Critical Golden DMSA Attacks in Windows Server 2025 allow cross-domain attacks and permanent access

July 16, 2025Ravi LakshmananWindows Server / Enterprise Security Cybersecurity researchers have revealed what they say is a “significant design flaw” in the Delegated Managed Service Account (DMSA) introduced in Windows Server 2025. “This flaw can cause impactful attacks, allowing cross-domain lateral movement, allowing permanent access to all managed service accounts and their resources indefinitely across […]

AI agents act like employees with root access – here’s how to get back control

July 16, 2025Hacker NewsIdentity Management / AI Security The AI Gold Rush is lit. But without identity-first security, all deployments are open doors. Most organizations protect native AI like web apps, but act like junior employees with root access and no manager. From hype to high stakes Generated AI has moved beyond the hype cycle. […]

Deep fake. Fake recruiter. Clone CFOS – Learn how to stop AI-driven attacks in real time

July 16, 2025Hacker NewsAI Security/Fraud Detection The attack on social engineering has entered a new era. And they are fast, smart, and deeply personalized. It’s not just suspicious emails in your spam folder. Today’s attackers mimic executives, hijack social channels, create websites, emails, and even audio, mimic executives, mimic executives, use stolen branding assets, Deep […]

Google releases CVE-2025-6558 crucial chrome update to wild and active exploits

July 16, 2025Ravi LakshmananBrowser Security / Zero Day On Tuesday, Google rolled out fixes for six security issues in the Chrome web browser. The high-strength vulnerability in question is CVE-2025-6558 (CVSS score: 8.8). This is described as an incorrect verification of browser angles and untrusted input of GPU components. “Insufficient validation of angles and GPU […]

Google AI “Big Sleep” stops exploitation of critical SQLite vulnerabilities before hacker law

July 16, 2025Ravi LakshmananAI Security/Vulnerability Google revealed on Tuesday that its Large Language Model (LLM)-assisted Vulnerability Discovery Framework discovered security flaws in the SQLite open source database engine before being exploited in the wild. The vulnerability tracked as CVE-2025-6965 (CVSS score: 7.2) is a memory corruption flaw that affects all versions prior to 3.50.2. It […]

Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors

July 15, 2025Ravi LakshmananBotnet/Network Security CloudFlare said Tuesday it mitigated a 7.3 million distributed denial-of-service (DDOS) attack in the second quarter of 2025, significantly lowering its 20 million DDOS attack, which it lost in the last quarter. “Overall, the second quarter of 2025 saw a surge in ultra-volume DDOS attacks,” said Omer Yoachimik and Jorge […]

State-backed HagyBeacon malware uses AWS Lambda to steal data from SE Asian government

July 15th, 2025Ravi LakshmananCyber Spy/Threat Intelligence Government organizations in Southeast Asia are targeting new campaigns aimed at collecting sensitive information using previously undocumented Windows backdoors. This activity is tracked by Palo Alto Networks Unit 42, where “CL” represents “cluster” and “STA”, “CL” represents “motivation for state responsibility”, and “CL” represents “CL”. “The threat actors behind […]

How to protect invisible identity access

July 15th, 2025Hacker NewsAutomation/Risk Management AI agents are committed to automating everything from financial adjustments to incident response. However, every time an AI agent rotates a workflow, it needs to be authenticated somewhere. Often, you use a High-Privilege API key, OAuth token, or service account that Defenders cannot easily view. These “invisible” nonhuman identities (NHIS) […]