North Korea’s ScarCruft Deploys KoSpy Malware, Spying on Android Users via Fake Utility Apps

13/03/2025 0 Comments 0 tags

The North Korea-linked threat actor known as ScarCruft is said to have been behind a never-before-seen Android surveillance tool named KoSpy targeting Korean and English-speaking users. Lookout, which shared details

WARNING: Expiring Root Certificate May Disable Firefox Add-Ons, Security Features, and DRM Playback

13/03/2025 0 Comments 0 tags

Browser maker Mozilla is urging users to update their Firefox instances to the latest version to avoid facing issues with using add-ons due to the impending expiration of a root

Meta Warns of FreeType Vulnerability (CVE-2025-27363) With Active Exploitation Risk

13/03/2025 0 Comments 0 tags

Meta has warned that a security vulnerability impacting the FreeType open-source font rendering library may have been exploited in the wild. The vulnerability has been assigned the CVE identifier CVE-2025-27363,

Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and Rootkits

12/03/2025 0 Comments 0 tags

The China-nexus cyber espionage group tracked as UNC3886 has been observed targeting end-of-life MX routers from Juniper Networks as part of a campaign designed to deploy custom backdoors, highlighting their

Pentesters: Is AI Coming for Your Role?

12/03/2025 0 Comments 0 tags

We’ve been hearing the same story for years: AI is coming for your job. In fact, in 2017, McKinsey printed a report, Jobs Lost, Jobs Gained: Workforce Transitions in a

Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

12/03/2025 0 Comments 0 tags

Threat intelligence firm GreyNoise is warning of a “coordinated surge” in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities spanning multiple platforms. “At least 400 IPs have been seen actively

URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days

12/03/2025 0 Comments 0 tags

Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild. Of

Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks

12/03/2025 0 Comments 0 tags

Apple on Tuesday released a security update to address a zero-day flaw that it said has been exploited in “extremely sophisticated” attacks. The vulnerability has been assigned the CVE identifier

Blind Eagle Hacks Colombian Institutions Using NTLM Flaw, RATs and GitHub-Based Attacks

11/03/2025 0 Comments 0 tags

The threat actor known as Blind Eagle has been linked to a series of ongoing campaigns targeting Colombian institutions and government entities since November 2024. “The monitored campaigns targeted Colombian

Your Risk Scores Are Lying: Adversarial Exposure Validation Exposes Real Threats

11/03/2025 0 Comments 0 tags

In cybersecurity, confidence is a double-edged sword. Organizations often operate under a false sense of security, believing that patched vulnerabilities, up-to-date tools, polished dashboards, and glowing risk scores guarantee safety.