Iran’s Infy APT resurfaces with new malware activity after years of silence

December 21, 2025Ravi LakshmananMalware/Cyber ​​Espionage Nearly five years after the hacking group was observed targeting victims in Sweden, the Netherlands, and Turkey, threat hunters have discovered new activity linked to the Iranian threat actor known as Infy (also known as Prince of Persia). “The scale of Prince of Persia’s activities is more significant than we […]

US Department of Justice charges $54 for ATM jackpotting scheme using Ploutus malware

December 20, 2025Ravi LakshmananCybercrime/ATM Security The US Department of Justice (DoJ) announced this week that it has indicted 54 people in connection with a multi-million dollar ATM jackpot scheme. This massive conspiracy involved deploying malware named Ploutus to hack Automated Teller Machines (ATMs) across the United States and force them to withdraw cash. The indicted […]

Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025Ravi LakshmananCyber ​​security/cloud security A group believed to be affiliated with Russia is believed to be behind a phishing campaign that uses device code authentication workflows to steal victims’ Microsoft 365 credentials and conduct account takeover attacks. This activity, which has been ongoing since September 2025, is tracked by Proofpoint under the name […]

Cracked software and YouTube videos spread CountLoader and GachiLoader malware

Cybersecurity researchers have revealed details of a new campaign that used a cracked software distribution site as a distribution vector for a new version of a modular stealth loader known as CountLoader. The Cyderes Howler Cell Threat Intelligence team said in its analysis that the campaign “uses CountLoader as the first tool in a multi-stage […]

WatchGuard warns of active exploitation of critical Fireware OS VPN vulnerability

December 19, 2025Ravi LakshmananVulnerability/Network Security WatchGuard has released a fix that addresses a critical security flaw in Fireware OS that was allegedly exploited in a real-world attack. The vulnerability is tracked as CVE-2025-14733 (CVSS score: 9.3) and is described as a case of an out-of-bounds write impacting the iked process, potentially allowing a remote unauthenticated […]

Nigeria arrests RaccoonO365 phishing developer involved in Microsoft 365 attack

December 19, 2025Ravi LakshmananCybercrime/Law Enforcement Nigerian authorities announced the arrest of three “prominent internet fraud suspects” suspected of involvement in phishing attacks targeting major companies, including the main developer of the RaccoonO365 phishing-as-a-service (PhaaS) scheme. The Nigeria Police National Cyber ​​Crime Center (NPF-NCCC) said an investigation conducted in collaboration with Microsoft and the Federal Bureau […]

New UEFI flaw allows early boot DMA attack on ASRock, ASUS, GIGABYTE, MSI motherboards

December 19, 2025Ravi LakshmananFirmware security/vulnerabilities Certain motherboard models from vendors such as ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by security vulnerabilities that make them susceptible to early-start direct memory access (DMA) attacks across architectures that implement Unified Extensible Firmware Interface (UEFI) or Input/Output Memory Management Unit (IOMMU). UEFI and IOMMU are designed to […]

China-aligned threat group uses Windows Group Policy to deploy espionage malware

December 18, 2025Ravi LakshmananMalware/Cloud Security A previously undocumented Chinese-aligned threat cluster called “LongNosed Goblin” is believed to have resulted from a series of cyberattacks targeting government agencies in Southeast Asia and Japan. Slovak cybersecurity company ESET said in a report released today that the ultimate goal of these attacks is cyber espionage. The threat activity […]

HPE OneView flaw assessed CVSS 10.0 allows unauthenticated remote code execution

December 18, 2025Ravi LakshmananVulnerabilities / Enterprise Security Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in its OneView software that could allow remote code execution if successfully exploited. This critical vulnerability has been assigned CVE identifier CVE-2025-37164 and has a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that […]

WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

Dec 18, 2025Ravie LakshmananCybersecurity / Hacking News This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s […]