Tag: cyber-security-news

  • Abusing dMSA with Advanced Active Directory Persistence Techniques 

    Abusing dMSA with Advanced Active Directory Persistence Techniques  Delegated Managed Service Accounts (dMSAs), introduced in Windows Server 2025, represent Microsoft’s latest innovation in secure service account management.  While designed to enhance security by preventing traditional credential theft attacks like Kerberoasting, security researchers have uncovered potential abuse vectors that could allow attackers to establish persistent access…

  • Preventing Phishing Attacks on Cryptocurrency Exchanges

    Preventing Phishing Attacks on Cryptocurrency Exchanges Cryptocurrency exchanges are intensifying security measures in 2025 to focus on preventing phishing attacks, as these scams reach alarming levels and have caused millions in losses for investors. As digital assets continue gaining mainstream adoption, cybercriminals deploy increasingly sophisticated techniques to compromise exchange accounts and steal funds. While exchanges…

  • AI Security Frameworks – Ensuring Trust in Machine Learning

    AI Security Frameworks – Ensuring Trust in Machine Learning As artificial intelligence transforms industries and enhances human capabilities, the need for strong AI security frameworks has become paramount. Recent developments in AI security standards aim to mitigate risks associated with machine learning systems while fostering innovation and building public trust. Organizations worldwide are now navigating…

  • Malware Defense 101 – Identifying and Removing Modern Threats

    Malware Defense 101 – Identifying and Removing Modern Threats The cybersecurity landscape in 2025 is defined by increasingly sophisticated malware threats, with attackers leveraging artificial intelligence, evasion tactics, and polymorphic code to bypass traditional defenses. Stealers, ransomware, and remote access trojans (RATs) dominate the threat matrix, while AI-driven malware adapts in real time to exploit…

  • PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files

    PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files A new information-stealing malware dubbed “PupkinStealer” has been identified by cybersecurity researchers, targeting sensitive user data through a straightforward yet effective approach. First observed in April 2025, this .NET-based malware written in C# focuses on stealing browser credentials, messaging app sessions, and desktop files,…

  • Adversarial Machine Learning – Securing AI Models

    Adversarial Machine Learning – Securing AI Models As AI systems using adversarial machine learning integrate into critical infrastructure, healthcare, and autonomous technologies, a silent battle ensues between defenders strengthening models and attackers exploiting vulnerabilities. The field of adversarial machine learning (AML) has emerged as both a threat vector and a defense strategy, with 2025 witnessing…

  • APT Group 123 Actively Attacking Windows Systems to Deliver Malicious Payloads

    APT Group 123 Actively Attacking Windows Systems to Deliver Malicious Payloads North Korean state-sponsored threat actor APT Group 123 has intensified its cyber espionage campaign, specifically targeting Windows systems across multiple sectors globally. The group, active since at least 2012 and also tracked under aliases such as APT37, Reaper, and ScarCruft, has historically focused on…

  • VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited – Pwn2Own Day 2

    VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited – Pwn2Own Day 2 Security researchers uncovered critical zero-day vulnerabilities across major enterprise platforms during the second day of Pwn2Own Berlin 2025, earning a staggering $435,000 in bounties. The competition, hosted at the OffensiveCon conference, witnessed successful exploits against VMware ESXi, Microsoft SharePoint, Mozilla…

  • Securing Generative AI – Mitigating Data Leakage Risks

    Securing Generative AI – Mitigating Data Leakage Risks Generative artificial intelligence (GenAI) has emerged as a transformative force across industries, enabling content creation, data analysis, and decision-making breakthroughs. However, its rapid adoption has exposed critical vulnerabilities, with data leakage emerging as the most pressing security challenge. Recent incidents, including the alleged OmniGPT breach impacting 34…

  • Cloud Security Essentials – Protecting Multi-Cloud Environments

    Cloud Security Essentials – Protecting Multi-Cloud Environments As organizations increasingly adopt multi-cloud environments to leverage flexibility, scalability, and cost-efficiency, securing these complex infrastructures has become a top priority. By 2025, 99% of cloud security failures will stem from customer misconfigurations or oversights, underscoring the urgent need for robust defense mechanisms. With 80% of organizations experiencing…

  • New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials

    New FrigidStealer Malware Attacking macOS Users to Steal Login Credentials FrigidStealer, a sophisticated information-stealing malware that emerged in January 2025, is actively targeting macOS endpoints to steal sensitive user data through deceptive tactics. Unlike traditional malware, FrigidStealer exploits user trust in routine software updates, making it particularly insidious. The malware has raised significant concerns among…

  • Hacking Abusing GovDelivery For TxTag ‘Toll Charges’ Phishing Attack

    Hacking Abusing GovDelivery For TxTag ‘Toll Charges’ Phishing Attack A sophisticated phishing operation exploiting compromised Indiana government sender accounts to distribute fraudulent TxTag toll collection messages.  The campaign, which emerged this week, leverages the GovDelivery communications platform to lend legitimacy to the scam emails targeting unsuspecting recipients nationwide. Sophisticated Phishing Targets Indiana Toll Users  The…

  • Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network

    Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network Microsoft has issued a security advisory regarding a new vulnerability in Active Directory Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network.  The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been…

  • Google Threat Intelligence Launches Actionable Technique To Hunt for Malicious .Desktop Files

    Google Threat Intelligence Launches Actionable Technique To Hunt for Malicious .Desktop Files Google Threat Intelligence has launched a new blog series aimed at empowering security professionals with advanced threat hunting techniques, kicking off with a deep dive into detecting malicious .desktop files on Linux systems. .desktop files, standard configuration files in Linux desktop environments, define…

  • Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges

    Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges A newly disclosed security flaw in Microsoft Defender for Endpoint could allow attackers with local access to elevate their privileges to SYSTEM level, potentially gaining complete control over affected systems.  The vulnerability, tracked as CVE-2025-26684, was patched as part of Microsoft’s May 2025 Patch Tuesday security updates…

  • 82,000+ WordPress Sites Exposed to Remote Code Execution Attacks

    82,000+ WordPress Sites Exposed to Remote Code Execution Attacks Critical vulnerabilities were identified in TheGem, a premium WordPress theme with more than 82,000 installations worldwide.  Researchers identified two separate but interconnected vulnerabilities in TheGem theme versions 5.10.3 and earlier.  When combined, these vulnerabilities create a dangerous attack vector that could lead to remote code execution…

  • Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats

    Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats A disturbing pattern of security failures in the firmware supply chain continues to expose millions of devices to pre-OS threats, potentially undermining the foundation of computer security. Between 2022 and 2025, a series of critical security incidents involving leaked cryptographic keys and mismanagement of signing certificates…

  • Ransomware Wreaks Havoc on Businesses Struggling to Bolster Digital Security Measures

    Ransomware Wreaks Havoc on Businesses Struggling to Bolster Digital Security Measures In an alarming trend that shows no signs of abating, ransomware attacks continue to devastate businesses worldwide as organizations struggle to strengthen their digital security infrastructure amid rising threats. Recent data reveals a record-breaking surge in attacks, with devastating financial consequences for unprepared companies.…

  • Cobalt Strike 4.11.1 Released With Fix For ‘Enable SSL’ Checkbox

    Cobalt Strike 4.11.1 Released With Fix For ‘Enable SSL’ Checkbox Fortra has released Cobalt Strike 4.11.1, an out-of-band update addressing critical issues discovered in their recent 4.11 release.  This update, released on May 12, 2025, focuses primarily on resolving module stomping complications while also addressing issues with SSL certificate functionality and adding deprecation warnings for…

  • PoC Exploit Released for macOS CVE-2025-31258 Vulnerability Bypassing Sandbox Security

    PoC Exploit Released for macOS CVE-2025-31258 Vulnerability Bypassing Sandbox Security A proof-of-concept (PoC) exploit has been released for a recently patched vulnerability in Apple’s macOS operating system, tracked as CVE-2025-31258.  The flaw could allow malicious applications to break out of the macOS sandbox protection mechanism, potentially giving attackers access to sensitive system resources and user…

  • F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands

    F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands F5 Networks has disclosed a high-severity command injection vulnerability (CVE-2025-31644) in its BIG-IP products running in Appliance mode.  The vulnerability exists in an undisclosed iControl REST endpoint and BIG-IP TMOS Shell (tmsh) command, allowing attackers to bypass Appliance mode security restrictions.  Classified as CWE-78…

  • New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis

    New Phishing Attack Abusing Blob URLs to Bypass SEGs and Evade Analysis Cybersecurity experts have identified a sophisticated phishing technique that exploits blob URIs (Uniform Resource Identifiers) to evade detection by Secure Email Gateways (SEGs) and security analysis tools. This emerging attack method leverages the unique properties of blob URIs, which are designed to display…

  • PoC Exploit Released For Linux Kernel’s nftables Subsystem Vulnerability

    PoC Exploit Released For Linux Kernel’s nftables Subsystem Vulnerability A critical Proof-of-Concept (PoC) exploit has been released for a significant vulnerability in the Linux kernel’s nftables subsystem, tracked as CVE-2024-26809.  This flaw, rooted in the kernel’s netfilter infrastructure, exposes affected systems to local privilege escalation through a sophisticated double-free attack.  Security researchers, including the user…

  • Defendnot — A New Tool That Disables Windows Defender by Posing as an Antivirus Solution

    Defendnot — A New Tool That Disables Windows Defender by Posing as an Antivirus Solution Defendnot, a sophisticated new tool that effectively disables Windows Defender by exploiting the Windows Security Center (WSC) API to register itself as a legitimate antivirus solution.  The Windows Security Center service is designed to ensure Windows computers maintain adequate security…

  • Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands

    Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands Security researchers have discovered two significant vulnerabilities affecting Mitel’s suite of SIP phones that could allow attackers to execute arbitrary commands and upload malicious files. The more severe vulnerability, identified as CVE-2025-47188, received a critical CVSS score of 9.8 and affects the company’s 6800…

  • “PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram

    “PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram A newly identified information-stealing malware, dubbed PupkinStealer, Developed in C# using the .NET framework, this lightweight yet effective malware targets sensitive user data, including browser credentials, desktop files, messaging app sessions, and screenshots. According to a CYFIRMA detailed analysis shared with Cyber Security…

  • Microsoft Teams To Block Screen Capture During Meetings

    Microsoft Teams To Block Screen Capture During Meetings Microsoft has announced a new “Prevent Screen Capture” feature for Teams that will block unauthorized screenshots during meetings. The feature, scheduled for worldwide rollout in July 2025, represents Microsoft’s continued focus on enterprise security and regulatory compliance in an era where sensitive information is increasingly shared in…

  • 20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly

    20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly In a coordinated effort, Lumen Technologies’ Black Lotus Labs, the U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), and the Dutch National Police have dismantled a sophisticated criminal proxy network that has operated since 2004. Proxy network homepage…

  • Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers

    Beware! Fake AI Video Generation Platforms Drop Stealer Malware on Your Computers As artificial intelligence (AI) tools gain mainstream traction for content creation, cybercriminals are capitalizing on the hype with a sophisticated new attack vector, fake AI platforms promising advanced video and image editing capabilities. These fraudulent sites, amplified through viral social media campaigns and…

  • Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results

    Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Cybersecurity experts have uncovered a sophisticated attack campaign targeting IT administrators through search engine optimization (SEO) poisoning tactics. Threat actors are leveraging advanced SEO techniques to push malicious versions of commonly used administrative tools to the top of search engine…

  • Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors

    Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide. The vulnerability allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable /developmentserver/metadatauploader endpoint.…

  • Threat Actors Attacking Job Seekers With Three New Unique Adversaries

    Threat Actors Attacking Job Seekers With Three New Unique Adversaries A significant surge in sophisticated recruitment scams has emerged, with cybercriminals exploiting economic vulnerabilities and the competitive job market to target desperate job seekers. These scams employ increasingly refined social engineering tactics that blend legitimate recruitment practices with fraudulent schemes, making them particularly effective at…

  • Beyond DDoS: The New Breed Of Layer 7 Attacks And How SMEs Can Outmaneuver Them 

    Beyond DDoS: The New Breed Of Layer 7 Attacks And How SMEs Can Outmaneuver Them  When most people think of DDoS attacks, they envision tsunami-like floods of traffic overwhelming servers. That’s the classic Layer 3/4 strategy brute force attacks meant to crash services by clogging up bandwidth. But over the last quarter, I’ve seen a…

  • Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide

    Darcula (PhaaS) Stolen 884,000 Credit Card Details on 13 Million Clicks from Users Worldwide Security researchers have uncovered one of the largest credit card theft operations in recent history, with a sophisticated Phishing-as-a-Service (PhaaS) platform called “Darcula” responsible for stealing approximately 884,000 credit card details through a massive campaign that generated over 13 million clicks…

  • Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware

    Threat Actor Bypass SentinelOne EDR to Deploy Babuk Ransomware A sophisticated new attack method that disables endpoint security protection has been identified by security researchers, enabling threat actors to deploy ransomware undetected.  The technique, dubbed “Bring Your Own Installer,” was recently discovered by Aon’s Stroz Friedberg Incident Response team during an investigation of a Babuk…

  • UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes

    UDP Vulnerability in Windows Deployment Services Allows 0-Click System Crashes A newly discovered vulnerability in Microsoft’s Windows Deployment Services (WDS) allows attackers to remotely crash servers with zero user interaction or authentication.  The flaw, which targets the UDP-based TFTP service at the WDS, could allow even low-skilled attackers to paralyze enterprise OS deployment infrastructure in…

  • PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test 

    PCI Compliance Is Not Just A Checkbox It’s A Live-Fire Security Test  Most executives still treat PCI DSS like paperwork something to file away after a quarterly scan. But that mindset is dangerous. PCI compliance isn’t just a checklist it’s a survival test. Every rule in PCI exists because someone got breached. These aren’t hypotheticals;…

  • Conducting Penetration Testing – CISO’s Resource Guide

    Conducting Penetration Testing – CISO’s Resource Guide In today’s digital landscape, organizations are constantly threatened by cyber adversaries who exploit vulnerabilities with increasing sophistication. For Chief Information Security Officers (CISOs), penetration testing is no longer a periodic checkbox but a dynamic and strategic necessity. It enables organizations to proactively uncover weaknesses before attackers do, offering…

  • Upskilling Your Security Team – A CISO’s Strategy for Closing the Skills Gap

    Upskilling Your Security Team – A CISO’s Strategy for Closing the Skills Gap The cybersecurity skills gap is a persistent challenge facing organizations worldwide. As threats become more sophisticated and technology evolves at a rapid pace, the demand for skilled security professionals far outpaces supply. For CISOs, this isn’t just a hiring problem-it’s a strategic…

  • How CISOs Can Balance Innovation and Security in a Digital-First World

    How CISOs Can Balance Innovation and Security in a Digital-First World In today’s fast-paced digital landscape, CISOs play a pivotal role in organizational success, navigating the critical balance of innovation vs security in a digital-first world. Their role is no longer confined to just protecting data and systems-they are now expected to drive business growth…

  • Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments

    Over 90% of Cybersecurity Leaders Worldwide Encountered Cyberattacks Targeting Cloud Environments In what security experts are describing as a “distributed crisis,” a staggering 90% of cybersecurity and IT leaders worldwide reported experiencing cyberattacks targeting their cloud environments within the past year. This alarming statistic emerges from comprehensive research conducted across ten countries, highlighting the increasing…

  • Apache ActiveMQ Vulnerability Allows Remote Attackers to Execute Arbitrary Code

    Apache ActiveMQ Vulnerability Allows Remote Attackers to Execute Arbitrary Code A critical security vulnerability (CVE-2025-29953) in Apache ActiveMQ’s NMS OpenWire Client has been disclosed, enabling remote attackers to execute arbitrary code on vulnerable systems. The flaw, rooted in unsafe deserialization of untrusted data, affects versions prior to 2.1.1 and poses significant risks to organizations using…

  • Defending Against APTs – CISO’s Strategic Guide

    Defending Against APTs – CISO’s Strategic Guide Advanced Persistent Threats (APTs) represent one of the most formidable challenges in the cybersecurity landscape. These sophisticated attacks, typically orchestrated by nation-states or well-funded criminal organizations, target critical infrastructure, government agencies, and enterprises with surgical precision. Unlike conventional cyber threats, APTs maintain a long-term, stealthy presence within networks,…

  • Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data

    Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data A critical Cross-Site Request Forgery (CSRF) vulnerability in Zimbra Collaboration Server (ZCS) versions 9.0 through 10.1, tracked as CVE-2025-32354, allows attackers to execute unauthorized GraphQL operations and access sensitive user data.  The flaw resides in Zimbra’s webmail interface’s GraphQL endpoint (/service/extension/graphql), where improper CSRF token validation…

  • Link11 brings three brands together on one platform with new branding

    Link11 brings three brands together on one platform with new branding Link11 has fully integrated DOSarrest and Reblaze to become one of Europe’s leading providers of network security, web application security, and application performance Link11, DOSarrest, and Reblaze have combined their strengths into a single, integrated platform with a new brand identity. The result: a…

  • PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition

    PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation.  The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8…

  • Docker Registry Vulnerability Lets MacOS Users Pull Images from Any Registry

    Docker Registry Vulnerability Lets MacOS Users Pull Images from Any Registry A newly disclosed vulnerability in Docker Desktop’s Registry Access Management (RAM) feature has left macOS users vulnerable to unauthorized image pulls, undermining critical container security controls.  Designated CVE-2025-4095, the flaw allows developers to bypass registry restrictions enforced by administrators, potentially exposing organizations to malicious…

  • Building Trust Through Transparency – CISO Cybersecurity Practices

    Building Trust Through Transparency – CISO Cybersecurity Practices In an era of digital transformation and rising cyber threats, Building Trust Through Transparency has become a critical mission for the Chief Information Security Officer (CISO), who has evolved from a technical expert to a strategic leader responsible for protecting organizational trust. Transparency in cybersecurity practices is…

  • XDR In Penetration Testing: Leveraging Advanced Detection To Find Vulnerabilities

    XDR In Penetration Testing: Leveraging Advanced Detection To Find Vulnerabilities Extended Detection and Response (XDR) has emerged as a transformative security technology that unifies visibility across multiple security layers. When applied to penetration testing methodologies, XDR offers unprecedented capabilities for identifying vulnerabilities that might otherwise remain hidden. This article explores how security professionals can leverage…

  • Social Engineering Awareness: How CISOs And SOC Heads Can Protect The Organization

    Social Engineering Awareness: How CISOs And SOC Heads Can Protect The Organization Social engineering has become the dominant attack vector in the modern cybersecurity landscape. As technical defenses evolve and strengthen, attackers have shifted their focus to the human element, exploiting psychological vulnerabilities to bypass even the most robust security systems. Studies indicate that social…

  • New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands

    New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands A sophisticated phishing campaign dubbed “Power Parasites” has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week. The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy,…

  • DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models

    DragonForce and Anubis Ransomware Operators Unveils New Affiliate Models Despite significant disruptions by international law enforcement operations targeting major ransomware schemes, cybercriminal groups continue demonstrating remarkable adaptability in 2025. Two noteworthy ransomware operations, DragonForce and Anubis, have introduced innovative affiliate models designed to expand their reach and increase profitability in the ever-evolving cybercrime landscape. DragonForce…

  • Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid

    Spring Security Vulnerability Let Attackers Determine Which Usernames are Valid A serious vulnerability related to information exposure (CVE-2025-22234) impacts several versions of the spring-security-crypto package. The flaw enables attackers to determine valid usernames through timing attacks, undermining a key security feature designed to prevent user enumeration.  The vulnerability affects Spring Security versions 5.7.16, 5.8.18, 6.0.16,…

  • Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations

    Russian VPS Servers With RDP, Proxy Servers Fuel North Korean Cybercrime Operations North Korea’s cybercrime operations have significantly expanded beyond the limited 1,024 IP addresses assigned to their national network through an elaborate scheme involving Russian infrastructure. According to recent findings, five Russian IP ranges, primarily located in the border towns of Khasan and Khabarovsk,…

  • New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy

    New Reports Reveals How AI is Boosting the Phishing Attack Rapidly With More Accuracy Cybercriminals have dramatically evolved their phishing tactics, leveraging generative AI to create highly personalized and convincing attacks, according to the newly released ThreatLabz 2025 Phishing Report. The days of mass phishing campaigns have given way to hyper-targeted scams designed to exploit…

  • North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers

    North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers A sophisticated North Korean advanced persistent threat (APT) group known as “Contagious Interview” has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware. The group, a subunit of the infamous North Korean state-sponsored Lazarus Group, has created three…

  • Microsoft’s Symlink Patch Created New Windows DoS Vulnerability

    Microsoft’s Symlink Patch Created New Windows DoS Vulnerability A recent Microsoft security update, intended to patch a critical privilege escalation vulnerability, has inadvertently introduced a new and significant flaw.  The fix now enables non-administrative users to effectively block all future Windows security updates, creating a denial-of-service condition.  This unintended consequence of the patch highlights the…

  • Blue Shield Leaked Health Info of 4.7M patients with Google Ads

    Blue Shield Leaked Health Info of 4.7M patients with Google Ads Blue Shield of California has disclosed a significant data breach affecting 4.7 million members, representing the majority of its nearly 6 million customers.  The health insurance provider revealed that protected health information (PHI) was inadvertently shared with Google’s advertising platforms over a nearly three-year…

  • SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances

    SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances SonicWall has disclosed a critical security vulnerability in its SSLVPN service that allows unauthenticated remote attackers to crash affected firewall appliances, potentially causing significant disruptions to enterprise networks.  The vulnerability, tracked as CVE-2025-32818, received a high severity CVSS score of 7.5 and affects numerous SonicWall firewall…

  • Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites

    Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites Phishing campaigns have evolved significantly in 2025, with threat actors increasingly leveraging unconventional file formats to bypass security solutions. A particularly concerning trend involves the weaponization of Scalable Vector Graphics (SVG) files, which are being embedded with malicious JavaScript code designed to redirect…

  • 1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities

    1000+ Unique IPs Attacking Ivanti Connect Secure Systems to Exploit Vulnerabilities A significant increase in suspicious scanning activity targeting Ivanti Connect Secure (ICS) and Ivanti Pulse Secure (IPS) VPN systems, signaling a potential coordinated reconnaissance effort by threat actors.  The spike, registering more than 230 unique IP addresses probing ICS/IPS endpoints in a single day,…

  • Microsoft to Offer Rewards Up to $30,000 for AI Vulnerabilities

    Microsoft to Offer Rewards Up to $30,000 for AI Vulnerabilities Microsoft has launched an expanded bug bounty program offering rewards of up to $30,000 for researchers who identify critical vulnerabilities in AI systems within its Dynamics 365 and Power Platform products.  The initiative, announced by Microsoft Security Response, aims to strengthen security in enterprise AI…

  • The Role of AI in Modernizing Cybersecurity Programs – Insights for Security Leaders

    The Role of AI in Modernizing Cybersecurity Programs – Insights for Security Leaders In the face of relentless cyber threats and an ever-expanding digital attack surface, security leaders are under growing pressure to modernize their cybersecurity programs by leveraging AI in cybersecurity to enhance detection, response, and overall resilience. Artificial Intelligence (AI) has rapidly emerged…

  • CISA Releases Five Advisories Covering ICS Vulnerabilities & Exploits

    CISA Releases Five Advisories Covering ICS Vulnerabilities & Exploits The Cybersecurity and Infrastructure Security Agency (CISA) has released five new advisories addressing critical vulnerabilities in Industrial Control Systems (ICS) from Siemens, Schneider Electric, and ABB.  These advisories, published on April 22, 2025, provide detailed information on security flaws, associated Common Vulnerabilities and Exposures (CVEs), and…

  • Zyxel Patches Privilege Management Vulnerabilities in USG FLEX H Series Firewalls

    Zyxel Patches Privilege Management Vulnerabilities in USG FLEX H Series Firewalls Zyxel Networks has released critical security patches to address two high-severity vulnerabilities in its USG FLEX H series firewalls that could potentially allow attackers to escalate privileges and gain unauthorized access to affected devices.  The security advisory, published on April 22, 2025, details the…

  • From Response to Resilience – Shifting the CISO Mindset in Times of Crisis

    From Response to Resilience – Shifting the CISO Mindset in Times of Crisis In an era where cyber threats evolve faster than defense mechanisms, Chief Information Security Officers (CISOs) must transition their leadership approach from response to resilience. The traditional focus on prevention and rapid response is no longer sufficient; resilience has emerged as the…

  • Hackers Attacking Organization With New Malware Mimic as Networking Software Updates

    Hackers Attacking Organization With New Malware Mimic as Networking Software Updates A sophisticated backdoor targeting various large Russian organizations across government, finance, and industrial sectors has been uncovered during a cybersecurity investigation in April 2025. The malware, which masquerades as legitimate updates for ViPNet secure networking software, enables attackers to steal sensitive data and deploy…

  • How To Prioritize Threat Intelligence Alerts In A High-Volume SOC

    How To Prioritize Threat Intelligence Alerts In A High-Volume SOC In today’s rapidly evolving cyber threat landscape, Security Operations Centers (SOCs) face an unprecedented challenge: efficiently managing and prioritizing the overwhelming volume of security alerts they receive daily. SOC analysts often can’t read and respond to a significant portion of the alerts they see every…

  • How to Implementing SOAR To Reduce Incident Response Time Effectively

    How to Implementing SOAR To Reduce Incident Response Time Effectively In the modern digital landscape, organizations are constantly challenged by an ever-increasing volume of security alerts, sophisticated cyber threats, and the ongoing shortage of skilled cybersecurity professionals. Security Orchestration, Automation, and Response (SOAR) platforms have emerged as a transformative solution to these challenges, enabling security…

  • Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities

    Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities Microsoft has warned organizations worldwide that threat actors are ramping up their exploitation of critical vulnerabilities in on-premises Exchange Server and SharePoint Server. These attacks, observed in recent months, have enabled cybercriminals to gain persistent and privileged access to targeted environments, leading to remote code execution,…

  • Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN

    Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN A server briefly linked to the notorious KeyPlug malware has inadvertently exposed a comprehensive arsenal of exploitation tools specifically designed to target Fortinet firewall and VPN appliances. The infrastructure, which security researchers have attributed to the RedGolf threat group (overlapping with APT41),…

  • Detecting And Responding To New Nation-State Persistence Techniques

    Detecting And Responding To New Nation-State Persistence Techniques Nation-state cyber threats have evolved dramatically over the past decade, with attackers employing increasingly sophisticated persistence techniques to maintain long-term access within targeted environments. These advanced persistent threats (APTs) are often orchestrated by government-backed groups with significant resources, making them particularly dangerous for critical infrastructure, government agencies,…

  • 100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure

    100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure A severe vulnerability in the popular WordPress plugin SureTriggers has been actively exploited within just four hours of its public disclosure on April 10, 2025.  The critical authentication bypass flaw affects all versions of the plugin up to 1.0.78, which has over 100,000…

  • Why Security Leaders Are Turning to AI for Threat Detection

    Why Security Leaders Are Turning to AI for Threat Detection In today’s rapidly evolving digital landscape, cybersecurity threats are becoming increasingly sophisticated and harder to detect using traditional methods. Security leaders across industries are recognizing artificial intelligence as a transformative force in strengthening defensive capabilities. This paradigm shift is prompting security leaders to integrate AI-powered…

  • Apache Roller Vulnerability Let Attackers Gain Unauthorized Access

    Apache Roller Vulnerability Let Attackers Gain Unauthorized Access A critical security vulnerability in Apache Roller has been discovered, allowing attackers to maintain unauthorized access to blog systems even after password changes.  The vulnerability, CVE-2025-24859, has received the highest possible CVSS v4 score of 10, indicating severe risk to affected systems. The security flaw stems from…

  • Why Every CISO Needs a Crisis Communications Plan in 2025

    Why Every CISO Needs a Crisis Communications Plan in 2025 In an era defined by escalating cyber threats and regulatory scrutiny, the role of the Chief Information Security Officer (CISO) has expanded far beyond technical oversight. By 2025, cyberattacks will not only test an organization’s technical defenses but also its ability to maintain stakeholder trust…

  • Google Groups File Attachment Restrictions Bypassed via Email Posting

    Google Groups File Attachment Restrictions Bypassed via Email Posting A significant security vulnerability has been identified in Google Groups, allowing users to circumvent file attachment restrictions by simply sending emails to group addresses.  This broken access control issue potentially impacts thousands of organizations that rely on Google Groups for controlled information sharing and collaboration. Ph.Hitachi…

  • Chinese Hackers Exploit Ivanti VPN Vulnerabilities to Infiltrate Organizations

    Chinese Hackers Exploit Ivanti VPN Vulnerabilities to Infiltrate Organizations A China-linked advanced persistent threat (APT) group has exploited critical vulnerabilities in Ivanti Connect Secure VPN appliances to infiltrate organizations across 12 countries and 20 industries, cybersecurity firm TeamT5 revealed in a report shared with Cyber Security News. The campaign, active since late March 2025, leverages…

  • Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data

    Threat Actors Weaponize Shell Techniques to Maintain Persistence and Exfiltrate Data Shells provide crucial command-line interfaces to operating systems. While legitimate for system administration tasks, when weaponized by threat actors, shells transform into dangerous avenues for unauthorized access, system control, and data theft across organizational networks. The misuse of these tools has become increasingly sophisticated,…

  • VMware ESXi 8.0 Update 3e Released for Free, What’s New!

    VMware ESXi 8.0 Update 3e Released for Free, What’s New! Broadcom has officially reintroduced the free version of VMware ESXi with the release of ESXi 8.0 Update 3e (Build 24674464) on April 10, 2025. This marks a significant policy reversal after Broadcom discontinued the free ESXi offering following its acquisition of VMware, a move that…

  • Hackers Allegedly Leaked 1.59 Million Rows of Indian Insurance User’s Sensitive Data

    Hackers Allegedly Leaked 1.59 Million Rows of Indian Insurance User’s Sensitive Data Hackers allegedly claim that a software company based in India was compromised on December 19, 2024, by a hacker identified as @303. The breach exposed approximately 1,590,798 rows of sensitive data, including customer information and administrative credentials. The dataset, initially leaked on the…

  • Cybersecurity Leadership in Crisis? CISO Resignations Spike After Major Breaches

    Cybersecurity Leadership in Crisis? CISO Resignations Spike After Major Breaches The cybersecurity landscape is witnessing an alarming trend, Chief Information Security Officers (CISOs) are leaving their positions at unprecedented rates. Nearly half of CISOs globally are expected to change jobs by 2025, with a significant portion quitting entirely due to work-related stress. This exodus comes…

  • Beware Developers! Malicious NPM Packages Targeting PayPal Users to Steal Sensitive Data

    Beware Developers! Malicious NPM Packages Targeting PayPal Users to Steal Sensitive Data FortiGuard Labs, Fortinet’s AI-driven threat intelligence arm, has uncovered a series of malicious NPM packages designed to steal sensitive information from developers and target PayPal users. Detected between March 5 and March 14, 2025, these packages were published by a threat actor using…

  • RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals

    RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025. This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging…

  • NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data

    NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data A critical vulnerability in NVIDIA’s Container Toolkit, CVE-2024-0132, remains exploitable due to an incomplete patch, endangering AI infrastructure and sensitive data. Coupled with a newly discovered denial-of-service (DoS) flaw in Docker on Linux, these issues could allow attackers to breach systems, steal proprietary…

  • Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies

    Sapphire Werewolf Enhances Toolkit With New Amethyst Stealer to Attack Energy Companies Cybersecurity experts have detected a sophisticated campaign targeting energy sector companies, as the threat actor known as Sapphire Werewolf deploys an enhanced version of the Amethyst stealer malware. The campaign represents a significant evolution in the group’s capabilities, featuring advanced evasion techniques and…

  • Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows

    Google Unveils A2A Protocol That Enable AI Agents Collaborate to Automate Workflows Google has announced the launch of Agent2Agent Protocol (A2A), a groundbreaking open protocol designed to enable AI agents to communicate with each other, securely exchange information, and coordinate actions across enterprise platforms. Revealed on April 9, 2025, the protocol marks a significant advancement…

  • Critical pgAdmin Vulnerability Let Attackers Execute Remote Code

    Critical pgAdmin Vulnerability Let Attackers Execute Remote Code A critical security vulnerability discovered in pgAdmin 4, the most widely used management tool for PostgreSQL databases, is allowing attackers to execute arbitrary code on affected systems.  Security researchers have disclosed details of CVE-2025-2945, a severe Remote Code Execution (RCE) vulnerability with a CVSS score of 9.9,…

  • CISA Releases NICE Workforce Framework Version 2.0.0 Released – What’s New

    CISA Releases NICE Workforce Framework Version 2.0.0 Released – What’s New The US Cybersecurity and Infrastructure Security Agency (CISA) has officially released Version 2.0.0 of the NICE Workforce Framework for Cybersecurity, marking a significant update to this nationally focused resource.  Released on March 5, 2025, this major update introduces substantial changes aimed at enhancing the…

  • Bitdefender GravityZone Console PHP Vulnerability Let Attackers Execute Arbitrary Commands

    Bitdefender GravityZone Console PHP Vulnerability Let Attackers Execute Arbitrary Commands A critical security vulnerability has been discovered in Bitdefender GravityZone Console that could allow remote attackers to execute arbitrary commands on affected systems.  The flaw tracked as CVE-2025-2244 has a CVSS score of 9.5. It stems from an insecure PHP deserialization issue that poses significant…

  • Top 10 Programming Languages For Cyber Security – 2025

    Top 10 Programming Languages For Cyber Security – 2025 Communication is the key in all areas, and the cyber world is no different. To communicate in the cyber world, you must learn the language used here: programming languages. This will help you command the machines to act according to you.  In cybersecurity, programming languages allow…

  • 10 Best Kubernetes Container Scanners In 2025

    10 Best Kubernetes Container Scanners In 2025 Kubernetes container scanners are essential tools for ensuring the security of containerized applications and Kubernetes clusters. These scanners analyze vulnerabilities, misconfigurations, and compliance issues within container images, Kubernetes manifests, and runtime environments. Popular tools like Kube Bench focus on compliance by auditing Kubernetes clusters against CIS benchmarks, while…

  • 10 Best Ransomware File Decryptor Tools – 2025

    10 Best Ransomware File Decryptor Tools – 2025 Ransomware file decryptor tools are essential for recovering data encrypted by malicious software without paying ransoms. These tools help victims regain access to their files by using decryption keys or algorithms to unlock the encrypted data. The No More Ransom project is a collaborative effort that offers…

  • Microsoft Strengthens Outlook’s Email Ecosystem to Protect Inboxes

    Microsoft Strengthens Outlook’s Email Ecosystem to Protect Inboxes Microsoft Outlook will enforce stricter authentication requirements for high-volume senders, impacting domains that send over 5,000 emails daily. These changes, which will take effect on May 5, 2025, aim to enhance inbox protection and maintain trust in digital communication. Outlook’s updated policy will mandate compliance with SPF…

  • “Clipboard Hijacking” A Fake CAPTCHA Leverage Pastejacking Script Via Hacked Sites To Steal Clipboard Data

    “Clipboard Hijacking” A Fake CAPTCHA Leverage Pastejacking Script Via Hacked Sites To Steal Clipboard Data A sophisticated new cyberattack chain dubbed “KongTuke” has been uncovered by cybersecurity researchers, targeting unsuspecting internet users through compromised legitimate websites. Detailed in a report by Bradley Duncan of Palo Alto Networks’ Unit 42 team, this attack leverages malicious scripts…

  • “IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control

    “IngressNightmare” Critical RCE Vulnerabilities in Kubernetes NGINX Clusters Let Attackers Gain Full Control A recently discovered set of vulnerabilities, dubbed “IngressNightmare,” found in Ingress NGINX Controller, exposing clusters to unauthenticated remote code execution (RCE). Kubernetes dominates container orchestration, but its prominence has made it a target for exploitation. In Kubernetes, Ingress serves as a sophisticated…

  • Sec-Gemini v1 – Google Released a New AI Model for Cybersecurity

    Sec-Gemini v1 – Google Released a New AI Model for Cybersecurity Google has made a big move to fight cyber threats by announcing Sec-Gemini v1, an experimental AI model designed to revolutionize cybersecurity. Elie Burzstein and Marianna Tishchenko from the Sec-Gemini team unveiled a new AI model designed to help cybersecurity defenders tackle the growing…

  • CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog

    CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-22457, a critical vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, to its Known Exploited Vulnerabilities (KEV) Catalog. This stack-based buffer overflow, actively exploited since mid-March 2025, allows remote unauthenticated attackers…

  • Microsoft Celebrates 50th Anniversary!

    Microsoft Celebrates 50th Anniversary! Microsoft celebrated its 50th anniversary on April 4, 2025, reflecting on its journey since Bill Gates and Paul Allen founded the company in 1975. The milestone event, held at Microsoft’s Redmond, Washington headquarters, blended nostalgia with cutting-edge AI advancements, particularly through its Copilot platform, while highlighting the transformative role of technology…

  • Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild – Apply Patch Now!

    Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild – Apply Patch Now! Ivanti has disclosed a critical vulnerability, CVE-2025-22457, affecting its Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways products that are actively exploited in the wild. This stack-based buffer overflow flaw, with a CVSS score of 9.0, has been…