Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra

27/08/2025 0 Comments 0 tags

Cybersecurity researchers have discovered five distinct activity clusters linked to a persistent threat actor known as Blind Eagle between May 2024 and July 2025. These attacks, observed by Recorded Future

Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data

27/08/2025 0 Comments 0 tags

A widespread data theft campaign has allowed hackers to breach sales automation platform Salesloft to steal OAuth and refresh tokens associated with the Drift artificial intelligence (AI) chat agent. The

Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775

26/08/2025 0 Comments 0 tags

Citrix has released fixes to address three security flaws in NetScaler ADC and NetScaler Gateway, including one that it said has been actively exploited in the wild. The vulnerabilities in

New Sni5Gect Attack Crashes Phones and Downgrades 5G to 4G without Rogue Base Station

26/08/2025 0 Comments 0 tags

A team of academics has devised a novel attack that can be used to downgrade a 5G connection to a lower generation without relying on a rogue base station (gNB).

MixShell Malware Delivered via Contact Forms Targets U.S. Supply Chain Manufacturers

26/08/2025 0 Comments 0 tags

Cybersecurity researchers are calling attention to a sophisticated social engineering campaign that’s targeting supply chain-critical manufacturing companies with an in-memory malware dubbed MixShell. The activity has been codenamed ZipLine by

ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners

26/08/2025 0 Comments 0 tags

A new large-scale campaign has been observed exploiting over 100 compromised WordPress sites to direct site visitors to fake CAPTCHA verification pages that employ the ClickFix social engineering tactic to

HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands

26/08/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a new variant of an Android banking trojan called HOOK that features ransomware-style overlay screens to display extortion messages. “A prominent characteristic of the latest variant

Google to Verify All Android Developers in 4 Countries to Block Malicious Apps

26/08/2025 0 Comments 0 tags

Google has announced plans to begin verifying the identity of all developers who distribute apps on Android, even for those who distribute their software outside the Play Store. “Android will

CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git

26/08/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws impacting Citrix Session Recording and Git to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence

Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3

25/08/2025 0 Comments 0 tags

Docker has released fixes to address a critical security flaw affecting the Docker Desktop app for Windows and macOS that could potentially allow an attacker to break out of the