GhostPoster malware found in 17 Firefox add-ons with over 50,000 downloads

December 17, 2025Ravi LakshmananAd fraud/browser security The new campaign, dubbed GhostPoster, utilized logo files associated with 17 Mozilla Firefox browser add-ons to embed malicious JavaScript code designed to hijack affiliate links, inject tracking codes, and commit click and ad fraud. In total, the extension was downloaded more than 50,000 times, according to Koi Security, which […]

Compromised IAM Credentials Power Massive AWS Crypto Mining Campaign

December 16, 2025Ravi LakshmananMalware/threat detection An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining. The activity was first detected by Amazon’s managed threat detection service GuardDuty and its automated security monitoring systems on November 2, 2025, and employs never-before-seen persistence […]

Malicious NuGet package impersonates Tracer.Fody and steals cryptocurrency wallet data

December 16, 2025Ravi LakshmananCybersecurity/Cryptocurrency Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its creator to sneak into cryptocurrency wallet stealers. The malicious package named “Tracer.Fody.NLog” remained in the repository for nearly six years. This was published on February 26, 2020 by a user named […]

Amazon exposes years-long GRU cyber campaign targeting energy and cloud infrastructure

December 16, 2025Ravi LakshmananCloud security/vulnerabilities Amazon’s threat intelligence team has revealed details of a “multiyear-long” Russian state-led campaign targeting critical infrastructure in the West from 2021 to 2025. Targets of the campaign included organizations in the energy sector in Western countries, critical infrastructure providers in North America and Europe, and companies with cloud-hosted network infrastructure. […]

Why data security and privacy needs to start in code

AI-assisted coding and AI app generation platforms have sparked an unprecedented surge in software development. Enterprises are currently facing rapid growth in both the number of applications and the pace of change within applications. Security and privacy teams are under tremendous pressure as the surface area they must cover expands rapidly, even as staffing levels […]

Fortinet FortiGate under active attack with SAML SSO authentication bypass

December 16, 2025Ravi LakshmananNetwork security/vulnerabilities Threat actors began exploiting two newly disclosed security flaws in Fortinet FortiGate devices less than a week after they were made public. Cybersecurity company Arctic Wolf announced that it observed an active intrusion involving a malicious single sign-on (SSO) login on a FortiGate appliance on December 12, 2025. The attack […]

React2Shell vulnerability is actively exploited to deploy Linux backdoors

According to findings from Palo Alto Networks Unit 42 and NTT Security, a security vulnerability known as React2Shell is being exploited by threat actors to distribute malware families such as KSwapDoor and ZnDoor. “KSwapDoor is a professionally engineered remote access tool designed with stealth in mind,” Justin Moore, senior manager of threat intelligence research at […]

Google to end dark web monitoring tools in February 2026

December 16, 2025Ravi LakshmananDark Web / Online Safety Google announced it would retire its Dark Web Reporting tool in February 2026, less than two years after launching it as a way for users to monitor whether their personal information was found on the dark web. As a result, scanning for new dark web breaches will […]

FreePBX patches critical SQLi, file upload, and AUTHTYPE bypass flaws that enable RCE

December 15, 2025Ravi LakshmananVulnerabilities/Software Security Multiple security vulnerabilities have been disclosed in the open source private branch exchange (PBX) platform FreePBX, including a critical flaw that could lead to authentication bypass under certain configurations. The shortcomings discovered by Horizon3.ai and reported to the project administrator on September 15, 2025 are as follows: CVE-2025-61675 (CVSS Score: […]