Google Patch is a critical zero-day flaw in Chrome’s V8 engine after active exploitation

July 1, 2025Ravi LakshmananVulnerability/Browser Security Google has released a security update to address a vulnerability in the Chrome browser that has exploits in Wild. The zero-day vulnerability tracked as CVE-2025-6554 (CVSS score: N/A) is described as a confusing flaw in the type of V8 JavaScript and WebAssembly engine. “Confusion in the V8 type of Google […]
US arrests key facilitators in North Korea’s IT Workers Scheme and seizes $7.74 million

The U.S. Department of Justice (DOJ) announced Monday a sweep action targeting the North Korean Information Technology (IT) worker scheme, leading to the arrest of one individual and the seizing of 29 financial accounts, 21 fraudulent websites and around 200 computers. The coordinated action searched 21 known or suspicious “laptop farms” in 14 US states, […]
Microsoft will remove password management from Authenticator app from August 2025

July 1, 2025Ravi LakshmananMobile Security/Privacy Microsoft has said it has stopped supporting passwords for the Authenticator app from August 1, 2025. According to the company, the change is part of an effort to streamline Autofill for its two-factor authentication (2FA) app. “From July 2025, Authill features will no longer work, and passwords will no longer […]
US agencies warn of an increase in Iran’s cyberattacks on defense, OT networks and critical infrastructure

June 30, 2025Ravi LakshmananCyber Attacks/Critical Infrastructure The US Cybersecurity and Intelligence Agency has issued a joint advisory warning of potential cyberattacks from Iranian state-sponsored or affiliated threat actors. “Over the past few months, there has been an increase in activity from actors related to Hattivists and the Iranian government, which is expected to escalate due […]
Europol will dismantle a $540 million cryptocurrency fraud network and arrest five suspects

On Monday, Europol announced a takedown of its cryptocurrency investment fraud ring, which has laundered 460 million euros ($540 million) from more than 5,000 casualties worldwide. He said the operation was carried out by Spanish Guardian citizens, along with support from law enforcement agencies in Estonia, France and the United States. Europol said the syndicate […]
Blind Eagle uses Proton 66 hosting for fishing and rat deployment at the Bank of Columbia

June 30, 2025Ravi LakshmananCybercrime/Vulnerability The threat actor known as Blind Eagle is attributed to a high degree of confidence in the use of Russian bulletproof hosting service Proton66. TrustWave SpiderLabs said in a report published last week that this connection can be created by pivoting from Proton66-related digital assets, leading to the discovery of an […]
A practical approach to NHI inventory

Identity-based attacks are on the rise. Attacks that assume the identity of an entity that allows malicious actors to easily access resources and easily access sensitive data have increased in recent years. Several recent reports estimate that 83% of attacks will involve compromised secrets. Reports such as Verizon DBIR show that attackers are gaining their […]
Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and more

Jun 30, 2025Ravie LakshmananCybersecurity / Hacking News Ever wonder what happens when attackers don’t break the rules—they just follow them better than we do? When systems work exactly as they’re built to, but that “by design” behavior quietly opens the door to risk? This week brings stories that make you stop and rethink what’s truly […]
The FBI is using social engineering to warn about scattered spider spreading attacks on airlines

The US Federal Bureau of Investigation (FBI) has revealed that it has observed that infamous cybercriminal groups scattering spiders and widening their targeting footprint to attack the airline sector. To that end, the agency said it is actively working with aviation and industry partners to combat the activities and support the victims. “These actors rely […]
From browser steelers to intelligence gathering tools

June 28, 2025Ravi LakshmananMalware/Cyber War The threat actors behind the GiftedCrook malware have made important updates to transform malicious programs from basic browser data steelers into powerful intelligence gathering tools. “The recent campaign in June 2025 shows that it strengthens its talented ability to remove a wide range of sensitive documents from targeted personal devices, […]