Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild

02/12/2025 0 Comments 0 tags

Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild. The patch addresses a total of

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

01/12/2025 0 Comments 0 tags

A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time. Five of these extensions started off

India Orders Phone Makers to Pre-Install Sanchar Saathi App to Tackle Telecom Fraud

01/12/2025 0 Comments 0 tags

India’s telecommunications ministry has reportedly asked major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report

⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More

01/12/2025 0 Comments 0 tags

Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and

Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams

01/12/2025 0 Comments 0 tags

The AI browser wars are coming to a desktop near you, and you need to start worrying about their security challenges. For the last two decades, whether you used Chrome,

New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control

01/12/2025 0 Comments 0 tags

A new Android malware named Albiriox has been advertised under a malware-as-a-service (MaaS) model to offer a “full spectrum” of features to facilitate on-device fraud (ODF), screen manipulation, and real-time

Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets

01/12/2025 0 Comments 0 tags

The threat actor known as Tomiris has been attributed to attacks targeting foreign ministries, intergovernmental organizations, and government entities in Russia with an aim to establish remote access and deploy

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

30/11/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation. The

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

28/11/2025 0 Comments 0 tags

Cybersecurity researchers have discovered vulnerable code in legacy Python packages that could potentially pave the way for a supply chain compromise on the Python Package Index (PyPI) via a domain

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware

28/11/2025 0 Comments 0 tags

The North Korean threat actors behind the Contagious Interview campaign have continued to flood the npm registry with 197 more malicious packages since last month. According to Socket, these packages