Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

26/05/2025 0 Comments 0 tags

As many as 60 malicious npm packages have been discovered in the package registry with malicious functionality to harvest hostnames, IP addresses, DNS servers, and user directories to a Discord-controlled

CISO’s Guide To Web Privacy Validation And Why It’s Important

26/05/2025 0 Comments 0 tags

Are your web privacy controls protecting your users, or just a box-ticking exercise? This CISO’s guide provides a practical roadmap for continuous web privacy validation that’s aligned with real-world practices.

⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs

26/05/2025 0 Comments 0 tags

Cyber threats don’t show up one at a time anymore. They’re layered, planned, and often stay hidden until it’s too late. For cybersecurity teams, the key isn’t just reacting to

Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware

25/05/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed a malware campaign that uses fake software installers masquerading as popular tools like LetsVPN and QQ Browser to deliver the Winos 4.0 framework. The campaign, first

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

23/05/2025 0 Comments 0 tags

The malware known as Latrodectus has become the latest to embrace the widely-used social engineering technique called ClickFix as a distribution vector. “The ClickFix technique is particularly risky because it

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

23/05/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed that a threat actor codenamed ViciousTrap has compromised nearly 5,300 unique network edge devices across 84 countries and turned them into a honeypot-like network. The threat

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

23/05/2025 0 Comments 0 tags

From zero-day exploits to large-scale bot attacks — the demand for a powerful, self-hosted, and user-friendly web application security solution has never been greater. SafeLine is currently the most starred

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

23/05/2025 0 Comments 0 tags

As part of the latest “season” of Operation Endgame, a coalition of law enforcement agencies have taken down about 300 servers worldwide, neutralized 650 domains, and issued arrest warrants against

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

23/05/2025 0 Comments 0 tags

Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab’s artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject untrusted HTML into

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

23/05/2025 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday revealed that Commvault is monitoring cyber threat activity targeting applications hosted in their Microsoft Azure cloud environment. “Threat actors may