Iran-linked hackers map ship’s AIS data days before actual attempted missile attack

November 20, 2025Ravi LakshmananCyberwarfare/Threat Intelligence Iranian-linked attackers are engaging in cyber warfare as part of efforts to facilitate and intensify real-world physical attacks, a trend Amazon refers to as cyber-enabled dynamic targeting. The development shows that the line between state-sponsored cyberattacks and violent warfare is becoming increasingly blurred, necessitating a new category of warfare, the […]
TamperedChef malware spreads via fake software installer in ongoing global campaign

November 20, 2025Ravi LakshmananMalvertising / Artificial Intelligence Threat actors are using fake installers disguised as popular software to trick users into installing malware as part of a global malvertising campaign called TamperedChef. The ultimate goal of the attack is to establish persistence and deliver JavaScript malware that facilitates remote access and control, according to a […]
Hackers are actively exploiting the 7-Zip symbolic link-based RCE vulnerability (CVE-2025-11001)

November 19, 2025Ravi LakshmananVulnerability/Threat Intelligence A recently revealed security flaw affecting 7-Zip is being exploited in the wild, according to an advisory issued by NHS England Digital on Tuesday. The vulnerability in question is CVE-2025-11001 (CVSS score: 7.0), which could allow a remote attacker to execute arbitrary code. This issue was addressed in 7-Zip version […]
Python-based WhatsApp worm spreads Eternidade Stealer to Brazilian devices

Cybersecurity researchers have revealed details of a new campaign that combines social engineering and WhatsApp hijacking to distribute a Delphi-based banking Trojan named Eternidade Stealer as part of an attack targeting users in Brazil. “It uses Internet Message Access Protocol (IMAP) to dynamically obtain a command and control (C2) address, allowing the attacker to update […]
WrtHug exploits six flaws in ASUS WRT to hijack tens of thousands of EoL routers worldwide

November 19, 2025Ravi LakshmananVulnerability/Threat Intelligence A newly discovered campaign has compromised tens of thousands of obsolete or end-of-life (EoL) ASUS routers around the world, primarily in Taiwan, the United States, and Russia, and connected them to large networks. This router hijacking activity has been codenamed “Operation WrtHug” by SecurityScorecard’s STRIKE team. Southeast Asia and European […]
How to use ringfencing to prevent weaponization of trusted software

The challenge facing security leaders is securing an environment where failure is not an option. Relying on traditional security postures such as endpoint detection and response (EDR) to track threats that enter a network is fundamentally risky and contributes significantly to the $5 trillion annual cost of cybercrime. Zero Trust fundamentally changes this approach, moving […]
EdgeStepper Implant reroutes DNS queries and deploys malware via hijacked software updates

November 19, 2025Ravi LakshmananCyber espionage/malware A threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor (codenamed EdgeStepper) to facilitate adversary-man-in-the-middle (AitM) attacks. EdgeStepper “redirects all DNS queries to an external malicious hijacking node, effectively rerouting traffic from legitimate infrastructure used for software updates to attacker-controlled infrastructure,” ESET security researcher […]
ServiceNow AI agents can be tricked into turning against each other via secondary prompts

November 19, 2025Ravi LakshmananAI security / SaaS security A malicious attacker could exploit the default configuration of ServiceNow’s Now Assist generative artificial intelligence (AI) platform and leverage its agent capabilities to perform prompt injection attacks. According to AppOmni, second-degree prompt injection leverages Now Assist’s agent-to-agent detection capabilities to perform unauthorized actions that allow attackers to […]
Fortinet warns of new FortiWeb CVE-2025-58034 vulnerability being exploited

November 19, 2025Ravi LakshmananVulnerability/Network Security Fortinet has warned that a new security flaw exists and is being exploited in FortiWeb. This medium severity vulnerability, tracked as CVE-2025-58034, has a CVSS score of 6.7 out of a maximum of 10.0. “Improper Disabling of Special Elements Used in OS Commands (“OS Command Injection”) Vulnerability” [CWE-78] “FortiWeb could […]
Sneaky 2FA phishing kit adds BitB pop-up designed to mimic browser address bar

Malware authors associated with the Phishing-as-a-Service (PhaaS) kit known as Sneaky 2FA have incorporated Browser-in-the-Browser (BitB) functionality into their arsenals, highlighting the continued evolution of such products, making it even easier for less-skilled attackers to launch large-scale attacks. Push Security said in a report shared with The Hacker News that it observed the technique being […]