Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days

10/12/2025 0 Comments 0 tags

Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild. Of the

Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws

10/12/2025 0 Comments 0 tags

Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could result in an authentication bypass and code execution. The Fortinet vulnerabilities

North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware

09/12/2025 0 Comments 0 tags

Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical security React2Shell flaw in React Server Components (RSC) to deliver a previously

Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure

09/12/2025 0 Comments 0 tags

Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

09/12/2025 0 Comments 0 tags

The threat actor known as Storm-0249 is likely shifting from its role as an initial access broker to adopt a combination of more advanced tactics like domain spoofing, DLL side-loading,

Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats

09/12/2025 0 Comments 0 tags

Google on Monday announced a set of new security features in Chrome, following the company’s addition of agentic artificial intelligence (AI) capabilities to the web browser. To that end, the

How to Streamline Zero Trust Using the Shared Signals Framework

09/12/2025 0 Comments 0 tags

Zero Trust helps organizations shrink their attack surface and respond to threats faster, but many still struggle to implement it because their security tools don’t share signals reliably. 88% of

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

09/12/2025 0 Comments 0 tags

Canadian organizations have emerged as the focus of a targeted cyber campaign orchestrated by a threat activity cluster known as STAC6565. Cybersecurity company Sophos said it investigated almost 40 intrusions

Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data

09/12/2025 0 Comments 0 tags

Cybersecurity researchers have discovered two new extensions on Microsoft Visual Studio Code (VS Code) Marketplace that are designed to infect developer machines with stealer malware. The VS Code extensions masquerade

Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT

08/12/2025 0 Comments 0 tags

Cybersecurity researchers are calling attention to a new campaign dubbed JS#SMUGGLER that has been observed leveraging compromised websites as a distribution vector for a remote access trojan named NetSupport RAT.