Category: TheHackersNews
-
AI-Powered Social Engineering: Ancillary Tools and Techniques
AI-Powered Social Engineering: Ancillary Tools and Techniques Social engineering is advancing fast, at the speed of generative AI. This is offering bad actors multiple new tools and techniques for researching, scoping, and exploiting organizations. In a recent communication, the FBI pointed out: ‘As technology continues to evolve, so do cybercriminals’ tactics.’ This article explores some…
-
Fast Deployments, Secure Code: Watch this Learn to Sync Dev and Sec Teams
Fast Deployments, Secure Code: Watch this Learn to Sync Dev and Sec Teams Ever felt like your team is stuck in a constant battle? Developers rush to add new features, while security folks worry about vulnerabilities. What if you could bring both sides together without sacrificing one for the other? We invite you to our…
-
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks A nation-state threat actor with ties to North Korea has been linked to an ongoing campaign targeting South Korean business, government, and cryptocurrency sectors. The attack campaign, dubbed DEEP#DRIVE by Securonix, has been attributed to a hacking group known as Kimsuky, which is…
-
Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud. “The attacker targets victims searching for documents on search engines, resulting in…
-
PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks
PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024 likely also exploited a previously unknown SQL injection flaw in PostgreSQL, according to findings from Rapid7. The vulnerability, tracked as CVE-2025-1094…
-
RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset
RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset An RA World ransomware attack in November 2024 targeting an unnamed Asian software and services company involved the use of a malicious tool exclusively used by China-based cyber espionage groups, raising the possibility that the threat actor may be moonlighting as a ransomware…
-
How to Steer AI Adoption: A CISO Guide
How to Steer AI Adoption: A CISO Guide CISOs are finding themselves more involved in AI teams, often leading the cross-functional effort and AI strategy. But there aren’t many resources to guide them on what their role should look like or what they should bring to these meetings. We’ve pulled together a framework for security…
-
Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability
Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability Cybersecurity researchers have discovered a bypass for a now-patched security vulnerability in the NVIDIA Container Toolkit that could be exploited to break out of a container’s isolation protections and gain complete access to the underlying host. The new vulnerability is being tracked as CVE-2025-23359 (CVSS…
-
Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries
Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries A subgroup within the infamous Russian state-sponsored hacking group known as Sandworm has been attributed to a multi-year initial access operation dubbed BadPilot that stretched across the globe. “This subgroup has conducted globally diverse compromises of Internet-facing infrastructure to enable Seashell Blizzard to persist on…
-
Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation
Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation Microsoft on Tuesday released fixes for 63 security flaws impacting its software products, including two vulnerabilities that it said has come under active exploitation in the wild. Of the 63 vulnerabilities, three are rated Critical, 57 are rated Important, one is rated Moderate, and…
-
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack The North Korea-linked threat actor known as Kimsuky has been observed using a new tactic that involves deceiving targets into running PowerShell as an administrator and then instructing them to paste and run malicious code provided by them. “To execute this tactic, the…
-
Gcore DDoS Radar Reveals 56% YoY Increase in DDoS Attacks
Gcore DDoS Radar Reveals 56% YoY Increase in DDoS Attacks Gcore’s latest DDoS Radar report analyzes attack data from Q3–Q4 2024, revealing a 56% YoY rise in the total number of DDoS attacks with the largest attack peaking at a record 2 Tbps. The financial services sector saw the most dramatic increase, with a 117%…
-
Progress Software Patches High-Severity LoadMaster Flaws Affecting Multiple Versions
Progress Software Patches High-Severity LoadMaster Flaws Affecting Multiple Versions Progress Software has addressed multiple high-severity security flaws in its LoadMaster software that could be exploited by malicious actors to execute arbitrary system commands or download any file from the system. Kemp LoadMaster is a high-performance application delivery controller (ADC) and load balancer that provides availability,…
-
4 Ways to Keep MFA From Becoming too Much of a Good Thing
4 Ways to Keep MFA From Becoming too Much of a Good Thing Multi-factor authentication (MFA) has quickly become the standard for securing business accounts. Once a niche security measure, adoption is on the rise across industries. But while it’s undeniably effective at keeping bad actors out, the implementation of MFA solutions can be a…
-
Google Confirms Android SafetyCore Enables AI-Powered On-Device Content Classification
Google Confirms Android SafetyCore Enables AI-Powered On-Device Content Classification Google has stepped in to clarify that a newly introduced Android System SafetyCore app does not perform any client-side scanning of content. “Android provides many on-device protections that safeguard users against threats like malware, messaging spam and abuse protections, and phone scam protections, while preserving user…
-
Ivanti Patches Critical Flaws in Connect Secure and Policy Secure – Update Now
Ivanti Patches Critical Flaws in Connect Secure and Policy Secure – Update Now Ivanti has released security updates to address multiple security flaws impacting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA) that could be exploited to achieve arbitrary code execution. The list of vulnerabilities is below – CVE-2024-38657 (CVSS score: 9.1)…
-
Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update
Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update Apple on Monday released out-of-band security updates to address a security flaw in iOS and iPadOS that it said has been exploited in the wild. Assigned the CVE identifier CVE-2025-24200, the vulnerability has been described as an authorization issue that could make it possible for…
-
DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling Redirects
DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling Redirects Threat actors have been observed targeting Internet Information Services (IIS) servers in Asia as part of a search engine optimization (SEO) manipulation campaign designed to install BadIIS malware. “It is likely that the campaign is financially motivated since redirecting users to illegal…
-
Don’t Overlook These 6 Critical Okta Security Configurations
Don’t Overlook These 6 Critical Okta Security Configurations Given Okta’s role as a critical part of identity infrastructure, strengthening Okta security is essential. This article covers six key Okta security settings that provide a strong starting point, along with recommendations for implementing continuous monitoring of your Okta security posture. With over 18,000 customers, Okta serves…
-
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February]
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February] In cybersecurity, the smallest crack can lead to the biggest breaches. A leaked encryption key, an unpatched software bug, or an abandoned cloud storage bucket—each one seems minor until it becomes the entry point for an attack. This week, we’ve seen cybercriminals turn…
-
Hackers Exploit Google Tag Manager to Deploy Credit Card Skimmers on Magento Stores
Hackers Exploit Google Tag Manager to Deploy Credit Card Skimmers on Magento Stores Threat actors have been observed leveraging Google Tag Manager (GTM) to deliver credit card skimmer malware targeting Magento-based e-commerce websites. Website security company Sucuri said the code, while appearing to be a typical GTM and Google Analytics script used for website analytics…
-
XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells
XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells Threat actors have been observed exploiting multiple security flaws in various software products, including Progress Telerik UI for ASP.NET AJAX and Advantive VeraCore, to drop reverse shells and web shells, and maintain persistent remote access to compromised systems. The zero-day exploitation of security flaws…
-
Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks
Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks Microsoft is warning of an insecure practice wherein software developers are incorporating publicly disclosed ASP.NET machine keys from publicly accessible resources, thereby putting their applications in attackers’ pathway. The tech giant’s threat intelligence team said it observed limited activity in December 2024 that involved an…
-
AI-Powered Social Engineering: Reinvented Threats
AI-Powered Social Engineering: Reinvented Threats The foundations for social engineering attacks – manipulating humans – might not have changed much over the years. It’s the vectors – how these techniques are deployed – that are evolving. And like most industries these days, AI is accelerating its evolution. This article explores how these changes are impacting…
-
CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability
CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a security flaw impacting Trimble Cityworks GIS-centric asset management software has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0994 (CVSS v4 score: 8.6), a deserialization of untrusted data bug that…
-
DeepSeek App Transmits Sensitive User and Device Data Without Encryption
DeepSeek App Transmits Sensitive User and Device Data Without Encryption A new audit of DeepSeek’s mobile app for the Apple iOS operating system has found glaring security issues, the foremost being that it sends sensitive data over the internet sans any encryption, exposing it to interception and manipulation attacks. The assessment comes from NowSecure, which…
-
Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection
Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade Detection Cybersecurity researchers have uncovered two malicious machine learning (ML) models on Hugging Face that leveraged an unusual technique of “broken” pickle files to evade detection. “The pickle files extracted from the mentioned PyTorch archives revealed the malicious Python content at the beginning…
-
The Evolving Role of PAM in Cybersecurity Leadership Agendas for 2025
The Evolving Role of PAM in Cybersecurity Leadership Agendas for 2025 Privileged Access Management (PAM) has emerged as a cornerstone of modern cybersecurity strategies, shifting from a technical necessity to a critical pillar in leadership agendas. With the PAM market projected to reach $42.96 billion by 2037 (according to Research Nester), organizations invest heavily in…
-
SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images
SparkCat Malware Uses OCR to Extract Crypto Wallet Recovery Phrases from Images A new malware campaign dubbed SparkCat has leveraged a suit of bogus apps on both Apple’s and Google’s respective app stores to steal victims’ mnemonic phrases associated with cryptocurrency wallets. The attacks leverage an optical character recognition (OCR) model to exfiltrate select images…
-
Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023
Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023 Ransomware attacks netted cybercrime groups a total of $813.5 million in 2024, a decline from $1.25 billion in 2023. The total amount extorted during the first half of 2024 stood at $459.8 million, blockchain intelligence firm Chainalysis said, adding payment activity slumped after…
-
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking Bogus websites advertising Google Chrome have been used to distribute malicious installers for a remote access trojan called ValleyRAT. The malware, first detected in 2023, is attributed to a threat actor tracked as Silver Fox, with prior attack campaigns primarily targeting Chinese-speaking regions like Hong…
-
Hackers Exploiting SimpleHelp RMM Flaws for Persistent Access and Ransomware
Hackers Exploiting SimpleHelp RMM Flaws for Persistent Access and Ransomware Threat actors have been observed exploiting recently disclosed security flaws in SimpleHelp’s Remote Monitoring and Management (RMM) software as a precursor for what appears to be a ransomware attack. The intrusion leveraged the now-patched vulnerabilities to gain initial access and maintain persistent remote access to…
-
Navigating the Future: Key IT Vulnerability Management Trends
Navigating the Future: Key IT Vulnerability Management Trends As the cybersecurity landscape continues to evolve, proactive vulnerability management has become a critical priority for managed service providers (MSPs) and IT teams. Recent trends indicate that organizations increasingly prioritize more frequent IT security vulnerability assessments to identify and address potential security flaws. Staying informed on these…
-
New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack
New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack Veeam has released patches to address a critical security flaw impacting its Backup software that could allow an attacker to execute arbitrary code on susceptible systems. The vulnerability, tracked as CVE-2025-23114, carries a CVSS score of 9.0 out of 10.0. “A vulnerability within the Veeam…
-
Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks
Silent Lynx Using PowerShell, Golang, and C++ Loaders in Multi-Stage Cyberattacks A previously undocumented threat actor known as Silent Lynx has been linked to cyber attacks targeting various entities in Kyrgyzstan and Turkmenistan. “This threat group has previously targeted entities around Eastern Europe and Central Asian government think tanks involved in economic decision making and…
-
Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts
Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts Cybercriminals are increasingly leveraging legitimate HTTP client tools to facilitate account takeover (ATO) attacks on Microsoft 365 environments. Enterprise security company Proofpoint said it observed campaigns using HTTP clients Axios and Node Fetch to send HTTP requests and receive HTTP responses from…
-
Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign
Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group Campaign The North Korea-linked Lazarus Group has been linked to an active campaign that leverages fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malware capable of infecting Windows, macOS, and Linux operating systems. According to cybersecurity company Bitdefender, the scam begins…
-
North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS
North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS The North Korean threat actors behind the Contagious Interview campaign have been observed delivering a collection of Apple macOS malware strains dubbed FERRET as part of a supposed job interview process. “Targets are typically asked to communicate with an interviewer through a link…
-
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections A recently patched security vulnerability in the 7-Zip archiver tool was exploited in the wild to deliver the SmokeLoader malware. The flaw, CVE-2025-0411 (CVSS score: 7.0), allows remote attackers to circumvent mark-of-the-web (MotW) protections and execute arbitrary code in the context of the current…
-
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access Cybersecurity researchers have called attention to a software supply chain attack targeting the Go ecosystem that involves a malicious package capable of granting the adversary remote access to infected systems. The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt),…
-
CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25
CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows – CVE-2024-45195 (CVSS score: 7.5/9.8)…
-
Watch Out For These 8 Cloud Security Shifts in 2025
Watch Out For These 8 Cloud Security Shifts in 2025 As cloud security evolves in 2025 and beyond, organizations must adapt to both new and evolving realities, including the increasing reliance on cloud infrastructure for AI-driven workflows and the vast quantities of data being migrated to the cloud. But there are other developments that could…
-
Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform
Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform Cybersecurity researchers have disclosed details of a now-patched vulnerability impacting the Microsoft SharePoint connector on Power Platform that, if successfully exploited, could allow threat actors to harvest a user’s credentials and stage follow-on attacks. This could manifest in the form of post-exploitation actions that…
-
Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104
Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024-53104 Google has shipped patches to address 47 security flaws in its Android operating system, including one it said has come under active exploitation in the wild. The vulnerability in question is CVE-2024-53104 (CVSS score: 7.8), which has been described as a case of privilege escalation…
-
Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score
Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges under certain conditions. The flaws are listed below – CVE-2025-21396 (CVSS score: 7.5) – Microsoft…
-
PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages
PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages The maintainers of the Python Package Index (PyPI) registry have announced a new feature that allows package developers to archive a project as part of efforts to improve supply chain security. “Maintainers can now archive a project to let users know that the project…
-
768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023
768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023 As many as 768 vulnerabilities with designated CVE identifiers were reported as exploited in the wild in 2024, up from 639 CVEs in 2023, registering a 20% increase year-over-year. Describing 2024 as “another banner year for threat actors targeting the exploitation of…
-
Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware
Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware A Russian-speaking cybercrime gang known as Crazy Evil has been linked to over 10 active social media scams that leverage a wide range of tailored lures to deceive victims and trick them into installing malware such as StealC, Atomic macOS Stealer (aka AMOS),…
-
U.S. and Dutch Authorities Dismantle 39 Domains Linked to BEC Fraud Network
U.S. and Dutch Authorities Dismantle 39 Domains Linked to BEC Fraud Network U.S. and Dutch law enforcement agencies have announced that they have dismantled 39 domains and their associated servers as part of efforts to disrupt a network of online marketplaces originating from Pakistan. The action, which took place on January 29, 2025, has been…
-
Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists
Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists Meta-owned WhatsApp on Friday said it disrupted a campaign that involved the use of spyware to target journalists and civil society members. The campaign, which targeted around 90 members, involved the use of spyware from an Israeli company known as Paragon Solutions. The attackers were…
-
BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key
BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key BeyondTrust has revealed it completed an investigation into a recent cybersecurity incident that targeted some of the company’s Remote Support SaaS instances by making use of a compromised API key. The company said the breach involved 17 Remote Support SaaS customers and that the…
-
CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors
CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Food and Drug Administration (FDA) have issued alerts about the presence of hidden functionality in Contec CMS8000 patient monitors and Epsimed MN-120 patient monitors. The vulnerability, tracked as CVE-2025-0626, carries a CVSS v4…
-
Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts
Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts Cybersecurity researchers have discovered a malvertising campaign that’s targeting Microsoft advertisers with bogus Google ads that aim to take them to phishing pages that are capable of harvesting their credentials. “These malicious ads, appearing on Google Search, are designed to steal the login information…
-
Top 5 AI-Powered Social Engineering Attacks
Top 5 AI-Powered Social Engineering Attacks Social engineering has long been an effective tactic because of how it focuses on human vulnerabilities. There’s no brute-force ‘spray and pray’ password guessing. No scouring systems for unpatched software. Instead, it simply relies on manipulating emotions such as trust, fear, and respect for authority, usually with the goal…
-
SOC Analysts – Reimagining Their Role Using AI
SOC Analysts – Reimagining Their Role Using AI The job of a SOC analyst has never been easy. Faced with an overwhelming flood of daily alerts, analysts (and sometimes IT teams who are doubling as SecOps) must try and triage thousands of security alerts—often false positives—just to identify a handful of real threats. This relentless,…
-
Lightning AI Studio Vulnerability Could’ve Allowed RCE via Hidden URL Parameter
Lightning AI Studio Vulnerability Could’ve Allowed RCE via Hidden URL Parameter Cybersecurity researchers have disclosed a critical security flaw in the Lightning AI Studio development platform that, if successfully exploited, could have allowed for remote code execution. The vulnerability, rated a CVSS score of 9.4, enables “attackers to potentially execute arbitrary commands with root privileges”…
-
Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown
Authorities Seize Domains of Popular Hacking Forums in Major Cybercrime Crackdown An international law enforcement operation has dismantled the domains associated with various online platforms linked to cybercrime such as Cracked, Nulled, Sellix, and StarkRDP. The effort, which took place between January 28 and 30, 2025, targeted the following domains – www.cracked.io www.nulled.to www.mysellix.io www.sellix.io…
-
Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations
Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations Over 57 distinct threat actors with ties to China, Iran, North Korea, and Russia have been observed using artificial intelligence (AI) technology powered by Google to further enable their malicious cyber and information operations. “Threat actors are experimenting with Gemini to enable their operations,…
-
Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information. The list of identified flaws, which impact versions 8.x…
-
New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits
New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits A team of security researchers from Georgia Institute of Technology and Ruhr University Bochum has demonstrated two new side-channel attacks targeting Apple silicon that could be exploited to leak sensitive information from web browsers like Safari and Google Chrome. The attacks have…
-
AI in Cybersecurity: What’s Effective and What’s Not – Insights from 200 Experts
AI in Cybersecurity: What’s Effective and What’s Not – Insights from 200 Experts Curious about the buzz around AI in cybersecurity? Wonder if it’s just a shiny new toy in the tech world or a serious game changer? Let’s unpack this together in a not-to-be-missed webinar that goes beyond the hype to explore the real…
-
Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks
Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks The North Korean threat actor known as the Lazarus Group has been observed leveraging a “web-based administrative platform” to oversee its command-and-control (C2) infrastructure, giving the adversary the ability to centrally supervise all aspects of their campaigns. “Each C2 server hosted a web-based administrative…
-
Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution
Critical Cacti Security Flaw (CVE-2025-22604) Enables Remote Code Execution A critical security flaw has been disclosed in the Cacti open-source network monitoring and fault management framework that could allow an authenticated attacker to achieve remote code execution on susceptible instances. The flaw, tracked as CVE-2025-22604, carries a CVSS score of 9.1 out of a maximum…
-
How Interlock Ransomware Infects Healthcare Organizations
How Interlock Ransomware Infects Healthcare Organizations Ransomware attacks have reached an unprecedented scale in the healthcare sector, exposing vulnerabilities that put millions at risk. Recently, UnitedHealth revealed that 190 million Americans had their personal and healthcare data stolen during the Change Healthcare ransomware attack, a figure that nearly doubles the previously disclosed total. This breach…
-
OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking
OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals. “By exploiting this flaw, attackers can gain unauthorized access to any user’s account within the system, effectively allowing them to impersonate…
-
PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks
PureCrypter Deploys Agent Tesla and New TorNet Backdoor in Ongoing Cyberattacks A financially motivated threat actor has been linked to an ongoing phishing email campaign that has been ongoing since at least July 2024 specifically targeting users in Poland and Germany. The attacks have led to the deployment of various payloads, such as Agent Tesla,…
-
Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability
Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability Cybersecurity researchers are warning that a critical zero-day vulnerability impacting Zyxel CPE Series devices is seeing active exploitation attempts in the wild. “Attackers can leverage this vulnerability to execute arbitrary commands on affected devices, leading to complete system compromise, data exfiltration, or network infiltration,”…
-
Broadcom Warns of High-Severity SQL Injection Flaw in VMware Avi Load Balancer
Broadcom Warns of High-Severity SQL Injection Flaw in VMware Avi Load Balancer Broadcom has alerted of a high-severity security flaw in VMware Avi Load Balancer that could be weaponized by malicious actors to gain entrenched database access. The vulnerability, tracked as CVE-2025-22217 (CVSS score: 8.6), has been described as an unauthenticated blind SQL injection. “A…
-
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents The advanced persistent threat (APT) group known as UAC-0063 has been observed leveraging legitimate documents obtained by infiltrating one victim to attack another target with the goal of delivering a known malware dubbed HATVIBE. “This research focuses on completing the picture of UAC-0063’s operations, particularly…
-
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January] Welcome to your weekly cybersecurity scoop! Ever thought about how the same AI meant to protect our hospitals could also compromise them? This week, we’re breaking down the sophisticated world of AI-driven threats, key updates in regulations, and some urgent vulnerabilities in healthcare…
-
GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs
GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs Multiple security vulnerabilities have been disclosed in GitHub Desktop as well as other Git-related projects that, if successfully exploited, could permit an attacker to gain unauthorized access to a user’s Git credentials. “Git implements a protocol called Git Credential Protocol to retrieve credentials from the…
-
Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More
Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More Apple has released software updates to address several security flaws across its portfolio, including a zero-day vulnerability that it said has been exploited in the wild. The vulnerability, tracked as CVE-2025-24085, has been described as a use-after-free bug in the Core Media component that could…
-
Top-Rated Chinese AI App DeepSeek Limits Registrations Amid Cyberattacks
Top-Rated Chinese AI App DeepSeek Limits Registrations Amid Cyberattacks DeepSeek, the Chinese AI startup that has captured much of the artificial intelligence (AI) buzz in recent days, said it’s restricting registrations on the service, citing malicious attacks. “Due to large-scale malicious attacks on DeepSeek’s services, we are temporarily limiting registrations to ensure continued service,” the…
-
Do We Really Need The OWASP NHI Top 10?
Do We Really Need The OWASP NHI Top 10? The Open Web Application Security Project has recently introduced a new Top 10 project – the Non-Human Identity (NHI) Top 10. For years, OWASP has provided security professionals and developers with essential guidance and actionable frameworks through its Top 10 projects, including the widely used API…
-
Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks
Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks A high-severity security flaw has been disclosed in Meta’s Llama large language model (LLM) framework that, if successfully exploited, could allow an attacker to execute arbitrary code on the llama-stack inference server. The vulnerability, tracked as CVE-2024-50050, has been assigned a CVSS score…
-
Android’s New Identity Check Feature Locks Device Settings Outside Trusted Locations
Android’s New Identity Check Feature Locks Device Settings Outside Trusted Locations Google has launched a new feature called Identity Check for supported Android devices that locks sensitive settings behind biometric authentication when outside of trusted locations. “When you turn on Identity Check, your device will require explicit biometric authentication to access certain sensitive resources when…
-
DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations
DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations The U.S. Department of Justice (DoJ) on Thursday indicted two North Korean nationals, a Mexican national, and two of its own citizens for their alleged involvement in the ongoing fraudulent information technology (IT) worker scheme that seeks to generate revenue for the Democratic…
-
2025 State of SaaS Backup and Recovery Report
2025 State of SaaS Backup and Recovery Report The modern workplace has undergone a seismic transformation over recent years, with hybrid work becoming the norm and businesses rapidly adopting cloud-based Software-as-a-Service (SaaS) applications to facilitate it. SaaS applications like Microsoft 365 and Google Workspace have now become the backbone of business operations, enabling seamless collaboration…
-
RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations
RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even gain a foothold into the cellular core network. The 119 vulnerabilities, assigned…
-
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The medium-severity vulnerability is CVE-2020-11023 (CVSS score: 6.1/6.9), a nearly five-year-old…
-
Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers
Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers Enterprise-grade Juniper Networks routers have become the target of a custom backdoor as part of a campaign dubbed J-magic. According to the Black Lotus Labs team at Lumen Technologies, the activity is so named for the fact that the backdoor continuously monitors for a “magic packet”…
-
New Research: The State of Web Exposure 2025
New Research: The State of Web Exposure 2025 Are your websites leaking sensitive data? New research reveals that 45% of third-party apps access user info without proper authorization, and 53% of risk exposures in Retail are due to the excessive use of tracking tools. Learn how to uncover and mitigate these hidden threats and risks—download…
-
Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks
Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks Cybersecurity researchers are calling attention to a new malware campaign that leverages fake CAPTCHA verification checks to deliver the infamous Lumma information stealer. “The campaign is global, with Netskope Threat Labs tracking victims targeted in Argentina, Colombia, the United States, the Philippines, and other countries…
-
Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices’ firmware as well as misconfigured security features. “These weren’t obscure, corner-case vulnerabilities,” security vendor Eclypsium said in a report shared with…
-
TRIPLESTRENGTH Hits Cloud for Cryptojacking, On-Premises Systems for Ransomware
TRIPLESTRENGTH Hits Cloud for Cryptojacking, On-Premises Systems for Ransomware Google on Wednesday shed light on a financially motivated threat actor named TRIPLESTRENGTH for its opportunistic targeting of cloud environments for cryptojacking and on-premise ransomware attacks. “This actor engaged in a variety of threat activity, including cryptocurrency mining operations on hijacked cloud resources and ransomware activity,”…
-
Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed denial-of-service (DDoS) attacks. According to QiAnXin XLab, the attacks have leveraged the security flaw since June 2024.…
-
Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Review
Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Review The new Trump administration has terminated all memberships of advisory committees that report to the Department of Homeland Security (DHS). “In alignment with the Department of Homeland Security’s (DHS) commitment to eliminating the misuse of resources and ensuring that DHS activities prioritize our national security, I…
-
President Trump Pardons Silk Road Creator Ross Ulbricht After 11 Years in Prison
President Trump Pardons Silk Road Creator Ross Ulbricht After 11 Years in Prison U.S. President Donald Trump on Tuesday granted a “full and unconditional pardon” to Ross Ulbricht, the creator of the infamous Silk Road drug marketplace, after spending more than 11 years behind bars. “I just called the mother of Ross William Ulbricht to…
-
Discover Hidden Browsing Threats: Free Risk Assessment for GenAI, Identity, Web, and SaaS Risks
Discover Hidden Browsing Threats: Free Risk Assessment for GenAI, Identity, Web, and SaaS Risks As GenAI tools and SaaS platforms become a staple component in the employee toolkit, the risks associated with data exposure, identity vulnerabilities, and unmonitored browsing behavior have skyrocketed. Forward-thinking security teams are looking for security controls and strategies to address these…
-
Ex-CIA Analyst Pleads Guilty to Sharing Top-Secret Data with Unauthorized Parties
Ex-CIA Analyst Pleads Guilty to Sharing Top-Secret Data with Unauthorized Parties A former analyst working for the U.S. Central Intelligence Agency (CIA) pleaded guilty to transmitting top secret National Defense Information (NDI) to individuals who did not have the necessary authorization to receive it and attempted to cover up the activity. Asif William Rahman, 34,…
-
13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks
13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks A global network of about 13,000 hijacked Mikrotik routers has been employed as a botnet to propagate malware via spam campaigns, the latest addition to a list of botnets powered by MikroTik devices. The activity “take[s] advantage of misconfigured DNS records to pass email protection…
-
Mirai Variant Murdoc Botnet Exploits AVTECH IP Cameras and Huawei Routers
Mirai Variant Murdoc Botnet Exploits AVTECH IP Cameras and Huawei Routers Cybersecurity researchers have warned of a new large-scale campaign that exploits security flaws in AVTECH IP cameras and Huawei HG532 routers to rope the devices into a Mirai botnet variant dubbed Murdoc Botnet. The ongoing activity “demonstrates enhanced capabilities, exploiting vulnerabilities to compromise devices…
-
Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Device
Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Device Web infrastructure and security company Cloudflare on Tuesday said it detected and blocked a 5.6 Terabit per second (Tbps) distributed denial-of-service (DDoS) attack, the largest ever attack to be reported to date. The UDP protocol-based attack took place on October 29, 2024, targeting…
-
HackGATE: Setting New Standards for Visibility and Control in Penetration Testing Projects
HackGATE: Setting New Standards for Visibility and Control in Penetration Testing Projects Imagine receiving a penetration test report that leaves you with more questions than answers. Questions like, “Were all functionalities of the web app tested?” or ” Were there any security issues that could have been identified during testing?” often go unresolved, raising concerns…
-
PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers
PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers Cybersecurity researchers are calling attention to a series of cyber attacks that have targeted Chinese-speaking regions like Hong Kong, Taiwan, and Mainland China with a known malware called ValleyRAT. The attacks leverage a multi-stage loader dubbed PNGPlug to deliver the ValleyRAT payload, Intezer said in a…
-
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [20 January]
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [20 January] As the digital world becomes more complicated, the lines between national security and cybersecurity are starting to fade. Recent cyber sanctions and intelligence moves show a reality where malware and fake news are used as tools in global politics. Every cyberattack now seems…
-
DoNot Team Linked to New Tanzeem Android Malware Targeting Intelligence Collection
DoNot Team Linked to New Tanzeem Android Malware Targeting Intelligence Collection The Threat actor known as DoNot Team has been linked to a new Android malware as part of highly targeted cyber attacks. The artifacts in question, named Tanzeem (meaning “organization” in Urdu) and Tanzeem Update, were spotted in October and December 2024 by cybersecurity…
-
Unsecured Tunneling Protocols Expose 4.2 Million Hosts, Including VPNs and Routers
Unsecured Tunneling Protocols Expose 4.2 Million Hosts, Including VPNs and Routers New research has uncovered security vulnerabilities in multiple tunneling protocols that could allow attackers to perform a wide range of attacks. “Internet hosts that accept tunneling packets without verifying the sender’s identity can be hijacked to perform anonymous attacks and provide access to their…
-
CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits The Computer Emergency Response Team of Ukraine (CERT-UA) is warning of ongoing attempts by unknown threat actors to impersonate the cybersecurity agency by sending AnyDesk connection requests. The AnyDesk requests claim to be for conducting an audit to assess the “level of…
-
Hackers Deploy Malicious npm Packages to Steal Solana Wallet Keys via Gmail SMTP
Hackers Deploy Malicious npm Packages to Steal Solana Wallet Keys via Gmail SMTP Cybersecurity researchers have identified three sets of malicious packages across the npm and Python Package Index (PyPI) repository that come with capabilities to steal data and even delete sensitive data from infected systems. The list of identified packages is below – @async-mutex/mutex,…