Your Risk Scores Are Lying: Adversarial Exposure Validation Exposes Real Threats

11/03/2025 0 Comments 0 tags

In cybersecurity, confidence is a double-edged sword. Organizations often operate under a false sense of security, believing that patched vulnerabilities, up-to-date tools, polished dashboards, and glowing risk scores guarantee safety.

Ballista Botnet Exploits Unpatched TP-Link Vulnerability, Infects Over 6,000 Devices

11/03/2025 0 Comments 0 tags

Unpatched TP-Link Archer routers have become the target of a new botnet campaign dubbed Ballista, according to new findings from the Cato CTRL team. “The botnet exploits a remote code

Steganography Explained: How XWorm Hides Inside Images

11/03/2025 0 Comments 0 tags

Inside the most innocent-looking image, a breathtaking landscape, or a funny meme, something dangerous could be hiding, waiting for its moment to strike. No strange file names. No antivirus warnings.

Moxa Issues Fix for Critical Authentication Bypass Vulnerability in PT Switches

11/03/2025 0 Comments 0 tags

Taiwanese company Moxa has released a security update to address a critical security flaw impacting its PT switches that could permit an attacker to bypass authentication guarantees. The vulnerability, tracked

SideWinder APT Targets Maritime, Nuclear, and IT Sectors Across Asia, Middle East, and Africa

11/03/2025 0 Comments 0 tags

Maritime and logistics companies in South and Southeast Asia, the Middle East, and Africa have become the target of an advanced persistent threat (APT) group dubbed SideWinder. The attacks, observed

CISA Adds Five Actively Exploited Vulnerabilities in Advantive VeraCore and Ivanti EPM to KEV List

11/03/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting Advantive VeraCore and Ivanti Endpoint Manager (EPM) to its Known Exploited Vulnerabilities (KEV) catalog, based

Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials

10/03/2025 0 Comments 0 tags

Cybersecurity researchers have demonstrated a novel technique that allows a malicious web browser extension to impersonate any installed add-on. “The polymorphic extensions create a pixel perfect replica of the target’s

Desert Dexter Targets 900 Victims Using Facebook Ads and Telegram Malware Links

10/03/2025 0 Comments 0 tags

The Middle East and North Africa have become the target of a new campaign that delivers a modified version of a known malware called AsyncRAT since September 2024. “The campaign,

Why The Modern Google Workspace Needs Unified Security

10/03/2025 0 Comments 0 tags

The Need For Unified Security Google Workspace is where teams collaborate, share ideas, and get work done. But while it makes work easier, it also creates new security challenges. Cybercriminals

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

10/03/2025 0 Comments 0 tags

Cyber threats today don’t just evolve—they mutate rapidly, testing the resilience of everything from global financial systems to critical infrastructure. As cybersecurity confronts new battlegrounds—ranging from nation-state espionage and ransomware