⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and More

10/11/2025 0 Comments 0 tags

Cyber threats didn’t slow down last week—and attackers are getting smarter. We’re seeing malware hidden in virtual machines, side-channel leaks exposing AI chats, and spyware quietly targeting Android devices in

GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs

10/11/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware

10/11/2025 0 Comments 0 tags

Cybersecurity researchers have called attention to a massive phishing campaign targeting the hospitality industry that lures hotel managers to ClickFix-style pages and harvest their credentials by deploying malware like PureRAT.

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic

08/11/2025 0 Comments 0 tags

Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model conversation topics

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp

07/11/2025 0 Comments 0 tags

A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a “commercial-grade” Android spyware dubbed LANDFALL in targeted attacks in the Middle East. The

From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools

07/11/2025 0 Comments 0 tags

A China-linked threat actor has been attributed to a cyber attack targeting an U.S. non-profit organization with an aim to establish long-term persistence, as part of broader activity aimed at

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

07/11/2025 0 Comments 0 tags

A set of nine malicious NuGet packages has been identified as capable of dropping time-delayed payloads to sabotage database operations and corrupt industrial control systems. According to software supply chain

Enterprise Credentials at Risk – Same Old, Same Old?

07/11/2025 0 Comments 0 tags

Imagine this: Sarah from accounting gets what looks like a routine password reset email from your organization’s cloud provider. She clicks the link, types in her credentials, and goes back

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts

07/11/2025 0 Comments 0 tags

Google on Thursday said it’s rolling out a dedicated form to allow businesses listed on Google Maps to report extortion attempts made by threat actors who post inauthentic bad reviews

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

07/11/2025 0 Comments 0 tags

Cybersecurity researchers have flagged a malicious Visual Studio Code (VS Code) extension with basic ransomware capabilities that appears to be created with the help of artificial intelligence – in other