RaccoonO365 Phishing Network Shut Down After Microsoft and Cloudflare Disrupt 338 Domains

17/09/2025 0 Comments 0 tags

Microsoft’s Digital Crimes Unit said it teamed up with Cloudflare to coordinate the seizure of 338 domains used by RaccoonO365, a financially motivated threat group that was behind a phishing-as-a-service

Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover

16/09/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed multiple critical security vulnerabilities in Chaos Mesh that, if successfully exploited, could lead to cluster takeover in Kubernetes environments. “Attackers need only minimal in-cluster network access

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids

16/09/2025 0 Comments 0 tags

A massive ad fraud and click fraud operation dubbed SlopAds ran a cluster of 224 apps, collectively attracting 38 million downloads across 228 countries and territories. “These apps deliver their

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site

16/09/2025 0 Comments 0 tags

Cybersecurity researchers have warned of a new campaign that’s leveraging a variant of the FileFix social engineering tactic to deliver the StealC information stealer malware. “The observed campaign uses a

Securing the Agentic Era: Introducing Astrix’s AI Agent Control Plane

16/09/2025 0 Comments 0 tags

AI agents are rapidly becoming a core part of the enterprise, being embedded across enterprise workflows, operating with autonomy, and making decisions about which systems to access and how to

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

16/09/2025 0 Comments 0 tags

Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild. The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds

Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds

16/09/2025 0 Comments 0 tags

A team of academics from ETH Zürich and Google has discovered a new variant of a RowHammer attack targeting Double Data Rate 5 (DDR5) memory chips from South Korean semiconductor

40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials

16/09/2025 0 Comments 0 tags

Cybersecurity researchers have flagged a fresh software supply chain attack targeting the npm registry that has affected more than 40 packages that belong to multiple maintainers. “The compromised versions include

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

15/09/2025 0 Comments 0 tags

The China-aligned threat actor known as Mustang Panda has been observed using an updated version of a backdoor called TONESHELL and a previously undocumented USB worm called SnakeDisk. “The worm

⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

15/09/2025 0 Comments 0 tags

In a world where threats are persistent, the modern CISO’s real job isn’t just to secure technology—it’s to preserve institutional trust and ensure business continuity. This week, we saw a