Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets

01/12/2025 0 Comments 0 tags

The threat actor known as Tomiris has been attributed to attacks targeting foreign ministries, intergovernmental organizations, and government entities in Russia with an aim to establish remote access and deploy

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

30/11/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation. The

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

28/11/2025 0 Comments 0 tags

Cybersecurity researchers have discovered vulnerable code in legacy Python packages that could potentially pave the way for a supply chain compromise on the Python Package Index (PyPI) via a domain

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware

28/11/2025 0 Comments 0 tags

The North Korean threat actors behind the Contagious Interview campaign have continued to flood the npm registry with 197 more malicious packages since last month. According to Socket, these packages

Why Organizations Are Turning to RPAM

28/11/2025 0 Comments 0 tags

As IT environments become increasingly distributed and organizations adopt hybrid and remote work at scale, traditional perimeter-based security models and on-premises Privileged Access Management (PAM) solutions no longer suffice. IT

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

28/11/2025 0 Comments 0 tags

Cybersecurity researchers have shed light on a cross-tenant blind spot that allows attackers to bypass Microsoft Defender for Office 365 protections via the guest access feature in Teams. “When users

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan

27/11/2025 0 Comments 0 tags

The threat actor known as Bloody Wolf has been attributed to a cyber attack campaign that has targeted Kyrgyzstan since at least June 2025 with the goal of delivering NetSupport

Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update

27/11/2025 0 Comments 0 tags

Microsoft has announced plans to improve the security of Entra ID authentication by blocking unauthorized script injection attacks starting a year from now. The update to its Content Security Policy

ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories

27/11/2025 0 Comments 0 tags

Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals

Gainsight Expands Impacted Customer List Following Salesforce Security Alert

27/11/2025 0 Comments 0 tags

Gainsight has disclosed that the recent suspicious activity targeting its applications has affected more customers than previously thought. The company said Salesforce initially provided a list of 3 impacted customers