CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download

18/04/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation

Experts Uncover New XorDDoS Controller, Infrastructure as Malware Expands to Docker, Linux, IoT

18/04/2025 0 Comments 0 tags

Cybersecurity researchers are warning of continued risks posed by a distributed denial-of-service (DDoS) malware known as XorDDoS, with 71.3 percent of the attacks between November 2023 and February 2025 targeting

Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates

17/04/2025 0 Comments 0 tags

The China-linked threat actor known as Mustang Panda has been attributed to a cyber attack targeting an unspecified organization in Myanmar with previously unreported tooling, highlighting continued effort by the

Artificial Intelligence – What’s all the fuss?

17/04/2025 0 Comments 0 tags

Talking about AI: Definitions Artificial Intelligence (AI) — AI refers to the simulation of human intelligence in machines, enabling them to perform tasks that typically require human intelligence, such as

State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns

17/04/2025 0 Comments 0 tags

Multiple state-sponsored hacking groups from Iran, North Korea, and Russia have been found leveraging the increasingly popular ClickFix social engineering tactic to deploy malware over a three-month period from late

Blockchain Offers Security Benefits – But Don’t Neglect Your Passwords

17/04/2025 0 Comments 0 tags

Blockchain is best known for its use in cryptocurrencies like Bitcoin, but it also holds significant applications for online authentication. As businesses in varying sectors increasingly embrace blockchain-based security tools,

Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers

17/04/2025 0 Comments 0 tags

Microsoft is calling attention to an ongoing malvertising campaign that makes use of Node.js to deliver malicious payloads capable of information theft and data exfiltration. The activity, first detected in

Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution

17/04/2025 0 Comments 0 tags

A critical security vulnerability has been disclosed in the Erlang/Open Telecom Platform (OTP) SSH implementation that could permit an attacker to execute arbitrary code sans any authentication under certain conditions.

CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices

17/04/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security flaw impacting SonicWall Secure Mobile Access (SMA) 100 Series gateways to its Known Exploited Vulnerabilities (KEV) catalog,

Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks

17/04/2025 0 Comments 0 tags

Apple on Wednesday released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two security flaws that it said have come under active exploitation in the wild.