Why IT Leaders Should Rethink Backups in the Age of Ransomware

As it stops and confusion escalates, IT teams are shifting their focus beyond simply backing up data and maintaining operations during the incident. One of the key drivers behind this shift is the growing threat of ransomware, which continues to evolve in both frequency and complexity. The Ransomware-as-a-Service (RAAS) platform allows inexperienced threat actors with […]

Hackers use GitHub repository to host Amadey Malware and Data Stealers and bypass filters

July 17, 2025Ravi LakshmananMalware/Social Engineering As part of a campaign observed in April 2025, Threat Actors leverages public Github repositories to host malicious payloads and distribute them via Amadey. “Mers [malware-as-a-service] The operators used fake Github accounts to host payloads, tools, and Amadey plugins. This is probably an attempt to bypass web filtering and is […]

2025 Gartner® MagicQuadrant™ Endpoint Protection

Gartner, Magic Quadrant of Endpoint Protection Platform, Evgeny Mirololyubov, Franz Hinner, Deepak Mishra, July 14, 2025. Gartner does not endorse any vendors, products or services portrayed in research publications, and does not advise technology users to select only vendors with the highest ratings or other designations. Gartner’s research publications are composed of the opinions of […]

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

July 17, 2025Ravi LakshmananCryptocurrency/Vulnerability Cybersecurity researchers have discovered a new campaign that offers cryptocurrency miners called Linuxsys, leveraging known security flaws affecting Apache HTTP servers. The vulnerability in question is CVE-2021-41773 (CVSS score: 7.5). This is a high-strength past traversal vulnerability in Apache HTTP server version 2.4.49 that can lead to remote code execution. “Attackers […]

Europol destroys Hacktivist Group linked to DDOS attacks against Ukraine

The international operations coordinated by Europol disrupt the infrastructure of a Russian hacktivist group known as NonMAME057 (16), which is associated with a series of distributed denial of service (DDOS) attacks against Ukraine and its allies. This action has dismantled most of the group’s central server infrastructure and over 100 systems around the world. The […]

What security leaders need to know in 2025

The modern threat landscape requires enterprise security teams to think and act beyond traditional cybersecurity measures that are purely passive and reactive, and most often ineffective against new threats and sophisticated threat actors. Cybersecurity prioritization means implementing more proactive, adaptive and practical measures that can be collaborated to effectively deal with the threats that impact […]

Chinese hackers target cobalt strikes and custom backdoors in Taiwan’s semiconductor sector

Taiwan’s semiconductor industry has been the target of a spear phishing campaign carried out by three threatening actors sponsored by China. “The goals of these campaigns ranged from organizations involved in the manufacturing, design and testing of semiconductors and integrated circuits, a wide range of equipment and service supply chain entities within this sector, and […]

Cisco warns of critical ISE flaws, allowing uncertified attackers to run route code

July 17, 2025Ravi LakshmananVulnerability/Network Security Cisco has revealed a new maximum security vulnerability affecting the Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC). This drawback, tracked as CVE-2025-20337, is similar to CVE-2025-20281, which has a CVSS score of 10.0 and was patched by the Networking Equipment Major later last month. “Several […]

Hackers leverage Microsoft Teams to spread Mathambuchas 3.0 malware to targeted businesses

July 16, 2025Ravi LakshmananThreat Intelligence/Vulnerability Cybersecurity researchers are flagging a new variant of a known malware loader called Matanbuchus, which packs key features to enhance stealth and avoid detection. Matanbuchus is the name given to providing Malware as a Service (MAAS) that could serve as a conduit for the payload of the next stage, such […]

Fully patched Sonic Wall SMA 100 Series Device with UNC6148 Backdoor of Step Rootkit

A threat activity cluster has been observed and is targeting a fully patched Life-of-Life Sonicwall Secure Mobile Access (SMA) 100 Series appliance as part of a campaign designed to drop backdoors called OverStep. Malicious activity dating back at least to October 2024 is attributed to a group tracking it as UNC6148 from Google Threat Intelligence […]