MixShell Malware Delivered via Contact Forms Targets U.S. Supply Chain Manufacturers

26/08/2025 0 Comments 0 tags

Cybersecurity researchers are calling attention to a sophisticated social engineering campaign that’s targeting supply chain-critical manufacturing companies with an in-memory malware dubbed MixShell. The activity has been codenamed ZipLine by

ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners

26/08/2025 0 Comments 0 tags

A new large-scale campaign has been observed exploiting over 100 compromised WordPress sites to direct site visitors to fake CAPTCHA verification pages that employ the ClickFix social engineering tactic to

HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands

26/08/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a new variant of an Android banking trojan called HOOK that features ransomware-style overlay screens to display extortion messages. “A prominent characteristic of the latest variant

CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git

26/08/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws impacting Citrix Session Recording and Git to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence

Google to Verify All Android Developers in 4 Countries to Block Malicious Apps

26/08/2025 0 Comments 0 tags

Google has announced plans to begin verifying the identity of all developers who distribute apps on Android, even for those who distribute their software outside the Play Store. “Android will

Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3

25/08/2025 0 Comments 0 tags

Docker has released fixes to address a critical security flaw affecting the Docker Desktop app for Windows and macOS that could potentially allow an attacker to break out of the

UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats

25/08/2025 0 Comments 0 tags

A China-nexus threat actor known as UNC6384 has been attributed to a set of attacks targeting diplomats in Southeast Asia and other entities across the globe to advance Beijing’s strategic

Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads

25/08/2025 0 Comments 0 tags

Cybersecurity researchers have flagged a new phishing campaign that’s using fake voicemails and purchase orders to deliver a malware loader called UpCrypter. The campaign leverages “carefully crafted emails to deliver

⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-the-Wild Exploits & More

25/08/2025 0 Comments 0 tags

Cybersecurity today moves at the pace of global politics. A single breach can ripple across supply chains, turn a software flaw into leverage, or shift who holds the upper hand.

Why SIEM Rules Fail and How to Fix Them: Insights from 160 Million Attack Simulations

25/08/2025 0 Comments 0 tags

Security Information and Event Management (SIEM) systems act as the primary tools for detecting suspicious activity in enterprise networks, helping organizations identify and respond to potential attacks in real time.