Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

18/08/2025 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a dependency that allows it to establish persistence and achieve code

Wazuh for Regulatory Compliance

18/08/2025 0 Comments 0 tags

Organizations handling various forms of sensitive data or personally identifiable information (PII) require adherence to regulatory compliance standards and frameworks. These compliance standards also apply to organizations operating in regulated

ERMAC V3.0 Banking Trojan Source Code Leak Exposes Full Malware Infrastructure

16/08/2025 0 Comments 0 tags

Cybersecurity researchers have detailed the inner workings of an Android banking trojan called ERMAC 3.0, uncovering serious shortcomings in the operators’ infrastructure. “The newly uncovered version 3.0 reveals a significant

Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer Malware

16/08/2025 0 Comments 0 tags

The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads. Trustwave SpiderLabs said it recently observed an EncryptHub campaign

Taiwan Web Servers Breached by UAT-7237 Using Customized Open-Source Hacking Tools

15/08/2025 0 Comments 0 tags

A Chinese-speaking advanced persistent threat (APT) actor has been observed targeting web infrastructure entities in Taiwan using customized versions of open-sourced tools with an aim to establish long-term access within

Zero Trust + AI: Privacy in the Age of Agentic AI

15/08/2025 0 Comments 0 tags

We used to think of privacy as a perimeter problem: about walls and locks, permissions, and policies. But in a world where artificial agents are becoming autonomous actors — interacting

U.S. Sanctions Garantex and Grinex Over $100M in Ransomware-Linked Illicit Crypto Transactions

15/08/2025 0 Comments 0 tags

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on Thursday renewed sanctions against Russian cryptocurrency exchange platform Garantex for facilitating ransomware actors and other cybercriminals by

Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution

15/08/2025 0 Comments 0 tags

Cisco has released security updates to address a maximum-severity security flaw in Secure Firewall Management Center (FMC) Software that could allow an attacker to execute arbitrary code on affected systems.

New HTTP/2 ‘MadeYouReset’ Vulnerability Enables Large-Scale DoS Attacks

14/08/2025 0 Comments 0 tags

Multiple HTTP/2 implementations have been found susceptible to a new attack technique called MadeYouReset that could be explored to conduct powerful denial-of-service (DoS) attacks. “MadeYouReset bypasses the typical server-imposed limit

Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS

14/08/2025 0 Comments 0 tags

Japan’s CERT coordination center (JPCERT/CC) on Thursday revealed it observed incidents that involved the use of a command-and-control (C2) framework called CrossC2, which is designed to extend the functionality of