Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack

03/06/2025 0 Comments 0 tags

Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting users into executing malicious PowerShell scripts on their machines and infect them with the NetSupport

Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious Code

03/06/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a critical security flaw in the Roundcube webmail software that has gone unnoticed for a decade and could be exploited to take over susceptible

Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization

03/06/2025 0 Comments 0 tags

In the wake of high-profile attacks on UK retailers Marks & Spencer and Co-op, Scattered Spider has been all over the media, with coverage spilling over into the mainstream news

Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

03/06/2025 0 Comments 0 tags

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America. The malware, according to a new

Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues

03/06/2025 0 Comments 0 tags

Google has revealed that it will no longer trust digital certificates issued by Chunghwa Telecom and Netlock citing “patterns of concerning behavior observed over the past year.” The changes are

Microsoft and CrowdStrike Launch Shared Threat Actor Glossary to Cut Attribution Confusion

03/06/2025 0 Comments 0 tags

Microsoft and CrowdStrike have announced that they are teaming up to align their individual threat actor taxonomies by publishing a new joint threat actor mapping. “By mapping where our knowledge

New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch

03/06/2025 0 Comments 0 tags

Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild. The high-severity

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

02/06/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a new cryptojacking campaign that’s targeting publicly accessible DevOps web servers such as those associated with Docker, Gitea, and HashiCorp Consul and Nomad to illicitly mine

Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN

02/06/2025 0 Comments 0 tags

Three security vulnerabilities have been disclosed in preloaded Android applications on smartphones from Ulefone and Krüger&Matz that could enable any app installed on the device to perform a factory reset

Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU

02/06/2025 0 Comments 0 tags

Qualcomm has shipped security updates to address three zero-day vulnerabilities that it said have been exploited in limited, targeted attacks in the wild. The flaws in question, which were responsibly