Five ways identity-based attacks are violating retail

From the roles of underprivileged administrators to long-forgotten vendor tokens, these attackers have slipped through the cracks of trust and access. Here’s how the five retail violations unfolded and what they revealed… In recent months, major retailers such as Adidas, the North Face, Dior, Secrets of Victoria, Cartier, Marks & Spencer, and Copp have all […]

Rondodox Botnet Exploits TBK DVR and 4 faithful router flaws launch Explaws DDOS attack

Cybersecurity researchers have been calling attention to malware campaigns targeting the security flaws of the TBK Digital Video Recorder (DVR) and four faith routers, ropeing the devices into a new botnet called the Rondodox. Vulnerabilities in question include CVE-2024-3721, a moderately radical command injection vulnerability affecting TBK DVR-4104 and DVR-4216 DVRS, and CVE-2024-12856, an operating […]

Over 17,000 fake news websites caught fuel supply investment scams worldwide

A newly released report by cybersecurity company CTM360 reveals a massive fraud manipulation using fake news websites known as fake news sites (BNSs) to deceive users into online investment scams in 50 countries. These BNS pages are designed to look like real news outlets from CNN, BBC, CNBC, or local media. They publish fake stories […]

Researchers reveal Batavia window spyware and steal documents from Russian companies

July 8, 2025Ravi LakshmananCyber ​​Spy/Threat Intelligence The Russian organization is being targeted as part of an ongoing campaign to provide previously undocumented Windows spyware called Batavia. Activities for each cybersecurity vendor Kaspersky have been active since July 2024. “Targeted attacks start with bait emails containing malicious links sent under the pretext of signing a contract,” […]

CISA adds four important vulnerabilities to the KEV catalog through aggressive exploitation

July 8, 2025Ravi LakshmananCyber ​​Attacks/Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. Here’s a list of defects – CVE-2014-3931 (CVSS score: 9.8) – Multi-router-looking glass (MRLG) buffer overflow vulnerability that allows remote attackers […]

The SEO addiction campaign targets over 8,500 SMB users with malware disguised as AI tools

Cybersecurity researchers are revealing malicious campaigns that use search engine optimization (SEO) addiction technology to provide a known malware loader called Oyster (aka Broomstick or Cleanuploader). Malvertising activity per Arctic Wolf promotes fake websites that host troilerized versions of legal tools such as Putty and WinSCP, and aims to search for these programs and install […]

Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and More

Jul 07, 2025Ravie LakshmananCybersecurity / Hacking Everything feels secure—until one small thing slips through. Even strong systems can break if a simple check is missed or a trusted tool is misused. Most threats don’t start with alarms—they sneak in through the little things we overlook. A tiny bug, a reused password, a quiet connection—that’s all […]

Why you need a default password?

July 7, 2025Hacker NewsIoT Security/Cyber ​​Resilience If Iranian hackers haven’t heard of violating US water facilities, that’s because they couldn’t control a single pressure station serving 7,000 people. Notable for this attack, not its size, but how it was accessible to hackers simply by using the manufacturer’s default password, “1111”. With this narrow escape, CISA […]

TAG-140 deploys DRAT V2 rats targeting the Indian government, defense and railway sector

It was found that hacking groups with non-Pakistani ties are targeting Indian government organizations with modified variants of remote access trojans (rats), known as drats. This activity is attributed to a threat actor tracked as TAG-140 by the recorded Future Insikt group and is said to overlap with Sidecopy. This is a hostile group (a.k.a. […]