US Treasury Sanctions DPRK IT-Worker Scheme reveals $600,000 crypto transfers and more than $1 million profits

August 28, 2025Ravi LakshmananArtificial Intelligence/Malware The US Treasury Department’s Office of Foreign Assets Control (OFAC) has announced new sanctions on two individuals and two entities for its role in North Korea’s remote information technology (IT) worker scheme to generate illegal revenue for the administration’s mass destruction and ballistic missile programme. “The North Korean administration continues […]
Storm-0501 exploits Entra ID to remove and delete Azure data in hybrid cloud attacks

A financially motivated threat actor known as Storm-0501 has been observed to improve tactics for carrying out data delamination and tor attacks targeting cloud environments. “Unlike traditional on-premises ransomware, threat actors usually deploy malware to encrypt critical files across endpoints within the compromised network and negotiate with decryption keys. Cloud-based ransomware brings about fundamental changes.” […]
Someone created the first AI-powered ransomware using Openai’s GPT-oss:20B model

Cybersecurity company ESET has revealed it has discovered PromptLock, a ransomware variant codenamed PromptLock, powered by artificial intelligence (AI). The newly identified strain written in Golang generates malicious LUA scripts in real time using Openai’s GPT-OSS:20B model via the Ollama API. The Open-Weight Language model was released by Openai earlier this month. “Promptlock leverages LUA […]
Humanity disrupts AI-powered cyberattacks that automate theft and tor across critical sectors

August 27, 2025Ravi LakshmananCyber Attacks/Artificial Intelligence Humanity on Wednesday revealed that in July 2025 it disrupted a sophisticated operation to weaponize the AI-powered chatbot Claude in July 2025. “The actors targeted at least 17 different organizations, including healthcare, emergency services, government and religious institutions,” the company said. “As opposed to encrypt stolen information with traditional […]
Shadowsilk hits 35 organizations in Central Asia and APAC using Telegram bots

The threat activity cluster, known as Shadowsilk, is attributed to a new set of attacks targeting government agencies within Central Asia and the Asia-Pacific (APAC). Nearly 30 victims have been identified, with the intrusion being primarily directed towards data removal, according to Group-IB. The Hacking Group shares overlaps with toolsets and infrastructure, and campaigns run […]
Five golden rules for safe AI adoption

August 27, 2025Hacker NewsEnterprise Security/Data Protection Employees are experimenting with AI at record speeds. They draft emails, analyze data, and transform workplaces. The problem is not the pace of AI adoption, but the lack of control and protection measures. For CISOs and security leaders like you, the challenges are clear. We don’t want to slow […]
SalesLoftOAUTH violation via Drift AI chat agent publishes Salesforce customer data

August 27, 2025Ravi LakshmananCloud Security/Threat Intelligence A widespread data theft campaign allowed hackers to compromise sales automation platform SalesLoft, steal OAuth and update tokens associated with drift artificial intelligence (AI) chat agents. Activities rated as inherently opportunistic are threat actors tracked by Google Threat Intelligence Group and Mandiant, tracked as UNC6395. “Until August 8, 2025, […]
Five clusters of Blind Eagle target Columbia using rats, fish ladies and dynamic DNS infrastructure

Cybersecurity researchers discovered five different activity clusters linked to a permanent threat actor known as Blind Eagle between May 2024 and July 2025. These attacks observed by future recorded Insikt groups targeted a variety of casualties, but were primarily targeted within the Colombian government at the local, city and federal levels. The Threat Intelligence Company […]
Flaws in CITRIX patches of three netterlers confirm aggressive misuse of CVE-2025-7775

August 26, 2025Ravi LakshmananVulnerability/Remote code execution Citrix has released fixes to address three security flaws: Netscaler ADC and Netscaler Gateway. The vulnerabilities in question are listed below – CVE-2025-7775 (CVSS score: 9.2) – Memory overflow leading to remote code execution and/or denial of service CVE-2025-7776 (CVSS score: 8.8) – Memory overflow vulnerability leading to unpredictable […]
New sni5gect attack crashes phones without rogue base stations and downgrades from 5g to 4g

August 26, 2025Ravi LakshmananVulnerability/Mobile Security A team of scholars have devised a new attack that can be used to downgrade 5G connections to low-generations without relying on rogue base stations (GNBs). According to the Assets (Automatic System Security) Research Group at the Singapore Institute of Technology Design (SUTD), the attack relies on a new open […]