FireScam Android Malware Poses as Telegram Premium to Steal Data and Control Devices

06/01/2025 0 Comments 0 tags

An Android information stealing malware named FireScam has been found masquerading as a premium version of the Telegram messaging app to steal data and maintain persistent remote control over compromised

From $22M in Ransom to +100M Stolen Records: 2025’s All-Star SaaS Threat Actors to Watch

06/01/2025 0 Comments 0 tags

In 2024, cyber threats targeting SaaS surged, with 7,000 password attacks blocked per second (just in Entra ID)—a 75% increase from last year—and phishing attempts up by 58%, causing $3.5

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]

06/01/2025 0 Comments 0 tags

Every tap, click, and swipe we make online shapes our digital lives, but it also opens doors—some we never meant to unlock. Extensions we trust, assistants we rely on, and

India Proposes Digital Data Rules with Tough Penalties and Cybersecurity Requirements

06/01/2025 0 Comments 0 tags

The Indian government has published a draft version of the Digital Personal Data Protection (DPDP) Rules for public consultation. “Data fiduciaries must provide clear and accessible information about how personal

Russian-Speaking Attackers Target Ethereum Devs with Fake Hardhat npm Packages

06/01/2025 0 Comments 0 tags

Cybersecurity researchers have revealed several malicious packages on the npm registry that have been found impersonating the Nomic Foundation’s Hardhat tool in order to steal sensitive data from developer systems.

Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution

04/01/2025 0 Comments 0 tags

A high-severity security flaw has been disclosed in ProjectDiscovery’s Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass signature checks and potentially execute malicious

U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns

04/01/2025 0 Comments 0 tags

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday issued sanctions against a Beijing-based cybersecurity company known as Integrity Technology Group, Incorporated for orchestrating several cyber attacks

PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN Apps

04/01/2025 0 Comments 0 tags

Cybersecurity researchers have flagged a new malware called PLAYFULGHOST that comes with a wide range of information-gathering features like keylogging, screen capture, audio capture, remote shell, and file transfer/execution. The

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

03/01/2025 0 Comments 0 tags

Microsoft has announced that it’s making an “unexpected change” to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure. “We expect that

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

03/01/2025 0 Comments 0 tags

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS) condition. The out-of-bounds reads vulnerability