Category: Threats
-
Hackers Exploit Legitimate Inno Setup Installer to Use as a Malware Delivery Vehicle
Hackers Exploit Legitimate Inno Setup Installer to Use as a Malware Delivery Vehicle Cybercriminals have increasingly turned to legitimate software installation frameworks as vehicles for malware distribution, with Inno Setup emerging as a preferred tool for threat actors seeking to bypass security measures. This legitimate Windows installer framework, originally designed to simplify software deployment, has…
-
Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence
Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence Cybersecurity researchers have discovered a sophisticated attack technique that exploits Microsoft Azure Arc deployments to gain persistent access to enterprise environments. The research, conducted during recent red team operations, reveals how adversaries can leverage misconfigured Azure Arc installations…
-
Hackers Exploiting Java Debug Wire Protocol Servers in Wild to Deploy Cryptomining Payload
Hackers Exploiting Java Debug Wire Protocol Servers in Wild to Deploy Cryptomining Payload A new wave of cyberattacks is targeting organizations that inadvertently expose Java Debug Wire Protocol (JDWP) servers to the internet, with attackers leveraging this overlooked entry point to deploy sophisticated cryptomining malware. JDWP, a standard feature in the Java platform, is designed…
-
Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users
Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users A sophisticated mobile ad fraud operation dubbed “IconAds” has infiltrated Android devices worldwide through 352 malicious applications distributed via Google Play Store, generating up to 1.2 billion fraudulent bid requests daily at its peak. The scheme represents a significant evolution in mobile advertising…
-
Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware
Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware A sophisticated social engineering campaign has emerged targeting unsuspecting users through fraudulent Cloudflare verification screens, representing a new evolution in malware distribution tactics. This attack method leverages the trusted appearance of legitimate web security services to deceive victims into executing malicious code on…
-
Chinese Student Charged for Running a Mass Smishing Campaign to Harvest Victims Personal Details
Chinese Student Charged for Running a Mass Smishing Campaign to Harvest Victims Personal Details A sophisticated smishing operation targeting tens of thousands of potential victims across Greater London has resulted in the sentencing of Ruichen Xiong, a Chinese student, to over a year in prison at Inner London Crown Court. The case represents a significant…
-
TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections
TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections The cybersecurity landscape faces a renewed threat as TA829, a sophisticated threat actor group, has emerged with enhanced tactics, techniques, and procedures (TTPs) alongside an upgraded version of the notorious RomCom backdoor. This hybrid cybercriminal-espionage group has demonstrated remarkable adaptability, conducting both financially…
-
Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines
Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines The notorious North Korean threat group Kimsuky has adopted a sophisticated social engineering tactic known as “ClickFix” to deceive users into executing malicious scripts on their own systems. Originally introduced by Proofpoint researchers in April 2024, this deceptive technique tricks victims into believing…
-
North Korean Remote IT Workers Added New Tactics and Techniques to Infiltrate Organizations
North Korean Remote IT Workers Added New Tactics and Techniques to Infiltrate Organizations North Korean state-sponsored remote IT workers have significantly evolved their infiltration tactics, incorporating artificial intelligence tools and sophisticated deception techniques to penetrate organizations worldwide. Since 2024, these highly skilled operatives have enhanced their fraudulent employment schemes by leveraging AI-powered image manipulation, voice-changing…
-
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI, Department of Defense Cyber Crime Center, and National Security Agency, has issued an urgent warning regarding potential cyber attacks by Iranian-affiliated actors targeting U.S. critical infrastructure. Despite ongoing ceasefire negotiations and diplomatic efforts,…
-
Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger
Androxgh0st Botnet Operators Exploiting US University For Hosting C2 Logger The Androxgh0st botnet has significantly expanded its operations since 2023, with cybercriminals now compromising prestigious academic institutions to host their command and control infrastructure. This sophisticated malware campaign has demonstrated remarkable persistence and evolution, targeting a diverse range of vulnerabilities across web applications, frameworks, and…
-
TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts
TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts A sophisticated cyberattack campaign has weaponized a legitimate penetration testing framework to compromise thousands of Microsoft cloud accounts across hundreds of organizations worldwide. The malicious operation, designated UNK_SneakyStrike, leverages TeamFiltration, a popular cybersecurity tool originally designed for Office 365 security assessments, to conduct…
-
Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers
Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers A sophisticated malware campaign has emerged targeting WordPress and WooCommerce websites with highly obfuscated credit card skimmers and credential theft capabilities, representing a significant escalation in e-commerce cyberthreats. The malware family demonstrates advanced technical sophistication through its modular architecture, featuring multiple variants designed for…
-
North Korean Hackers Trick Users With Weaponized Zoom Apps to Execute System-Takeover Commands
North Korean Hackers Trick Users With Weaponized Zoom Apps to Execute System-Takeover Commands A sophisticated cybercriminal campaign has emerged targeting professionals through meticulously crafted fake Zoom applications designed to execute system takeover commands. The attack leverages advanced social engineering techniques combined with convincing domain spoofing to deceive users into compromising their systems, representing a significant…
-
LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly
LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly A sophisticated China-linked cyber espionage campaign has emerged, targeting over 1,000 Small Office/Home Office (SOHO) devices worldwide through an advanced Operational Relay Box (ORB) network dubbed “LapDogs.” This covert infrastructure operation, active since September 2023, represents a significant evolution in nation-state cyber…
-
BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware
BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware A sophisticated social engineering campaign leveraging the trusted Zoom platform has emerged as the latest weapon in the arsenal of North Korean state-sponsored hackers. The BlueNoroff group, a financially motivated subgroup of the notorious Lazarus Group, has been orchestrating targeted attacks against cryptocurrency and…
-
NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls
NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls The UK’s National Cyber Security Centre (NCSC) has issued a critical warning about a sophisticated malware campaign dubbed “UMBRELLA STAND” that specifically targets internet-facing Fortinet FortiGate 100D series firewalls. This newly identified threat represents a significant escalation in attacks against network infrastructure devices, with the…
-
Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency
Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency Cybersecurity researchers have uncovered a significant resurgence of the Prometei botnet, a sophisticated malware operation targeting Linux servers for cryptocurrency mining and credential theft. This latest campaign, observed since March 2025, demonstrates the evolving nature of cryptomining malware and its persistent threat to enterprise infrastructure worldwide. The…
-
Beware of Weaponized MSI Installer Mimic as WhatsApp Delivers Modified XWorm RAT
Beware of Weaponized MSI Installer Mimic as WhatsApp Delivers Modified XWorm RAT Cybersecurity professionals across East and Southeast Asia are facing a sophisticated new threat as China-linked attackers deploy a weaponized MSI installer disguised as a legitimate WhatsApp setup package. This malicious campaign represents a significant escalation in social engineering tactics, leveraging the popularity and…
-
Hackers Exploit Atlassian’s Model Context Protocol by Submitting a Malicious Support Ticket
Hackers Exploit Atlassian’s Model Context Protocol by Submitting a Malicious Support Ticket A sophisticated attack vector targeting Atlassian’s Model Context Protocol (MCP) that allows external threat actors to gain privileged access to internal systems through malicious support tickets. The attack, dubbed “Living off AI,” exploits the trust boundary between external users submitting support requests and…
-
PowerShell Loaders With In-Memory Execution Techniques To Evade Disk-Based Detection
PowerShell Loaders With In-Memory Execution Techniques To Evade Disk-Based Detection Cybersecurity researchers have uncovered a sophisticated PowerShell-based attack campaign that leverages advanced in-memory execution techniques to bypass traditional disk-based security controls. The malicious infrastructure spans across Chinese, Russian, and global hosting providers, demonstrating the international scope of modern cyber threats. At the center of this…
-
AntiDot – 3-in-1 Android Malware Let Attackers Full Control of Compromised Devices
AntiDot – 3-in-1 Android Malware Let Attackers Full Control of Compromised Devices A sophisticated new Android botnet malware called AntiDot has emerged as a significant threat to mobile device security, offering cybercriminals unprecedented control over infected devices. This malicious software operates as part of a Malware-as-a-Service (MaaS) model, marketed by threat actor LARVA-398 on underground…
-
Hackers Leverage Cloudflare Tunnels to Infect Systems Using Stealthy Python-Based Malware
Hackers Leverage Cloudflare Tunnels to Infect Systems Using Stealthy Python-Based Malware A sophisticated malware campaign has emerged that exploits Cloudflare’s tunneling infrastructure to deliver multi-stage Python-based payloads, demonstrating an alarming evolution in cybercriminal tactics. The campaign, tracked as SERPENTINE#CLOUD, represents a significant escalation in the abuse of legitimate cloud services for malicious purposes, combining social…
-
Hackers Using ClickFix Technique to Deploy Remote Access Trojans and Data-Stealing Malware
Hackers Using ClickFix Technique to Deploy Remote Access Trojans and Data-Stealing Malware Cybersecurity researchers have documented a significant surge in attacks utilizing the ClickFix social engineering technique, which has emerged as one of the most effective methods for initial access in modern cyber campaigns. This deceptive tactic tricks users into executing malicious PowerShell commands by…
-
Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages
Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages The cryptocurrency and blockchain development ecosystem is facing an unprecedented surge in sophisticated malware campaigns targeting the open source supply chain. Over the past year, threat actors have significantly escalated their attacks against Web3 developers by publishing malicious packages to trusted registries…
-
China and Taiwan Accuse Each Other for Cyberattacks Against Critical Infrastructure
China and Taiwan Accuse Each Other for Cyberattacks Against Critical Infrastructure Cross-strait tensions have escalated into a new domain as China and Taiwan engage in unprecedented mutual accusations of cyberwarfare targeting critical infrastructure systems. The diplomatic dispute has intensified following Taiwan President Lai Ching-te’s first year in office, during which both governments have publicly traded…
-
Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection
Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection Despite sustained international pressure, sanctions, and public exposures over the past two years, the sophisticated Predator mobile spyware has demonstrated remarkable resilience, continuing to evolve and adapt its infrastructure to evade detection while maintaining operations across multiple continents. The mercenary spyware, originally developed…
-
Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider
Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider Cybersecurity researchers have uncovered a sophisticated ransomware campaign targeting utility billing software providers through unpatched vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) systems. The attack represents a concerning evolution in ransomware tactics, where threat actors are leveraging trusted remote access tools to establish…
-
Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware
Fog Ransomware Actors Exploits Pentesting Tools to Exfiltrate Data and Deploy Ransomware The Fog ransomware group has evolved beyond conventional attack methods, deploying an unprecedented arsenal of legitimate pentesting tools in a sophisticated May 2025 campaign targeting a financial institution in Asia. This latest operation marks a significant departure from typical ransomware tactics, incorporating employee…
-
Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation
Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation Cybersecurity researchers have uncovered a sophisticated malware campaign that leveraged an advanced JavaScript obfuscation technique to compromise hundreds of legitimate websites and redirect unsuspecting visitors to malicious content. The campaign, which infected over 269,000 webpages between March and April 2025, employed a variant…
-
New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers
New Rust Based InfoStealer Extracts Sensitive Data from Chromium-based Browsers A sophisticated new information-stealing malware written in the Rust programming language has emerged, demonstrating advanced capabilities to extract sensitive data from both Chromium-based and Gecko-based web browsers. The malware, known as Myth Stealer, represents a significant evolution in cybercriminal tactics, combining modern programming techniques with…
-
Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts
Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts Cybersecurity researchers have identified a sophisticated new social engineering campaign that exploits fundamental human trust in everyday computer interactions. The ClickFix technique, which has been actively deployed since March 2024, represents a dangerous evolution in cybercriminal tactics that bypasses traditional security measures by…
-
Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User
Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User A sophisticated malware distribution campaign has weaponized over 140 GitHub repositories to target inexperienced cybercriminals and gaming cheat users, representing one of the largest documented cases of supply chain attacks on the platform. The repositories, masquerading as legitimate malware tools and game cheats,…
-
New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently
New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently A sophisticated new social engineering attack campaign has emerged that exploits users’ familiarity with routine security checks to deliver malware through deceptive Cloudflare verification pages. The ClickFix attack technique represents a concerning evolution in phishing methodology, abandoning traditional file downloads in favor of…
-
DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year
DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year DragonForce, a sophisticated ransomware operation that emerged in fall 2023, has established itself as a formidable threat in the cybercriminal landscape by claiming over 120 victims across the past year. Unlike traditional ransomware-as-a-service models, this threat actor has evolved into what security experts…
-
Hackers Exploit AI Tools Misconfiguration To Run Malicious AI-generated Payloads
Hackers Exploit AI Tools Misconfiguration To Run Malicious AI-generated Payloads Cybercriminals are increasingly leveraging misconfigured artificial intelligence tools to execute sophisticated attacks that generate and deploy malicious payloads automatically, marking a concerning evolution in threat actor capabilities. This emerging attack vector combines traditional configuration vulnerabilities with the power of AI-driven content generation, enabling attackers to…
-
Threat Actors Actively Exploiting Critical vBulletin Vulnerability in the Wild
Threat Actors Actively Exploiting Critical vBulletin Vulnerability in the Wild A critical, unauthenticated remote code execution vulnerability in vBulletin forum software is now being actively exploited. The vulnerability, which impacts vBulletin versions 5.0.0 through 6.0.3, has been assigned CVE-2025-48827 and CVE-2025-48828 and is now being actively targeted by threat actors, marking it as a Known…
-
Threat Actors Leverage Google Apps Script To Host Phishing Websites
Threat Actors Leverage Google Apps Script To Host Phishing Websites Cybercriminals have escalated their tactics by exploiting Google Apps Script, a trusted development platform, to host sophisticated phishing campaigns that bypass traditional security measures. This emerging threat represents a significant shift in how attackers leverage legitimate infrastructure to enhance the credibility of their malicious operations.…
-
LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data
LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data LexisNexis Risk Solutions has disclosed a significant data breach affecting approximately 364,000 individuals after discovering that an unauthorized third party gained access to sensitive personal information through a compromised third-party software development platform. The cybersecurity incident, which LexisNexis learned about on April 1, 2025, actually…
-
Tycoon2FA Infra Used by Dadsec Hacker Group to Steal Office365 Credentials
Tycoon2FA Infra Used by Dadsec Hacker Group to Steal Office365 Credentials A sophisticated phishing campaign leveraging shared infrastructure between two prominent cybercriminal operations has emerged as a significant threat to Office 365 users worldwide. The Tycoon2FA Phishing-as-a-Service platform, which has been active since August 2023, has established operational connections with the notorious Storm-1575 group, also…
-
Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware
Beware of Weaponized AI Tool Installers That Infect Your Devices With Ransomware Cybercriminals are increasingly exploiting the growing popularity of artificial intelligence tools by distributing sophisticated malware disguised as legitimate AI solution installers. This emerging threat landscape has seen malicious actors create convincing replicas of popular AI platforms, using these deceptive packages to deploy devastating…
-
New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER
New Rust-based InfoStealer via Fake CAPTCHA Delivers EDDIESTEALER Cybersecurity researchers have uncovered a sophisticated malware campaign leveraging deceptive CAPTCHA verification pages to distribute a newly discovered Rust-based infostealer dubbed EDDIESTEALER. This campaign represents a significant evolution in social engineering tactics, where threat actors exploit users’ familiarity with routine security verification processes to trick them into…
-
New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware
New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware A sophisticated spear-phishing campaign has emerged targeting chief financial officers and senior financial executives across banking, energy, insurance, and investment sectors worldwide, marking a concerning escalation in precision-targeted cyber attacks against corporate leadership. The campaign, which surfaced on May 15, 2025, employs advanced social engineering…
-
W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials
W3LL Phishing Kit Actively Attacking Users to Steal Outlook Login Credentials A sophisticated phishing campaign utilizing the W3LL Phishing Kit has been actively targeting users’ Microsoft Outlook credentials through elaborate impersonation techniques. First identified by Group-IB in 2022, this phishing-as-a-service (PhaaS) tool has evolved into a comprehensive ecosystem complete with its own marketplace called W3LL…
-
APT Group 123 Actively Attacking Windows Systems to Deliver Malicious Payloads
APT Group 123 Actively Attacking Windows Systems to Deliver Malicious Payloads North Korean state-sponsored threat actor APT Group 123 has intensified its cyber espionage campaign, specifically targeting Windows systems across multiple sectors globally. The group, active since at least 2012 and also tracked under aliases such as APT37, Reaper, and ScarCruft, has historically focused on…
-
New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials
New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials FrigidStealer, a sophisticated information-stealing malware that emerged in January 2025, is actively targeting macOS endpoints to steal sensitive user data through deceptive tactics. Unlike traditional malware, FrigidStealer exploits user trust in routine software updates, making it particularly insidious. The malware has raised significant concerns among…
-
Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats
Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats A disturbing pattern of security failures in the firmware supply chain continues to expose millions of devices to pre-OS threats, potentially undermining the foundation of computer security. Between 2022 and 2025, a series of critical security incidents involving leaked cryptographic keys and mismanagement of signing certificates…
-
New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis
New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis Cybersecurity experts have identified a sophisticated phishing technique that exploits blob URIs (Uniform Resource Identifiers) to evade detection by Secure Email Gateways (SEGs) and security analysis tools. This emerging attack method leverages the unique properties of blob URIs, which are designed to display…
-
Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands
Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands Security researchers have discovered two significant vulnerabilities affecting Mitel’s suite of SIP phones that could allow attackers to execute arbitrary commands and upload malicious files. The more severe vulnerability, identified as CVE-2025-47188, received a critical CVSS score of 9.8 and affects the company’s 6800…
-
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Cybersecurity experts have uncovered a sophisticated attack campaign targeting IT administrators through search engine optimization (SEO) poisoning tactics. Threat actors are leveraging advanced SEO techniques to push malicious versions of commonly used administrative tools to the top of search engine…
-
Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors
Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide. The vulnerability allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable /developmentserver/metadatauploader endpoint.…
-
Threat Actors Attacking Job Seekers With Three New Unique Adversaries
Threat Actors Attacking Job Seekers With Three New Unique Adversaries A significant surge in sophisticated recruitment scams has emerged, with cybercriminals exploiting economic vulnerabilities and the competitive job market to target desperate job seekers. These scams employ increasingly refined social engineering tactics that blend legitimate recruitment practices with fraudulent schemes, making them particularly effective at…
-
Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide
Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS) platform called “Darcula” responsible for stealing approximately 884,000 credit card details through a massive campaign that generated over 13 million clicks…
-
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware
Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware A sophisticated new attack method that disables endpoint security protection has been identified by security researchers, enabling threat actors to deploy ransomware undetected. The technique, dubbed “Bring Your Own Installer,” was recently discovered by Aon’s Stroz Friedberg Incident Response team during an investigation of a Babuk…
-
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands
New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands A sophisticated phishing campaign dubbed “Power Parasites” has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week. The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy,…
-
DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models
DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models Despite significant disruptions by international law enforcement operations targeting major ransomware schemes, cybercriminal groups continue demonstrating remarkable adaptability in 2025. Two noteworthy ransomware operations, DragonForce and Anubis, have introduced innovative affiliate models designed to expand their reach and increase profitability in the ever-evolving cybercrime landscape. DragonForce…
-
New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy
New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy Cybercriminals have dramatically evolved their phishing tactics, leveraging generative AI to create highly personalized and convincing attacks, according to the newly released ThreatLabz 2025 Phishing Report. The days of mass phishing campaigns have given way to hyper-targeted scams designed to exploit…
-
North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers
North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers A sophisticated North Korean advanced persistent threat (APT) group known as “Contagious Interview” has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware. The group, a subunit of the infamous North Korean state-sponsored Lazarus Group, has created three…
-
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations
Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations North Korea’s cybercrime operations have significantly expanded beyond the limited 1,024 IP addresses assigned to their national network through an elaborate scheme involving Russian infrastructure. According to recent findings, five Russian IP ranges, primarily located in the border towns of Khasan and Khabarovsk,…
-
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites
Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites Phishing campaigns have evolved significantly in 2025, with threat actors increasingly leveraging unconventional file formats to bypass security solutions. A particularly concerning trend involves the weaponization of Scalable Vector Graphics (SVG) files, which are being embedded with malicious JavaScript code designed to redirect…
-
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN A server briefly linked to the notorious KeyPlug malware has inadvertently exposed a comprehensive arsenal of exploitation tools specifically designed to target Fortinet firewall and VPN appliances. The infrastructure, which security researchers have attributed to the RedGolf threat group (overlapping with APT41),…
-
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC
How To Prioritize Threat Intelligence Alerts In A High-Volume SOC In today’s rapidly evolving cyber threat landscape, Security Operations Centers (SOCs) face an unprecedented challenge: efficiently managing and prioritizing the overwhelming volume of security alerts they receive daily. SOC analysts often can’t read and respond to a significant portion of the alerts they see every…
-
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data
Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data Shells provide crucial command-line interfaces to operating systems. While legitimate for system administration tasks, when weaponized by threat actors, shells transform into dangerous avenues for unauthorized access, system control, and data theft across organizational networks. The misuse of these tools has become increasingly sophisticated,…
-
RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals
RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025. This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging…
-
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies
Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies Cybersecurity experts have detected a sophisticated campaign targeting energy sector companies, as the threat actor known as Sapphire Werewolf deploys an enhanced version of the Amethyst stealer malware. The campaign represents a significant evolution in the group’s capabilities, featuring advanced evasion techniques and…
-
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows
Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows Google has announced the launch of Agent2Agent Protocol (A2A), a groundbreaking open protocol designed to enable AI agents to communicate with each other, securely exchange information, and coordinate actions across enterprise platforms. Revealed on April 9, 2025, the protocol marks a significant advancement…
-
Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware
Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware Security researchers have identified a critical vulnerability in Ivanti Connect Secure (ICS) VPN appliances that is being actively exploited by suspected Chinese threat actors. The vulnerability, tracked as CVE-2025-22457, is a buffer overflow flaw affecting ICS version 22.7R2.5 and earlier that can lead to remote…
-
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring
Frida Penetration Testing Tool Kit Released With New APIs for Threat Monitoring Frida 16.7.0, the latest version of the popular dynamic instrumentation toolkit, has powerful new APIs specifically designed for advanced threat monitoring and security analysis. This major update, announced on March 13, 2025, introduces groundbreaking capabilities that significantly enhance the toolkit’s utility for security…
-
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot
Microsoft Uncovers Several Vulnerabilities in GRUB2, U-Boot, Barebox Bootloaders Using Copilot Microsoft has discovered multiple critical vulnerabilities affecting widely used bootloaders including GRUB2, U-Boot, and Barebox. These security flaws potentially expose systems to sophisticated boot-level attacks that could compromise devices before operating systems even initialize, allowing attackers to gain persistent and nearly undetectable control over…
-
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows
ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows A sophisticated social engineering technique has recently emerged in the cybersecurity landscape, rapidly gaining traction among threat actors seeking to distribute trojans, ransomware, and particularly Quakbot malware. This technique, known as ClickFix Captcha, exploits users’ trust in familiar web elements…
-
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows
Gamaredon Hacker Group Using Weaponize LNK Files To Drop Remcos Backdoor on Windows A sophisticated cyber espionage campaign targeting Ukrainian entities has been uncovered, revealing the latest tactics of the Russia-linked Gamaredon threat actor group. The attackers are leveraging weaponized LNK files disguised as Office documents to deliver the Remcos backdoor malware, utilizing themes related to…
-
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models
DeBackdoor – Framework to Detect Backdoor Attacks on Deep Models In an era where deep learning models increasingly power critical systems from self-driving cars to medical devices, security researchers have unveiled DeBackdoor, an innovative framework designed to detect stealthy backdoor attacks before deployment. Backdoor attacks, among the most effective and covert threats to deep learning,…
-
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence
Red Team Activities Turns More Sophisticated With The Progress of Artificial Intelligence Artificial intelligence has dramatically transformed the cybersecurity landscape, with red team activities increasingly leveraging sophisticated AI-driven techniques to simulate advanced persistent threats. These AI-enhanced red teams can now automate the process of penetrating targets and collecting sensitive data at unprecedented speeds. The evolution…
-
New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control
New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control A newly identified malware strain dubbed “IOCONTROL” has emerged as a critical threat to operational technology (OT) and Internet of Things (IoT) systems, particularly targeting fuel-management infrastructure in the United States and Israel. First observed in December 2024, this Linux-based malware has been…
-
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT
Hacker Weaponizing Hard Disk Image Files To Deliver VenomRAT A sophisticated phishing campaign is leveraging virtual hard disk (.vhd) files to distribute the dangerous VenomRAT malware. The attack begins with purchase order-themed emails containing archive attachments that, when extracted, reveal hard disk image files designed to evade traditional security measures. Batch file inside .vhd file…
-
Beware of Free File Word To PDF Converter That Delivers Malware
Beware of Free File Word To PDF Converter That Delivers Malware The FBI has issued an urgent warning about the rising threat of malicious file conversion tools that are being used to spread malware across the United States. Cybercriminals are targeting users searching for free utilities to convert documents from one format to another, with…
-
New Context Compliance Attack Jailbreaks Most of The Major AI Models
New Context Compliance Attack Jailbreaks Most of The Major AI Models A new, surprisingly simple method called Context Compliance Attack (CCA) has proven effective at bypassing safety guardrails in most leading AI systems. Unlike complex prompt engineering techniques that attempt to confuse AI systems with intricate word combinations, CCA exploits a fundamental architectural weakness present…
-
Black Basta Ransomware Attack Edge Network Devices With Automated Brute Force Attacks
Black Basta Ransomware Attack Edge Network Devices With Automated Brute Force Attacks A Russian-speaking actor using the Telegram handle @ExploitWhispers leaked internal chat logs of Black Basta Ransomware-as-a-Service (RaaS) members on February 11, 2025. These communications, spanning from September 2023 to September 2024, have provided security researchers with unprecedented insight into the group’s operational tactics…
-
Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations
Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations A sophisticated backdoor malware called “Squidoor” being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia. The malware, designed for exceptional stealth, offers attackers multiple methods to maintain persistent access to compromised networks while evading detection from advanced security systems. Initial…
-
North Korean IT Workers Using GitHub To Attack Organization Globally
North Korean IT Workers Using GitHub To Attack Organization Globally Cybersecurity research firm NISOS has uncovered a network of suspected North Korean IT workers who are leveraging GitHub to create elaborate fake personas aimed at securing employment with companies in Japan and the United States. These individuals pose as Vietnamese, Japanese, and Singaporean nationals while…
-
Google Silently Tracks Android Device Even No Apps Opened by User
Google Silently Tracks Android Device Even No Apps Opened by User Google collects and stores significant amounts of user data on Android devices, even when users haven’t opened any Google apps. The study by Professor D.J. Leith from Trinity College Dublin, documents for the first time how pre-installed Google apps silently track users without seeking…
-
Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses
Weaponized Signal, Line, and Gmail Apps Delivers Malware That Changes System Defenses A sophisticated cyberattack campaign targeting Chinese-speaking users, malicious actors have weaponized fake versions of popular applications such as Signal, Line, and Gmail. These fake and weaponized apps are distributed via deceptive download pages that deliver malware capable of altering system defenses, evading detection,…
-
Beware of Fake Outlook Troubleshooting Calls that Ends Up In Ransomware Deployment
Beware of Fake Outlook Troubleshooting Calls that Ends Up In Ransomware Deployment A sophisticated cyber threat has emerged in recent weeks, targeting unsuspecting users with fake Outlook troubleshooting calls. These calls, designed to appear legitimate, ultimately lead to the deployment of ransomware on the victim’s system. The scam involves a malicious binary named CITFIX#37.exe, which…
-
Hackers Using Pyramid Pentesting Tool For Stealthy C2 Communications
Hackers Using Pyramid Pentesting Tool For Stealthy C2 Communications Hackers have been leveraging the open-source Pyramid pentesting tool to establish stealthy command-and-control (C2) communications. Pyramid, first released on GitHub in 2023, is a Python-based post-exploitation framework designed to evade endpoint detection and response (EDR) tools. Its lightweight HTTP/S server capabilities make it an attractive choice…
-
SAML Bypass Authentication on GitHub Enterprise Servers To Login as Other User Account
SAML Bypass Authentication on GitHub Enterprise Servers To Login as Other User Account A significant vulnerability has been identified in GitHub Enterprise Servers, allowing attackers to bypass SAML authentication and log in as other user accounts. This exploit leverages quirks in the libxml2 library, specifically related to XML entities, to deceive the verification process. The…
-
Hackers Exploiting Google Tag Manager To Steal Credit Card From eCommerce Sites
Hackers Exploiting Google Tag Manager To Steal Credit Card From eCommerce Sites Hackers have been exploiting Google Tag Manager (GTM) to steal sensitive credit card information from eCommerce sites, particularly those built on the Magento platform. This sophisticated attack shows the evolving tactics of cybercriminals in leveraging legitimate tools for malicious purposes. Google Tag Manager…
-
Devil-Traff – New Malicious Bulk SMS Portal That Fuels Phishing Attacks
Devil-Traff – New Malicious Bulk SMS Portal That Fuels Phishing Attacks A new threat to cybersecurity has emerged in the form of Devil-Traff, a bulk SMS platform designed to facilitate large-scale phishing campaigns. Leveraging advanced features such as sender ID spoofing, API integration, and support for malicious content, this platform has become a favorite tool…
-
Google Has Blocked 2.28 Million Malicious Apps Entering Into Play Store
Google Has Blocked 2.28 Million Malicious Apps Entering Into Play Store Google announced today it blocked a record 2.28 million policy-violating apps from entering the Play Store in 2023, leveraging advanced machine learning, stricter developer vetting, and cross-industry collaborations to combat evolving cyberthreats. The milestone underscores efforts to uphold its SAFE principles (Safeguard Users, Advocate…
-
Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges
Critical One Identity Manager Vulnerability Let Attackers Escalate Privileges A critical Insecure Direct Object Reference (IDOR) vulnerability has been identified in One Identity Manager, a widely used identity and access management solution. This vulnerability, officially tracked as CVE-2024-56404, allows unauthorized privilege escalation under specific configurations. The issue affects only On-Premise installations and does not impact…
-
New Phishing Campaign Mimic Amazon Prime Membership To Steal Credit Card Data
New Phishing Campaign Mimic Amazon Prime Membership To Steal Credit Card Data A sophisticated phishing campaign targeting Amazon Prime members has been uncovered, aiming to steal credit card information and other sensitive data. Cybersecurity experts have identified a complex attack chain that leverages PDF attachments, redirects, and cleverly crafted phishing sites to deceive unsuspecting victims.…