Hackers spreading Agent Tesla, Asyncrat and Snake KeyLogger using the new QuirkyLoader malware

August 21, 2025Ravi LakshmananMalware/Email Security Cybersecurity researchers have revealed details of a new malware loader called QuirkyLoader, which has been used via email spam campaigns since November 2024, from information steelers to remote access trojans. Notable malware families distributed using QuirkyLoader include agents Tesla, Asyncrat, Formbook, MassLogger, Remcos Rat, Rhadamanthys Stealer, and Snake Keylogger. IBM […]
Important findings from Blue Report 2025

As a security expert, it’s easy to get caught up in a race to counter the latest advanced enemy techniques. However, the most influential attacks are often not due to cutting-edge exploits, but rather to cracked credentials and compromised accounts. Despite widespread awareness of this threat vector, Picus Security’s Blue Report 2025 shows that organizations […]
Scattered spider hackers win $13 million in reparations for SIMs replacing Crypto theft for 10 years

August 21, 2025Ravi LakshmananData Breach/Cybercrime The 20-year-old member of the infamous cybercrime gang known as the scattered spiders has been sentenced to 10 years in the United States in connection with a string of major hacks and cryptocurrency thefts. Noah Michael Urban pleaded guilty in April 2025 to charges relating to wire fraud and aggravated […]
Apple Patches CVE-2025-43300 Zero Day for iOS, iPados and Macos

August 21, 2025Ravi LakshmananVulnerability/Zero Day Apple has released security updates to address security flaws affecting iOS, iPados and MacOS, saying it is undergoing active exploitation in the wild. The zero-day outbound write vulnerability tracked as CVE-2025-43300 lies in the Imageio framework that can result in memory corruption when processing malicious images. “Apple is aware of […]
DOM-based extension ClickJacking exposes popular password managers to credentials and data theft

August 20, 2025Ravi LakshmananVulnerability/Browser Security It has been discovered that popular password manager plugin web browsers could click on security vulnerabilities that could be exploited to steal account eligibility, two-factor authentication (2FA) codes and credit card details under certain conditions. The technique dubbed a Document Object Model (DOM)-based extension by independent security researcher Marek Tóth, […]
FBI warns FSB-linked hackers exploiting Patchededed Cisco devices for Cyber Spionage

August 20, 2025Ravi LakshmananCyberspy/Vulnerability It has been observed that the Russian state-sponsored cyberspy group, known as the Static Tundra, is actively exploiting the seven-year-old security flaws of Cisco iOS and Cisco iOS XE software as a means of establishing permanent access to target networks. Cisco Talos, who revealed details of the activity, said the attack […]
Experts have discovered that AI browsers can be tricked by ProsptFix exploits to run malicious hidden prompts

Cybersecurity researchers have demonstrated a new prompt injection technique called PromptFix, which tricks the Generated Artificial Intelligence (Genai) model to perform the intended action by embedding malicious instructions within fake Captcha checks on web pages. The attack technique described by Guardio Labs as “AI-ERA accepts Clickfix scams,” shows how AI-driven browsers such as Perplexity comets […]
Discover and control Shadow AI agents in your company before hackers do it

August 20, 2025Hacker NewsArtificial Intelligence/Enterprise Security Do you know how many AI agents are currently running within your business? If you don’t know the answer, then you are not alone. That’s exactly what concerns you are. AI agents are set up every day across the industry. Sometimes it is by that, but in many cases […]
Turn BIA insights into resilient recovery

Modern business is facing a rapidly evolving and growing threat landscape, what does this mean for your business? That means more risks with increased frequency, diversity, complexity, severity and potential business impact. The real question is, “How do we tackle these rising threats?” The answer lies in having a robust BCDR strategy. However, to build […]
North Korea uses GitHub in diplomat cyberattacks as IT worker schemes hit more than 320 companies

The North Korean threat actor is attributed to a coordinated cyberspy campaign targeting diplomatic missions at its southern counterparts between March and July 2025. The activity appears in the form of at least 19 spear fishing emails, with the goal of inviting invitations, official letters and events, impersonating trusted diplomatic contacts aimed at seducing embassy […]