XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities

07/10/2025 0 Comments 0 tags

Cybersecurity researchers have charted the evolution of XWorm malware, turning it into a versatile tool for supporting a wide range of malicious actions on compromised hosts. “XWorm’s modular design is

13-Year Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

07/10/2025 0 Comments 0 tags

Redis has disclosed details of a maximum-severity security flaw in its in-memory database software that could result in remote code execution under certain circumstances. The vulnerability, tracked as CVE-2025-49844 (aka

Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware

07/10/2025 0 Comments 0 tags

Microsoft on Monday attributed a threat actor it tracks as Storm-1175 to the exploitation of a critical security flaw in Fortra GoAnywhere software to facilitate the deployment of Medusa ransomware.

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks

07/10/2025 0 Comments 0 tags

CrowdStrike on Monday said it’s attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a threat actor it tracks as Graceful Spider

New Report Links Research Firms BIETA and CIII to China’s MSS Cyber Operations

06/10/2025 0 Comments 0 tags

A Chinese company named the Beijing Institute of Electronics Technology and Application (BIETA) has been assessed to be likely led by the Ministry of State Security (MSS). The assessment comes

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

06/10/2025 0 Comments 0 tags

The cyber world never hits pause, and staying alert matters more than ever. Every week brings new tricks, smarter attacks, and fresh lessons from the field. This recap cuts through

5 Critical Questions For Adopting an AI Security Solution

06/10/2025 0 Comments 0 tags

In the era of rapidly advancing artificial intelligence (AI) and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AI-SPM

Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers

06/10/2025 0 Comments 0 tags

Cybersecurity researchers have shed light on a Chinese-speaking cybercrime group codenamed UAT-8099 that has been attributed to search engine optimization (SEO) fraud and theft of high-value credentials, configuration files, and

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

06/10/2025 0 Comments 0 tags

A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military. Tracked as CVE-2025-27915 (CVSS score: 5.4), the

Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks

06/10/2025 0 Comments 0 tags

Oracle has released an emergency update to address a critical security flaw in its E-Business Suite that it said has been exploited in the recent wave of Cl0p data theft