Dynamic AI-SaaS security case study as co-pilot scales

Over the past year, artificial intelligence co-pilots and agents have quietly infiltrated the SaaS applications that enterprises use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow have built-in AI assistant or agent-like features. Virtually all major SaaS vendors are rushing to incorporate AI into their products. The result is an explosion of […]

Kimsuky spreads DocSwap Android malware via QR phishing disguised as a distribution app

December 18, 2025Ravi LakshmananMalware/Mobile Security The North Korean threat actor known as Kimsuky is said to be behind a new campaign distributing a new variant of Android malware called DocSwap via QR codes hosted on phishing sites imitating Seoul-based logistics company CJ Logistics (formerly CJ Korea Express). “The attackers used QR codes and notification pop-ups […]

CISA reports critical flaw in ASUS Live Update following evidence of active exploitation

December 18, 2025Ravi LakshmananVulnerabilities/Software Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw affecting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), is described as “embedding a malicious code vulnerability” introduced by a supply […]

Cisco warns of active attack exploiting unpatched zero-day in AsyncOS email security appliances

December 18, 2025Ravi LakshmananVulnerability/Network Security Cisco has warned users of a maximum severity zero-day vulnerability in Cisco AsyncOS Software. This vulnerability, codenamed UAT-9686, is being actively exploited by a Chinese-aligned Advanced Persistent Threat (APT) attacker in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The network equipment giant said it […]

SonicWall fixes actively exploited CVE-2025-40602 on SMA 100 appliances

December 17, 2025Ravi LakshmananVulnerability/Network Security SonicWall has published fixes to address security flaws in its Secure Mobile Access (SMA) 100 Series appliances. This flaw is reportedly being exploited in the wild. The vulnerability, tracked as CVE-2025-40602 (CVSS score: 6.6), involves a case of local privilege escalation that occurs as a result of insufficient authentication in […]

Kimwolf botnet hijacks 1.8 million Android TVs and launches massive DDoS attack

QiAnXin “Kimwolf is a botnet compiled using NDK [Native Development Kit]”In addition to typical DDoS attack capabilities, it integrates proxy forwarding, reverse shell, and file management capabilities,” the company said in a report released today. The hyperscale botnet is estimated to have issued 1.7 billion DDoS attack commands in a three-day period from November 19 […]

APT28 targets UKR-net users in Ukraine in long-running credential phishing campaign

December 17, 2025Ravi LakshmananEmail Security/Threat Intelligence A Russian state-sponsored threat actor known as APT28 is believed to be involved in what is described as an “ongoing” credential harvesting campaign targeting UKR users.[.]net is a popular webmail and news service in Ukraine. This activity was observed by Recorded Future’s Insikt Group from June 2024 to April […]

New forum troll phishing attack uses fake e-library emails to target Russian academics

December 17, 2025Ravi LakshmananVulnerabilities/Malware According to Kaspersky, the attackers involved in the forum troll operation are believed to be involved in a new phishing campaign targeting individuals in Russia. A Russian cybersecurity vendor announced that it detected new activity in October 2025. The origin of the threat actor is currently unknown. “While the spring cyberattacks […]

See threats to your industry and country in real time

Modern security teams often feel like they’re driving through fog with broken headlights. Threats are accelerating, alerts are increasing, and SOCs struggle to understand which hazards are currently important to the business. Moving away from reactive defense is no longer an option. It’s the difference between preventing an incident and handling it afterwards. Here’s a […]

China-linked Ink Dragon uses ShadowPad and FINALDRAFT malware to hack government

The threat actor known as Jewelbug has increasingly focused on government targets in Europe since July 2025, even as it continues to attack organizations located in Southeast Asia and South America. Check Point Research is tracking this cluster under the name Ink Dragon. It is also referred to by the names CL-STA-0049, Earth Alux, and […]