabilities in healthcare…

  • GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

    GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs Multiple security vulnerabilities have been disclosed in GitHub Desktop as well as other Git-related projects that, if successfully exploited, could permit an attacker to gain unauthorized access to a user’s Git credentials. “Git implements a protocol called Git Credential Protocol to retrieve credentials from the…

  • Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More

    Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More Apple has released software updates to address several security flaws across its portfolio, including a zero-day vulnerability that it said has been exploited in the wild. The vulnerability, tracked as CVE-2025-24085, has been described as a use-after-free bug in the Core Media component that could…

  • Top-Rated Chinese AI App DeepSeek Limits Registrations Amid Cyberattacks

    Top-Rated Chinese AI App DeepSeek Limits Registrations Amid Cyberattacks DeepSeek, the Chinese AI startup that has captured much of the artificial intelligence (AI) buzz in recent days, said it’s restricting registrations on the service, citing malicious attacks. “Due to large-scale malicious attacks on DeepSeek’s services, we are temporarily limiting registrations to ensure continued service,” the…

  • Do We Really Need The OWASP NHI Top 10?

    Do We Really Need The OWASP NHI Top 10? The Open Web Application Security Project has recently introduced a new Top 10 project – the Non-Human Identity (NHI) Top 10. For years, OWASP has provided security professionals and developers with essential guidance and actionable frameworks through its Top 10 projects, including the widely used API…

  • Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

    Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks A high-severity security flaw has been disclosed in Meta’s Llama large language model (LLM) framework that, if successfully exploited, could allow an attacker to execute arbitrary code on the llama-stack inference server.  The vulnerability, tracked as CVE-2024-50050, has been assigned a CVSS score…

  • Android’s New Identity Check Feature Locks Device Settings Outside Trusted Locations

    Android’s New Identity Check Feature Locks Device Settings Outside Trusted Locations Google has launched a new feature called Identity Check for supported Android devices that locks sensitive settings behind biometric authentication when outside of trusted locations. “When you turn on Identity Check, your device will require explicit biometric authentication to access certain sensitive resources when…

  • DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations

    DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations The U.S. Department of Justice (DoJ) on Thursday indicted two North Korean nationals, a Mexican national, and two of its own citizens for their alleged involvement in the ongoing fraudulent information technology (IT) worker scheme that seeks to generate revenue for the Democratic…

  • 2025 State of SaaS Backup and Recovery Report

    2025 State of SaaS Backup and Recovery Report The modern workplace has undergone a seismic transformation over recent years, with hybrid work becoming the norm and businesses rapidly adopting cloud-based Software-as-a-Service (SaaS) applications to facilitate it. SaaS applications like Microsoft 365 and Google Workspace have now become the backbone of business operations, enabling seamless collaboration…

  • RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations

    RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even gain a foothold into the cellular core network. The 119 vulnerabilities, assigned…

  • CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List

    CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The medium-severity vulnerability is CVE-2020-11023 (CVSS score: 6.1/6.9), a nearly five-year-old…

  • Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers

    Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers Enterprise-grade Juniper Networks routers have become the target of a custom backdoor as part of a campaign dubbed J-magic. According to the Black Lotus Labs team at Lumen Technologies, the activity is so named for the fact that the backdoor continuously monitors for a “magic packet”…

  • New Research: The State of Web Exposure 2025

    New Research: The State of Web Exposure 2025 Are your websites leaking sensitive data? New research reveals that 45% of third-party apps access user info without proper authorization, and 53% of risk exposures in Retail are due to the excessive use of tracking tools. Learn how to uncover and mitigate these hidden threats and risks—download…

  • Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks

    Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks Cybersecurity researchers are calling attention to a new malware campaign that leverages fake CAPTCHA verification checks to deliver the infamous Lumma information stealer. “The campaign is global, with Netskope Threat Labs tracking victims targeted in Argentina, Colombia, the United States, the Philippines, and other countries…