Category: Threats
-
Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands
Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands Security researchers have discovered two significant vulnerabilities affecting Mitel’s suite of SIP phones that could allow attackers to execute arbitrary commands and upload malicious files. The more severe vulnerability, identified as CVE-2025-47188, received a critical CVSS score of 9.8 and affects the company’s 6800…
-
Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors
Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide. The vulnerability allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable /developmentserver/metadatauploader endpoint.…
-
Threat Actors Attacking Job Seekers With Three New Unique Adversaries
Threat Actors Attacking Job Seekers With Three New Unique Adversaries A significant surge in sophisticated recruitment scams has emerged, with cybercriminals exploiting economic vulnerabilities and the competitive job market to target desperate job seekers. These scams employ increasingly refined social engineering tactics that blend legitimate recruitment practices with fraudulent schemes, making them particularly effective at…
-
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Cybersecurity experts have uncovered a sophisticated attack campaign targeting IT administrators through search engine optimization (SEO) poisoning tactics. Threat actors are leveraging advanced SEO techniques to push malicious versions of commonly used administrative tools to the top of search engine…
-
Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide
Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS) platform called “Darcula” responsible for stealing approximately 884,000 credit card details through a massive campaign that generated over 13 million clicks…
-
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware A sophisticated new attack method that disables endpoint security protection has been identified by security researchers, enabling threat actors to deploy ransomware undetected. The technique, dubbed “Bring Your Own Installer,” was recently discovered by Aon’s Stroz Friedberg Incident Response team during an investigation of a Babuk…
-
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands A sophisticated phishing campaign dubbed “Power Parasites” has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week. The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy,…
-
DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models
DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models Despite significant disruptions by international law enforcement operations targeting major ransomware schemes, cybercriminal groups continue demonstrating remarkable adaptability in 2025. Two noteworthy ransomware operations, DragonForce and Anubis, have introduced innovative affiliate models designed to expand their reach and increase profitability in the ever-evolving cybercrime landscape. DragonForce…
-
New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy
New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy Cybercriminals have dramatically evolved their phishing tactics, leveraging generative AI to create highly personalized and convincing attacks, according to the newly released ThreatLabz 2025 Phishing Report. The days of mass phishing campaigns have given way to hyper-targeted scams designed to exploit…
-
North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers
North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers A sophisticated North Korean advanced persistent threat (APT) group known as “Contagious Interview” has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware. The group, a subunit of the infamous North Korean state-sponsored Lazarus Group, has created three…
-
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations North Korea’s cybercrime operations have significantly expanded beyond the limited 1,024 IP addresses assigned to their national network through an elaborate scheme involving Russian infrastructure. According to recent findings, five Russian IP ranges, primarily located in the border towns of Khasan and Khabarovsk,…
-
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites Phishing campaigns have evolved significantly in 2025, with threat actors increasingly leveraging unconventional file formats to bypass security solutions. A particularly concerning trend involves the weaponization of Scalable Vector Graphics (SVG) files, which are being embedded with malicious JavaScript code designed to redirect…
-
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN A server briefly linked to the notorious KeyPlug malware has inadvertently exposed a comprehensive arsenal of exploitation tools specifically designed to target Fortinet firewall and VPN appliances. The infrastructure, which security researchers have attributed to the RedGolf threat group (overlapping with APT41),…
-
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC In today’s rapidly evolving cyber threat landscape, Security Operations Centers (SOCs) face an unprecedented challenge: efficiently managing and prioritizing the overwhelming volume of security alerts they receive daily. SOC analysts often can’t read and respond to a significant portion of the alerts they see every…
-
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data Shells provide crucial command-line interfaces to operating systems. While legitimate for system administration tasks, when weaponized by threat actors, shells transform into dangerous avenues for unauthorized access, system control, and data theft across organizational networks. The misuse of these tools has become increasingly sophisticated,…
-
RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals
RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025. This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging…
-
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies Cybersecurity experts have detected a sophisticated campaign targeting energy sector companies, as the threat actor known as Sapphire Werewolf deploys an enhanced version of the Amethyst stealer malware. The campaign represents a significant evolution in the group’s capabilities, featuring advanced evasion techniques and…
-
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows Google has announced the launch of Agent2Agent Protocol (A2A), a groundbreaking open protocol designed to enable AI agents to communicate with each other, securely exchange information, and coordinate actions across enterprise platforms. Revealed on April 9, 2025, the protocol marks a significant advancement…
-
Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware
Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware Security researchers have identified a critical vulnerability in Ivanti Connect Secure (ICS) VPN appliances that is being actively exploited by suspected Chinese threat actors. The vulnerability, tracked as CVE-2025-22457, is a buffer overflow flaw affecting ICS version 22.7R2.5 and earlier that can lead to remote…
-
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring Frida 16.7.0, the latest version of the popular dynamic instrumentation toolkit, has powerful new APIs specifically designed for advanced threat monitoring and security analysis. This major update, announced on March 13, 2025, introduces groundbreaking capabilities that significantly enhance the toolkit’s utility for security…
-
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot Microsoft has discovered multiple critical vulnerabilities affecting widely used bootloaders including GRUB2, U-Boot, and Barebox. These security flaws potentially expose systems to sophisticated boot-level attacks that could compromise devices before operating systems even initialize, allowing attackers to gain persistent and nearly undetectable control over…
-
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows A sophisticated social engineering technique has recently emerged in the cybersecurity landscape, rapidly gaining traction among threat actors seeking to distribute trojans, ransomware, and particularly Quakbot malware. This technique, known as ClickFix Captcha, exploits users’ trust in familiar web elements…
-
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows A sophisticated cyber espionage campaign targeting Ukrainian entities has been uncovered, revealing the latest tactics of the Russia-linked Gamaredon threat actor group. The attackers are leveraging weaponized LNK files disguised as Office documents to deliver the Remcos backdoor malware, utilizing themes related to…
-
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models In an era where deep learning models increasingly power critical systems from self-driving cars to medical devices, security researchers have unveiled DeBackdoor, an innovative framework designed to detect stealthy backdoor attacks before deployment. Backdoor attacks, among the most effective and covert threats to deep learning,…
-
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence Artificial intelligence has dramatically transformed the cybersecurity landscape, with red team activities increasingly leveraging sophisticated AI-driven techniques to simulate advanced persistent threats. These AI-enhanced red teams can now automate the process of penetrating targets and collecting sensitive data at unprecedented speeds. The evolution…
-
New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control
New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control A newly identified malware strain dubbed “IOCONTROL” has emerged as a critical threat to operational technology (OT) and Internet of Things (IoT) systems, particularly targeting fuel-management infrastructure in the United States and Israel. First observed in December 2024, this Linux-based malware has been…
-
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT A sophisticated phishing campaign is leveraging virtual hard disk (.vhd) files to distribute the dangerous VenomRAT malware. The attack begins with purchase order-themed emails containing archive attachments that, when extracted, reveal hard disk image files designed to evade traditional security measures. Batch file inside .vhd file…
-
Beware of Free File Word To PDF Converter That Delivers Malware
Beware of Free File Word To PDF Converter That Delivers Malware The FBI has issued an urgent warning about the rising threat of malicious file conversion tools that are being used to spread malware across the United States. Cybercriminals are targeting users searching for free utilities to convert documents from one format to another, with…
-
New Context Compliance Attack Jailbreaks Most of The Major AI Models
New Context Compliance Attack Jailbreaks Most of The Major AI Models A new, surprisingly simple method called Context Compliance Attack (CCA) has proven effective at bypassing safety guardrails in most leading AI systems. Unlike complex prompt engineering techniques that attempt to confuse AI systems with intricate word combinations, CCA exploits a fundamental architectural weakness present…
-
Black Basta Ransomware Attack Edge Network Devices With Automated Brute Force Attacks
Black Basta Ransomware Attack Edge Network Devices With Automated Brute Force Attacks A Russian-speaking actor using the Telegram handle @ExploitWhispers leaked internal chat logs of Black Basta Ransomware-as-a-Service (RaaS) members on February 11, 2025. These communications, spanning from September 2023 to September 2024, have provided security researchers with unprecedented insight into the group’s operational tactics…
-
Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations
Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations A sophisticated backdoor malware called “Squidoor” being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia. The malware, designed for exceptional stealth, offers attackers multiple methods to maintain persistent access to compromised networks while evading detection from advanced security systems. Initial…
-
North Korean IT Workers Using GitHub To Attack Organization Globally
North Korean IT Workers Using GitHub To Attack Organization Globally Cybersecurity research firm NISOS has uncovered a network of suspected North Korean IT workers who are leveraging GitHub to create elaborate fake personas aimed at securing employment with companies in Japan and the United States. These individuals pose as Vietnamese, Japanese, and Singaporean nationals while…
-
Google Silently Tracks Android Device Even No Apps Opened by User
Google Silently Tracks Android Device Even No Apps Opened by User Google collects and stores significant amounts of user data on Android devices, even when users haven’t opened any Google apps. The study by Professor D.J. Leith from Trinity College Dublin, documents for the first time how pre-installed Google apps silently track users without seeking…
-
Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses
Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses A sophisticated cyberattack campaign targeting Chinese-speaking users, malicious actors have weaponized fake versions of popular applications such as Signal, Line, and Gmail. These fake and weaponized apps are distributed via deceptive download pages that deliver malware capable of altering system defenses, evading detection,…
-
Beware of Fake Outlook Troubleshooting Calls that Ends Up In Ransomware Deployment
Beware of Fake Outlook Troubleshooting Calls that Ends Up In Ransomware Deployment A sophisticated cyber threat has emerged in recent weeks, targeting unsuspecting users with fake Outlook troubleshooting calls. These calls, designed to appear legitimate, ultimately lead to the deployment of ransomware on the victim’s system. The scam involves a malicious binary named CITFIX#37.exe, which…
-
Hackers Using Pyramid Pentesting Tool For Stealthy C2 Communications
Hackers Using Pyramid Pentesting Tool For Stealthy C2 Communications Hackers have been leveraging the open-source Pyramid pentesting tool to establish stealthy command-and-control (C2) communications. Pyramid, first released on GitHub in 2023, is a Python-based post-exploitation framework designed to evade endpoint detection and response (EDR) tools. Its lightweight HTTP/S server capabilities make it an attractive choice…
-
SAML Bypass Authentication on GitHub Enterprise Servers To Login as Other User Account
SAML Bypass Authentication on GitHub Enterprise Servers To Login as Other User Account A significant vulnerability has been identified in GitHub Enterprise Servers, allowing attackers to bypass SAML authentication and log in as other user accounts. This exploit leverages quirks in the libxml2 library, specifically related to XML entities, to deceive the verification process. The…
-
Hackers Exploiting Google Tag Manager To Steal Credit Card From eCommerce Sites
Hackers Exploiting Google Tag Manager To Steal Credit Card From eCommerce Sites Hackers have been exploiting Google Tag Manager (GTM) to steal sensitive credit card information from eCommerce sites, particularly those built on the Magento platform. This sophisticated attack shows the evolving tactics of cybercriminals in leveraging legitimate tools for malicious purposes. Google Tag Manager…
-
Devil-Traff – New Malicious Bulk SMS Portal That Fuels Phishing Attacks
Devil-Traff – New Malicious Bulk SMS Portal That Fuels Phishing Attacks A new threat to cybersecurity has emerged in the form of Devil-Traff, a bulk SMS platform designed to facilitate large-scale phishing campaigns. Leveraging advanced features such as sender ID spoofing, API integration, and support for malicious content, this platform has become a favorite tool…
-
Google Has Blocked 2.28 Million Malicious Apps Entering Into Play Store
Google Has Blocked 2.28 Million Malicious Apps Entering Into Play Store Google announced today it blocked a record 2.28 million policy-violating apps from entering the Play Store in 2023, leveraging advanced machine learning, stricter developer vetting, and cross-industry collaborations to combat evolving cyberthreats. The milestone underscores efforts to uphold its SAFE principles (Safeguard Users, Advocate…
-
Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges
Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges A critical Insecure Direct Object Reference (IDOR) vulnerability has been identified in One Identity Manager, a widely used identity and access management solution. This vulnerability, officially tracked as CVE-2024-56404, allows unauthorized privilege escalation under specific configurations. The issue affects only On-Premise installations and does not impact…
-
New Phishing Campaign Mimic Amazon Prime Membership To Steal Credit Card Data
New Phishing Campaign Mimic Amazon Prime Membership To Steal Credit Card Data A sophisticated phishing campaign targeting Amazon Prime members has been uncovered, aiming to steal credit card information and other sensitive data. Cybersecurity experts have identified a complex attack chain that leverages PDF attachments, redirects, and cleverly crafted phishing sites to deceive unsuspecting victims.…