BaitTrap: Over 17,000 Fake News Websites Caught Fueling Investment Fraud Globally

08/07/2025 0 Comments 0 tags

A newly released report by cybersecurity firm CTM360 reveals a large-scale scam operation utilizing fake news websites—known as Baiting News Sites (BNS)—to deceive users into online investment fraud across 50

Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms

08/07/2025 0 Comments 0 tags

Russian organizations have been targeted as part of an ongoing campaign that delivers a previously undocumented Windows spyware called Batavia. The activity, per cybersecurity vendor Kaspersky, has been active since

CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation

08/07/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The

SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools

07/07/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed a malicious campaign that leverages search engine optimization (SEO) poisoning techniques to deliver a known malware loader called Oyster (aka Broomstick or CleanUpLoader). The malvertising activity,

⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and More

07/07/2025 0 Comments 0 tags

Everything feels secure—until one small thing slips through. Even strong systems can break if a simple check is missed or a trusted tool is misused. Most threats don’t start with

Manufacturing Security: Why Default Passwords Must Go

07/07/2025 0 Comments 0 tags

If you didn’t hear about Iranian hackers breaching US water facilities, it’s because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn’t

TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors

07/07/2025 0 Comments 0 tags

A hacking group with ties other than Pakistan has been found targeting Indian government organizations with a modified variant of a remote access trojan (RAT) called DRAT. The activity has

Taiwan NSB Alerts Public on Data Risks from TikTok, Weibo, and RedNote Over China Ties

05/07/2025 0 Comments 0 tags

Taiwan’s National Security Bureau (NSB) has warned that China-developed applications like RedNote (aka Xiaohongshu), Weibo, TikTok, WeChat, and Baidu Cloud pose security risks due to excessive data collection and data

Alert: Exposed JDWP Interfaces Lead to Crypto Mining, Hpingbot Targets SSH for DDoS

05/07/2025 0 Comments 0 tags

Threat actors are weaponizing exposed Java Debug Wire Protocol (JDWP) interfaces to obtain code execution capabilities and deploy cryptocurrency miners on compromised hosts. “The attacker used a modified version of

NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors

04/07/2025 0 Comments 0 tags

Cybersecurity researchers have shed light on a previously undocumented threat actor called NightEagle (aka APT-Q-95) that has been observed targeting Microsoft Exchange servers as a part of a zero-day exploit