CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active Exploitation

03/09/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity security flaw impacting TP-Link TL-WA855RE Wi-Fi Ranger Extender products to its Known Exploited Vulnerabilities (KEV) catalog, citing

Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

03/09/2025 0 Comments 0 tags

Salesloft on Tuesday announced that it’s taking Drift temporarily offline “in the very near future,” as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

02/09/2025 0 Comments 0 tags

The North Korea-linked threat actor known as the Lazarus Group has been attributed to a social engineering campaign that distributes three different pieces of cross-platform malware called PondRAT, ThemeForestRAT, and

Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control

02/09/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed a stealthy new backdoor called MystRodX that comes with a variety of features to capture sensitive data from compromised systems. “MystRodX is a typical backdoor implemented

Shadow AI Discovery: A Critical Part of Enterprise AI Governance

02/09/2025 0 Comments 0 tags

The Harsh Truths of AI Adoption MITs State of AI in Business report revealed that while 40% of organizations have purchased enterprise LLM subscriptions, over 90% of employees are actively

Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices

02/09/2025 0 Comments 0 tags

Cybersecurity researchers have flagged a Ukrainian IP network for engaging in massive brute-force and password spraying campaigns targeting SSL VPN and RDP devices between June and July 2025. The activity

Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT Malware

02/09/2025 0 Comments 0 tags

The threat actor known as Silver Fox has been attributed to abuse of a previously unknown vulnerable driver associated with WatchDog Anti-malware as part of a Bring Your Own Vulnerable

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

02/09/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious npm package that comes with stealthy features to inject malicious code into desktop apps for cryptocurrency wallets like Atomic and Exodus on Windows systems.

Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans

01/09/2025 0 Comments 0 tags

Cybersecurity researchers are calling attention to a new shift in the Android malware landscape where dropper apps, which are typically used to deliver banking trojans, to also distribute simpler malware

⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More

01/09/2025 0 Comments 0 tags

Cybersecurity today is less about single attacks and more about chains of small weaknesses that connect into big risks. One overlooked update, one misused account, or one hidden tool in