5 reasons why attackers phish through LinkedIn

Phishing attacks are no longer limited to email inboxes, with one in three phishing attacks occurring via channels other than email, such as social media, search engines, and messaging apps. LinkedIn in particular is a hotbed for phishing attacks, and for good reason. Attackers are conducting sophisticated spear-phishing attacks against corporate executives, with recent campaigns […]

Dragon Breath uses RONINGLOADER to disable security tools and introduces Gh0st RAT

An attacker known as Dragon Breath has been observed leveraging a multi-stage loader known by the codename RONINGLOADER to deliver a modified variant of the remote access Trojan known as Gh0st RAT. According to Elastic Security Labs, the campaign primarily targets Chinese-speaking users and uses trojanized NSIS installers disguised as legitimate versions such as Google […]

Adoption of Rust reduces Android memory safety bugs to less than 20% for the first time

November 17, 2025Ravi LakshmananVulnerabilities / Mobile Security Google revealed that the number of memory safety vulnerabilities has dropped below 20% for the first time as the company continues to adopt the Rust programming language in Android. “We adopted Rust for security and saw a 1,000x reduction in memory safety vulnerability density compared to Android’s C […]

RondoDox exploits unpatched XWiki servers to draw more devices into botnet

November 15, 2025Ravi LakshmananMalware/vulnerabilities Botnet malware known as RondoDox has been observed targeting unpatched XWiki instances for critical security flaws that could allow attackers to execute arbitrary code. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), which allows a guest user to execute arbitrary remote code via a request to the “/bin/get/Main/SolrSearch” endpoint due […]

Five Americans plead guilty to helping North Korean IT workers break into 136 companies

The U.S. Department of Justice (DoJ) announced Friday that five people have pleaded guilty to enabling fraud against information technology (IT) workers and supporting North Korea’s illegal revenue-generating scheme in violation of international sanctions. The 5 persons are listed below – Audrikas Fagnasey, 24 years old Jason Salazar, 30 years old Alexander Paul Travis, 34 […]

North Korean hackers turn JSON service into covert malware delivery channel

November 14, 2025Ravi LakshmananMalware/Threat Intelligence The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage their malicious payloads. NVISO researchers Bart Parys, Stef Collart, and Efstratios Lontzetidis said in a Thursday report that “attackers have recently been using JSON storage services such […]

Researchers discover serious AI bug exposing Meta, Nvidia, and Microsoft inference frameworks

Cybersecurity researchers have discovered a critical remote code execution vulnerability affecting major artificial intelligence (AI) inference engines, including Meta, Nvidia, Microsoft, and open source PyTorch projects such as vLLM and SGLang. “These vulnerabilities all trace back to the same root cause: the overlooked and dangerous use of ZeroMQ (ZMQ) and Python’s pickle deserialization,” Oligo Security […]

LockBit is back, but ransomware fragmentation reaches breaking point

Important points: We observed 85 active ransomware and extortion groups in Q3 2025, reflecting the most decentralized ransomware ecosystem ever. 1,590 victims were exposed across 85 breached sites, indicating high levels of continued activity despite law enforcement pressure. This quarter saw the launch of 14 new ransomware brands, proving how quickly affiliates can rebuild after […]

Chinese hackers use Anthropic’s AI to launch automated cyber espionage operations

In mid-September 2025, Chinese state-sponsored attackers used artificial intelligence (AI) technology developed by Anthropic to orchestrate an automated cyberattack as part of a “highly sophisticated espionage campaign.” “The attackers exploited AI’s ‘agent’ capabilities to an unprecedented degree, using AI not only as an advisor but also to carry out the cyberattack itself,” the AI ​​startup […]