Tag: cyber-security-news

  • BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

    BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing hundreds of Steam users to data theft and system compromise. The malicious patch, deployed on August 30, 2025, demonstrates how threat actors are increasingly exploiting…

  • Top 10 Best Supply Chain Risk Management Solutions in 2025

    Top 10 Best Supply Chain Risk Management Solutions in 2025 In today’s rapidly evolving global market, supply chain risk management has become more crucial than ever before. Organizations face risks like geopolitical issues, market unpredictability, compliance challenges, supplier failures, and even cyber threats. To maintain resilience, companies must adopt robust supply chain risk management (SCRM)…

  • 22.2 Tbps DDoS Attack Breaks Internet With New World Record

    22.2 Tbps DDoS Attack Breaks Internet With New World Record Cloudflare announced it had autonomously mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric attack peaked at an unprecedented 22.2 terabits per second (Tbps) and 10.6 billion packets per second (Bpps), setting a new and alarming benchmark for the scale of cyber threats.…

  • European Airport Disruptions Caused by Sophisticated Ransomware Attack

    European Airport Disruptions Caused by Sophisticated Ransomware Attack Over the weekend, a sophisticated ransomware attack compromised Collins Aerospace’s Muse check-in and boarding systems, forcing key hubs including Heathrow, Brussels, and Berlin to return to manual processes. Airlines reported hundreds of delayed and cancelled flights as security teams raced to contain the breach, restore encrypted data,…

  • Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands

    Libraesva ESG Vulnerability Let Attackers Inject Malicious Commands A critical security flaw in Libraesva ESG email security gateways has been identified and patched, allowing threat actors to execute arbitrary commands through specially crafted email attachments.  The vulnerability, tracked as CVE-2025-59689, affects multiple versions of the popular email security platform and has already been exploited by…

  • Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware

    Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware A sophisticated cyber-attack campaign exploiting GitHub Pages to distribute the notorious Atomic stealer malware to macOS users.  The threat actors behind this operation are leveraging Search Engine Optimization (SEO) techniques to position malicious repositories at the top of search results across major platforms,…

  • Cybersecurity Newsletter Weekly – Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More

    Cybersecurity Newsletter Weekly – Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More This week in cybersecurity, researchers exposed hidden alliances between ransomware groups, the rise of AI-powered phishing platforms, and large-scale vulnerabilities affecting telecom and enterprise systems. Major data breaches at financial services and luxury brands highlighted insider threats and supply chain…

  • BlackLock Ransomware Attacking Windows, Linux, and VMware ESXi Environments

    BlackLock Ransomware Attacking Windows, Linux, and VMware ESXi Environments A sophisticated new ransomware operation dubbed BlackLock has emerged as a significant threat to organizations worldwide, demonstrating advanced cross-platform capabilities and targeting diverse computing environments.  Originally operating under the name “El Dorado” since March 2024, the group rebranded to BlackLock in September 2024, establishing itself as…

  • Top Zero-Day Vulnerabilities Exploited in the Wild in 2025

    Top Zero-Day Vulnerabilities Exploited in the Wild in 2025 The cybersecurity landscape in 2025 has been marked by an unprecedented surge in zero-day vulnerabilities actively exploited by threat actors. According to recent data, more than 23,600 vulnerabilities were published in the first half of 2025 alone, representing a 16% increase over 2024. This alarming trend…

  • First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code

    First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Ransomware Code AI-powered malware, known as ‘MalTerminal’, uses OpenAI’s GPT-4 model to dynamically generate malicious code, including ransomware and reverse shells, marking a significant shift in how threats are developed and deployed. This discovery follows the recent analysis of PromptLock, another AI-driven malware, indicating a clear…

  • Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed

    Heathrow and Other European Airports Hit by Cyberattack, Several Flights Delayed A major cyberattack on a popular aviation software provider has caused significant disruptions at key European airports, including London’s Heathrow, Brussels, and Berlin, resulting in hundreds of flight delays and cancellations on Saturday. The attack disabled electronic check-in and baggage drop systems, forcing airport…

  • New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State

    New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and Response (EDR) and antivirus solutions into a suspended “coma” state. According to Zero Salarium, the technique leverages a built-in Windows function, offering a stealthier alternative to the increasingly…

  • Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

    Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication A critical authentication bypass vulnerability has emerged in Nokia’s CloudBand Infrastructure Software (CBIS) and Nokia Container Service (NCS) Manager API, designated as CVE-2023-49564. This high-severity flaw, scoring 9.6 on the CVSS v3.1 scale, enables unauthorized attackers to circumvent authentication mechanisms through specially crafted HTTP headers, potentially…

  • Top 10 Best API Security Testing Tools in 2025

    Top 10 Best API Security Testing Tools in 2025 In today’s rapidly evolving digital landscape, APIs (Application Programming Interfaces) have become the backbone of online business, connecting services, and enabling new customer experiences. However, as the API footprint grows, so does the attack surface making robust API security testing a critical pillar of enterprise cyber…

  • Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools

    Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools Phishing campaigns have long relied on social engineering to dupe unsuspecting users, but recent developments have elevated these attacks to a new level of sophistication. Attackers now harness advanced content-generation platforms to craft highly personalized emails and webpages, blending genuine corporate branding with…

  • BreachLock Named Sample Vendor for PTaaS and AEV in Two New 2025 Gartner® Reports

    BreachLock Named Sample Vendor for PTaaS and AEV in Two New 2025 Gartner® Reports New York, New York, September 19th, 2025, CyberNewsWire BreachLock, the global leader in offensive security, has been recognized as a Sample Vendor for Penetration Testing as a Service (PTaaS) in the 2025 Gartner Hype Cycle for Application Security. The company was…

  • Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’

    Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’ A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, ScreenConnect. The malware is being sold with a suite of advanced features designed to bypass…

  • Russian Airline Suffered Cyberattack Website and Other Systems Affected

    Russian Airline Suffered Cyberattack Website and Other Systems Affected Krasnoyarsk Regional Airlines (KrasAvia) confirmed a sophisticated cyberattack that has rendered its primary online services inoperable.  The breach targeted the airline’s web portal and associated back-end systems, including the Passenger Service System (PSS) and flight planning applications.  As a result, passengers are currently unable to complete…

  • New Phishing Attack Targets Facebook Users to Steal Login Credentials

    New Phishing Attack Targets Facebook Users to Steal Login Credentials A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials. Attackers leverage the platform’s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims to counterfeit Facebook login pages.…

  • Global Spyware Markets to Identify New Entities Entering The Market

    Global Spyware Markets to Identify New Entities Entering The Market The global spyware market continues its alarming expansion, with new research revealing the emergence of 130 additional entities spanning 46 countries between 1992 and 2024. This shadowy ecosystem of surveillance technologies has grown from 435 documented entities in the initial assessment to 561 organizations, fundamentally…

  • Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization

    Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization Detecting remote employment fraud has become a critical priority for organizations striving to secure their digital onboarding processes and safeguard sensitive systems. In recent months, threat actors posing as legitimate hires have leveraged sophisticated tactics to bypass pre-hire screenings and embed themselves within corporate…

  • UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach

    UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach UK law enforcement has arrested two individuals linked to the notorious Scattered Spider cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom payments.  The arrests…

  • Pixie Dust Wi-Fi Attack Exploits Routers WPS to Obtain PIN and Connect With Wireless Network

    Pixie Dust Wi-Fi Attack Exploits Routers WPS to Obtain PIN and Connect With Wireless Network The newly publicized Pixie Dust attack has once again exposed the critical vulnerabilities inherent in the Wi-Fi Protected Setup (WPS) protocol, enabling attackers to extract the router’s WPS PIN offline and seamlessly join the wireless network.  By targeting weak randomization…

  • Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service

    Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or glean sensitive configuration details.  Administrators running Jenkins weekly releases up to 2.527 or the Long-Term Support (LTS) stream up to 2.516.2 must…

  • Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data

    Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data Raven Stealer has emerged as a potent information‐stealing threat targeting users of Chromium‐based browsers, most notably Google Chrome. First observed in mid-2025, this lightweight malware distinguishes itself through a modular architecture and stealthy design, allowing it to harvest sensitive information without alerting victims. Delivered predominantly…

  • Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT

    Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT Python developers face a growing threat from typosquatted packages in the Python Package Index (PyPI), with malicious actors increasingly targeting this trusted repository to distribute sophisticated malware. Recent discoveries have exposed a concerning trend where threat actors create packages that closely mimic legitimate libraries, using…

  • Lessons Learned From Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware

    Lessons Learned From Massive npm Supply Chain Attack Using “Shai-Hulud” Self-Replicating Malware The JavaScript ecosystem experienced one of its most sophisticated and damaging supply chain attacks in September 2025, when a novel self-replicating worm dubbed “Shai-Hulud” compromised over 477 npm packages, marking the first successful automated propagation campaign in the npm registry’s history. This attack represents…

  • World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison

    World’s Largest Hacking Forum BreachForums Creator Sentenced to Three Years in Prison Conor Brian Fitzpatrick, the 22-year-old founder of BreachForums, has been resentenced to three years in federal prison for operating one of the world’s largest cybercriminal marketplaces.  The New York resident was sentenced on September 16, 2025, for creating and administering a platform that…

  • FinWise Insider Breach Exposes 700K Customer Records to Former Employee

    FinWise Insider Breach Exposes 700K Customer Records to Former Employee American First Finance, LLC, a Dallas-based financial services firm, suffered a significant insider breach when a recently terminated employee exploited unauthorized access to its production database.  The incident, dubbed the FinWise insider breach, resulted in the exfiltration of sensitive customer records nearly 689,000 names, Social…

  • Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages

    Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages A large-scale supply chain attack dubbed “Shai-Halud” that infiltrated the JavaScript ecosystem via the npm registry.  In total, 477 packages, including packages from CrowdStrike, were found to contain stealthy backdoors and trojanized modules designed to siphon credentials, exfiltrate source code, and enable remote code execution (RCE) on developer…

  • Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources

    Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources A denial-of-service flaw in the Linux kernel’s KSMBD (SMB Direct) subsystem has raised alarms across the open-source community.  Tracked as CVE-2025-38501, the issue allows a remote, unauthenticated adversary to exhaust all available SMB connections by exploiting the kernel’s handling of half-open TCP sessions.  Key…

  • How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks

    How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks A threat actor who gained initial access through a SonicWall VPN device was able to escalate their attack by finding Huntress recovery codes saved in a plaintext file on a user’s desktop. This allowed the attacker to log into the client’s…

  • SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks

    SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks SmokeLoader, first seen on criminal forums in 2011, has evolved into a highly modular malware loader designed to deliver a variety of second-stage payloads, including trojans, ransomware, and credential stealers. After Operation Endgame disrupted numerous campaigns in mid-2024, the loader reemerged…

  • Spring Framework and Security Vulnerabilities Enables Authorization Bypass and Annotation Detection Flaw

    Spring Framework and Security Vulnerabilities Enables Authorization Bypass and Annotation Detection Flaw Two critical vulnerabilities, CVE-2025-41248 and CVE-2025-41249, have emerged in Spring Security and Spring Framework that could allow attackers to bypass authorization controls in enterprise applications.  These flaws arise when using Spring Security’s @EnableMethodSecurity feature in conjunction with method-level annotations such as @PreAuthorize and…

  • New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials

    New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials Since May 2025, a novel credential stealer dubbed Maranhão Stealer has emerged as a significant threat to users of pirated gaming software. Distributed through deceptive websites hosting cracked launchers and cheats, the malware leverages cloud-hosted platforms to deliver trojanized installers that appear…

  • Open Source CyberSOCEval Sets New Standards for AI in Malware Analysis and Threat Intelligence

    Open Source CyberSOCEval Sets New Standards for AI in Malware Analysis and Threat Intelligence A groundbreaking open-source benchmark suite called CyberSOCEval has emerged as the first comprehensive evaluation framework for Large Language Models (LLMs) in Security Operations Center (SOC) environments.  Released as part of CyberSecEval 4, this innovative benchmark addresses critical gaps in cybersecurity AI…

  • AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack

    AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU. Emerging from XLab’s continuous monitoring of global DDoS incidents, this botnet leveraged…

  • Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online

    Great Firewall of China’s Sensitive Data of Over 500GB+ Leaked Online The Great Firewall of China (GFW) suffered its largest-ever internal data breach. More than 500 GB of sensitive material—including source code, work logs, configuration files, and internal communications—was exfiltrated and published online.  The breach stems from Geedge Networks and the MESA Lab at the…

  • Top 10 Best Ransomware Protection Solutions in 2025

    Top 10 Best Ransomware Protection Solutions in 2025 Ransomware continues to be one of the most destructive and pervasive cyber threats facing organizations of all sizes. In 2025, the sophistication of ransomware attacks has reached unprecedented levels, with threat actors employing advanced techniques like double extortion, supply chain attacks, and leveraging artificial intelligence to bypass…

  • New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

    New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm Emerging in early September 2025, the Yurei ransomware has swiftly drawn attention for its novel combination of Go-based execution and ChaCha20 encryption. First documented on September 5 when a Sri Lankan food manufacturer fell victim, the threat actor behind Yurei adopted a double-extortion model:…

  • DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments

    DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments DarkCloud Stealer has recently emerged as a potent threat targeting financial organizations through convincing phishing campaigns. Adversaries employ weaponized RAR attachments masquerading as legitimate documents to deliver a multi-stage JavaScript-based payload. Upon opening the archive, victims execute a VBE script that leverages Windows Script Host to…

  • New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

    New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, combines multiple anti-analysis techniques and adversary-in-the-middle (AitM) capabilities to target Microsoft 365 and Google accounts…

  • Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing

    Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing Nmap vs Wireshark are the most popular Network penetration testing tools. Security professionals face an increasingly complex threat landscape, and picking the right penetration testing tools can make the difference between a secure infrastructure and a compromised network. While both serve critical roles in…

  • FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration

    FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes. The advisory, published by the FBI on September 12, 2025,…

  • What Are The Takeaways From The Scattered LAPSUS $Hunters Statement?

    What Are The Takeaways From The Scattered LAPSUS $Hunters Statement? The well-known group of cybercriminals called Scattered Lapsus$ Hunters released a surprising farewell statement on BreachForums. This manifesto, a mix of confession and strategic deception, offers vital insights into the changing landscape of modern cybercrime and the increasing pressure from global law enforcement agencies. The…

  • New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT

    New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT Cybersecurity researchers have uncovered a sophisticated malware campaign that exploits SVG (Scalable Vector Graphics) files and email attachments to distribute dangerous Remote Access Trojans, specifically XWorm and Remcos RAT. This emerging threat represents a significant evolution in attack methodologies, as threat actors…

  • Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints

    Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints A sophisticated backdoor malware known as Backdoor.WIN32.Buterat has emerged as a significant threat to enterprise networks, demonstrating advanced persistence techniques and stealth capabilities that enable attackers to maintain long-term unauthorized access to compromised systems. The malware has been identified targeting government and corporate environments through…

  • New Malvertising Campaign Leverages GitHub Repository to Deliver Malware

    New Malvertising Campaign Leverages GitHub Repository to Deliver Malware A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform to deceive unsuspecting users into downloading…

  • EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections

    EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques to infiltrate systems…

  • Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods

    Microsoft Exchange Online Outage for Users Accessing Email via Exchange Online Methods Microsoft is investigating a significant Exchange Online service disruption that is preventing users in North and South America from accessing their mailboxes. The ongoing incident, tracked under the ID EX1151485 in the admin center, impacts all methods of connecting to the email service.…

  • VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests)

    VirtualBox 7.2.2 Released With Fix For GUI Crashes On Virtual Machines (guests) Oracle has released VirtualBox 7.2.2, a maintenance update for its open-source virtualization platform, focusing on improving stability and addressing a range of bugs. Released on September 10, 2025, this version comes as a follow-up to the major 7.2 release, which introduced significant new…

  • Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices

    Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices Apple has issued a warning regarding highly sophisticated “mercenary spyware” attacks targeting a select group of its users. The company’s threat notification system is designed to alert and support individuals who may have been targeted due to their profession or public profile, such as journalists,…

  • Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects

    Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects Microsoft has officially announced a multi-phase plan to deprecate VBScript in Windows, a move that signals a significant shift for developers, particularly those working with Visual Basic for Applications (VBA). The change, first detailed in May 2024, will gradually phase out the legacy…

  • Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

    Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges Microsoft has addressed four elevation of privilege vulnerabilities in its Windows Defender Firewall service, all rated as “Important” in severity. The security flaws were detailed in Microsoft’s September 9, 2025, security update release. If exploited, these vulnerabilities could allow an authenticated attacker to gain higher privileges on…

  • ACSC Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks

    ACSC Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks The Australian Cyber Security Centre (ACSC) has issued a critical alert regarding a severe access control vulnerability in SonicWall products that is being actively exploited in attacks. The flaw, tracked as CVE-2024-40766, affects multiple generations of SonicWall firewalls and carries a critical CVSS score…

  • DDoS Mitigation Provider targeted In 1.5 Gpps 1.5 Billion Packets per Second DDoS Attack

    DDoS Mitigation Provider targeted In 1.5 Gpps 1.5 Billion Packets per Second DDoS Attack FastNetMon, a prominent provider of DDoS detection solutions, announced this week that it had identified and helped mitigate a record-breaking distributed denial-of-service (DDoS) attack. The assault targeted a major DDoS scrubbing vendor located in Western Europe, pushing packet-forwarding rates to an…

  • 1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon

    1.5 Billion Packets Per Second DDoS Attack Detected with FastNetMon FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The malicious traffic was primarily a UDP…

  • Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities

    Senator Calls for FTC Investigation into Microsoft’s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms “gross cybersecurity negligence,” accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption…

  • Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs

    Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations. The schemes reportedly extorted over 250 companies in…

  • Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code

    Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were disclosed on September 9, 2025, and affect various versions of the popular productivity suite. While Microsoft…

  • Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System

    Critical SAP NetWeaver Vulnerability Let Attackers Execute Arbitrary Code And Compromise System A critical vulnerability CVE-2025-42922 has been discovered in SAP NetWeaver that allows an authenticated, low-privileged attacker to execute arbitrary code and achieve a full system compromise. The flaw resides in the Deploy Web Service upload mechanism, where insufficient access control validation permits the…

  • Windows BitLocker Vulnerability Let Attackers Elevate Privileges

    Windows BitLocker Vulnerability Let Attackers Elevate Privileges Microsoft has addressed two significant elevation of privilege vulnerabilities affecting its Windows BitLocker encryption feature. The flaws, tracked as CVE-2025-54911 and CVE-2025-54912, were disclosed on September 9, 2025, and carry an “Important” severity rating. Both vulnerabilities could allow an authorized attacker to gain full SYSTEM privileges on a…

  • Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication

    Sophos Wireless Access Points Vulnerability Let Attackers Bypass Authentication Sophos has resolved an authentication bypass vulnerability in its AP6 Series Wireless Access Points that could allow attackers to gain administrator-level privileges. The company discovered the issue during internal security testing and has released a firmware update to address it. The security vulnerability allows an attacker…

  • HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

    HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns. The bug bounty platform announced the…

  • SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

    SpamGPT – AI-powered Attack Tool Used By Hackers For Massive Phishing Attack A sophisticated new cybercrime toolkit named SpamGPT is enabling hackers to launch massive and highly effective phishing campaigns by combining artificial intelligence with the capabilities of professional email marketing platforms. Marketed on the dark web as a “spam-as-a-service” platform, SpamGPT automates nearly every…

  • Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials

    Elastic Salesloft Drift Security Incident – Hackers Accessed Email Account Contains Valid Credentials Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company’s core Salesforce environment was not impacted, the incident exposed sensitive information contained…

  • Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads

    Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved injecting malicious code designed to steal cryptocurrency from users. The compromised packages include…

  • Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

    Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM. The company confirmed that the incident was limited to its CRM platform and did…

  • New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability

    New Technique Uncovered To Exploit Linux Kernel Use-After-Free Vulnerability A new technique to exploit a complex use-after-free (UAF) vulnerability in the Linux kernel successfully bypasses modern security mitigations to gain root privileges. The method targets CVE-2024-50264, a difficult-to-exploit race condition bug in the AF_VSOCK subsystem that was recognized with a Pwnie Award for its complexity. The vulnerability,…

  • How Microsoft Azure Storage Logs Aid Forensics Following a Security Breach

    How Microsoft Azure Storage Logs Aid Forensics Following a Security Breach After a security breach, forensic investigators work quickly to follow the attacker’s trail. Security experts have analyzed this situation and found that a key source of evidence is often overlooked: Microsoft Azure Storage logs. While frequently overlooked, these logs provide invaluable insights that can…

  • U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China

    U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China U.S. federal authorities have launched an investigation into a sophisticated malware campaign that targeted sensitive trade negotiations between Washington and Beijing. The attack, which surfaced in July 2025, involved fraudulent emails purportedly sent by Representative John Moolenaar, chairman of the House Select Committee on Strategic…

  • Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data

    Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data The notorious Lazarus APT group has evolved its attack methodology by incorporating the increasingly popular ClickFix social engineering technique to distribute malware and steal sensitive intelligence data from targeted organizations. This North Korean-linked threat actor, internally tracked as APT-Q-1 by security researchers, has demonstrated…

  • Australian Authorities Uncovered Activities and Careers of Ransomware Criminal Groups

    Australian Authorities Uncovered Activities and Careers of Ransomware Criminal Groups Ransomware has emerged as one of the most devastating cybercrime threats in the contemporary digital landscape, with criminal organizations operating sophisticated billion-dollar enterprises that target critical infrastructure across multiple nations. Between 2020 and 2022, ransomware groups conducted over 865 documented attacks against organizations in Australia,…

  • Atomic Stealer Disguised as Cracked Software Attacking macOS Users

    Atomic Stealer Disguised as Cracked Software Attacking macOS Users A sophisticated malware campaign targeting macOS users has emerged, exploiting the widespread desire for free software to deliver the notorious Atomic macOS Stealer (AMOS). This information-stealing malware masquerades as cracked versions of popular applications, tricking unsuspecting users into compromising their own systems while believing they are…

  • Critical Argo CD API Vulnerability Exposes Repository Credentials

    Critical Argo CD API Vulnerability Exposes Repository Credentials A critical vulnerability has been discovered in Argo CD that allows API tokens with limited permissions to access sensitive repository credentials. The flaw in the project details API endpoint exposes usernames and passwords, undermining the platform’s security model by granting access to secrets without explicit permissions. The…

  • Top 10 Best AI Penetration Testing Companies in 2025

    Top 10 Best AI Penetration Testing Companies in 2025 AI is no longer just a buzzword; it’s a fundamental part of business operations, from customer service chatbots to complex financial models. However, this adoption has created a new and specialized attack surface. Traditional penetration testing, which focuses on network and application vulnerabilities, is insufficient to…

  • 10 Best Cloud Penetration Testing Companies in 2025

    10 Best Cloud Penetration Testing Companies in 2025 As more businesses migrate their infrastructure to the cloud, cloud penetration testing has become a critical service. Unlike traditional network tests, cloud pentesting focuses on unique attack vectors such as misconfigured services, insecure APIs, and overly permissive IAM (Identity and Access Management) policies. In 2025, the best…

  • “GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload

    “GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload A sophisticated malware campaign, dubbed “GPUGate,” abuses Google Ads and GitHub’s repository structure to trick users into downloading malicious software. The Arctic Wolf Cybersecurity Operations Center, the attack chain uses a novel technique to evade security analysis by leveraging a computer’s Graphics Processing…

  • SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month

    SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month A new ransomware threat has emerged as one of 2025’s most prolific cybercriminal operations, with SafePay ransomware claiming attacks against 73 victim organizations in June alone, followed by 42 additional victims in July. This surge has positioned SafePay as a significant threat actor…

  • 143,000 Malware Files Attacked Android and iOS Device Users in Q2 2025

    143,000 Malware Files Attacked Android and iOS Device Users in Q2 2025 Cybercriminals unleashed a massive wave of mobile malware attacks during the second quarter of 2025, with security researchers detecting nearly 143,000 malicious installation packages targeting Android and iOS devices. This surge represents a significant escalation in mobile cyber threats, affecting millions of users…

  • New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing

    New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing A recent investigation has revealed that Microsoft employed China-based engineers to maintain and support SharePoint software, the same collaboration platform that was recently compromised by Chinese state-sponsored hackers. This revelation raises significant concerns about cybersecurity practices and potential insider threats within critical…

  • Kali Linux vs Parrot OS – Which Penetration Testing Platform is Most Suitable for Cybersecurity Professionals?

    Kali Linux vs Parrot OS – Which Penetration Testing Platform is Most Suitable for Cybersecurity Professionals? Penetration testing and ethical hacking have been dominated by specialized Linux distributions designed to provide security professionals with comprehensive toolsets for vulnerability assessment and network analysis. Among the most prominent options, Kali Linux and Parrot OS have emerged as leading contenders, each offering…

  • TAG-150 Hackers Deploying Self-Developed Malware Families to Attack Organizations

    TAG-150 Hackers Deploying Self-Developed Malware Families to Attack Organizations A sophisticated new threat actor designated TAG-150 has emerged as a significant cybersecurity concern, demonstrating rapid development capabilities and technical sophistication in deploying multiple self-developed malware families since March 2025. The group has successfully created and deployed CastleLoader, CastleBot, and their latest creation, CastleRAT, a previously…

  • Colombian Malware Weaponizing SWF and SVG to Bypass Detection

    Colombian Malware Weaponizing SWF and SVG to Bypass Detection A previously unseen malware campaign began circulating in early August 2025, through email attachments and web downloads, targeting users in Colombia and beyond. By leveraging two distinct vector-based file formats—Adobe Flash SWF and Scalable Vector Graphics (SVG)—the attackers crafted a multiphase operation that evaded traditional antivirus…

  • Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files

    Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files A new technique that allows attackers to read highly sensitive files on Windows systems, bypassing many of the modern security tools designed to prevent such breaches. A report from Workday’s Offensive Security team explains how, by reading data directly from a…

  • Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign

    Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign Cybercriminals are increasingly exploiting the trust organizations place in artificial intelligence platforms to conduct sophisticated phishing attacks, according to a new report from cybersecurity firm Cato Networks. The company’s Managed Detection and Response (MDR) service recently uncovered a campaign where threat actors leveraged…

  • Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges

    Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges A recently patched vulnerability in a core Windows driver could allow a local attacker to execute code with the highest system privileges, effectively taking full control of a target machine. The flaw, identified as CVE-2025-53149, is a heap-based buffer overflow discovered in the Kernel Streaming WOW…

  • CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks

    CISA Warns of Linux Kernel Race Condition Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity vulnerability in the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, signaling that it is being actively exploited in attacks. The warning, issued on September 4, 2025, calls for urgent…

  • Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments

    Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish long-term footholds within global telecommunications and government networks. These actors, often identified under monikers such as Salt Typhoon and OPERATOR…

  • Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses

    Massive IPTV Hosted Across More Than 1,000 Domains and Over 10,000 IP Addresses A sprawling network of illicit Internet Protocol Television (IPTV) services has been discovered, operating across more than 1,100 domains and in excess of 10,000 IP addresses. This sprawling infrastructure, which has remained active for several years, delivers unauthorized streams of premium content—including…

  • New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face

    New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source…

  • XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust

    XWorm Malware With New Infection Chain Evade Detection Exploiting User and System Trust Emerging quietly in mid-2025, the XWorm backdoor has evolved into a deceptively sophisticated threat that preys on both user confidence and system conventions. Initial reports surfaced when organizations noted a sudden uptick in obscure .lnk-based phishing emails masquerading as benign documents. Security…

  • Threat Actors Attack PayPal Users in New Account Profile Set up Scam

    Threat Actors Attack PayPal Users in New Account Profile Set up Scam A sophisticated phishing campaign targeting PayPal’s massive user base has emerged, utilizing deceptive “Set up your account profile” emails to compromise user accounts through an ingenious secondary user addition scheme. The attack leverages advanced email spoofing techniques and psychological manipulation tactics to bypass…

  • CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks

    CISA Warns of WhatsApp 0-Day Vulnerability Exploited in Attacks CISA has issued an urgent advisory concerning a newly disclosed zero-day vulnerability in Meta Platforms’ WhatsApp messaging service (CVE-2025-55177).  This flaw, categorized under CWE-863: Incorrect Authorization, allows an unauthorized actor to manipulate linked device synchronization messages and force a target device to fetch and process content…

  • Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack

    Android Security Update – Patch for 0-Day Vulnerabilities Actively Exploited in Attack In response to the discovery of actively exploited 0-day vulnerabilities, Google has released its September 2025 Android Security Bulletin, rolling out patch level 2025-09-05 to safeguard millions of devices. The bulletin details critical issues in both System and Kernel components, and emphasizes the…

  • Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes

    Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes Threat actors are rapidly weaponizing Hexstrike-AI, a recently released AI-powered offensive security framework, to scan for and exploit zero-day CVEs in under ten minutes.  Originally marketed as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed by malicious operators…

  • New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files

    New TinyLoader Malware Attacking Windows Users Via Network Shares and Fake Shortcuts Files A stealthy new malware loader dubbed TinyLoader has begun proliferating across Windows environments, exploiting network shares and deceptive shortcut files to compromise systems worldwide. First detected in late August 2025, TinyLoader installs multiple secondary payloads—most notably RedLine Stealer and DCRat—transforming infected machines…

  • PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability

    PoC Exploit Released for IIS WebDeploy Remote Code Execution Vulnerability A proof-of-concept exploit for CVE-2025-53772, a critical remote code execution vulnerability in Microsoft’s IIS Web Deploy (msdeploy) tool, was published this week, raising urgent alarms across the .NET and DevOps communities.  The flaw resides in the unsafe deserialization of HTTP header contents in both the msdeployagentservice and msdeploy.axd…

  • Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely

    Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code.  These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each carry a CVSS score of 9.8 and exploit buffer-corruption weaknesses to compromise device security. Key…

  • New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities

    New TinkyWinkey Stealthily Attacking Windows Systems With Advanced Keylogging Capabilities A sophisticated Windows-based keylogger known as TinkyWinkey began surfacing on underground forums in late June 2025, targeting enterprise and individual endpoints with unprecedented stealth. Unlike traditional keylogging tools that rely on simple hooks or user-mode processes, TinkyWinkey leverages dual components—a Windows service and an injected…