Learn how leading enterprises protect cloud workloads and infrastructure at scale

November 18, 2025hacker newsCloud security/compliance Perhaps you’ve already moved, or are planning to move, some part of your business to the cloud. That’s a wise move. It helps you work faster, better serve your customers, and stay ahead of the game. However, as cloud configurations expand, it becomes difficult to control who has access to […]

Researchers detail Tuoni C2’s role in 2025 real estate cyber intrusion attempt

November 18, 2025Ravi LakshmananMalware/Social Engineering Cybersecurity researchers have revealed details of a cyberattack that targeted a major US-based real estate company. This attack included the use of an early command and control (C2) and red team framework known as Tuoni. “This campaign leveraged the emerging Tuoni C2 framework, a relatively new command-and-control (C2) tool (with […]

Iranian hackers use DEEPROOT and TWOSTROKE malware in aerospace and defense attacks

November 18, 2025Ravi LakshmananCyber ​​espionage/malware Suspected Iranian espionage actors have been observed deploying backdoors such as TWOSTROKE and DEEPROOT as part of an ongoing campaign targeting aerospace, aviation, and defense industries in the Middle East. The activity is believed to be due to a threat cluster tracked by Google-owned Mandiant as UNC1549 (also known as […]

Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities

Identity security fabric (ISF) is a unified architectural framework that brings together disparate identity capabilities. Through ISF, identity governance and administration (IGA), access management (AM), privileged access management (PAM), and identity threat detection and response (ITDR) are all integrated into a single, cohesive control plane. Building on Gartner’s definition of “identity fabric,” identity security fabric […]

7 npm packages use Adspect cloaking to lure victims to cryptocurrency scam pages

November 18, 2025Ravi LakshmananMalware/Web Security Cybersecurity researchers discovered a set of seven npm packages published by a single attacker. The package leverages a cloaking service called Adspect to distinguish between real victims and security researchers, ultimately redirecting them to a sketchy crypto-themed site. Below are malicious npm packages published by a threat actor named ‘dino_reborn’ […]

Microsoft mitigates record 5.72 Tbps DDoS attack by AISURU botnet

November 18, 2025Ravi LakshmananIoT Security/Botnet Microsoft on Monday said it automatically detected and neutralized a distributed denial of service (DDoS) attack that targeted a single endpoint in Australia. The scale of the attack was 5.72 terabits per second (Tbps), or approximately 3.64 billion packets per second (pps). The tech giant said this was the largest […]

Google issues security fix for actively exploited zero-day vulnerability in Chrome V8

November 18, 2025Ravi LakshmananBrowser security/vulnerabilities Google on Monday released security updates for its Chrome browser to address two security flaws, including one that is being exploited in the wild. The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8). This is a type confusion vulnerability in the V8 JavaScript and WebAssembly engines that can be exploited […]

New Assessment ClickFix Campaign Offers Amatera Stealer and NetSupport RAT

November 17, 2025Ravi Lakshmanan Cybersecurity researchers discovered a malware campaign deploying Amatera Stealer and NetSupport RATs using the now popular ClickFix social engineering tactic. This activity observed this month is tracked by eSentire under the name EVALUSION. First discovered in June 2025, Amatera is believed to be an evolution of ACR (short for “AcridRain”) Stealer, […]

Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

Nov 17, 2025Ravie LakshmananCybersecurity / Hacking News This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. […]