Patched Fortinet FortiWeb flaw exploited in attack to create administrator account

November 14, 2025Ravi LakshmananThreat Intelligence/Vulnerability Cybersecurity researchers have warned that the Fortinet Fortiweb WAF has an authentication bypass vulnerability that could allow an attacker to take over the administrator account and fully compromise the device. “The watchTowr team has observed active and indiscriminate field exploitation of vulnerabilities that appear to have been silently patched in […]
Russian hackers create 4,300 fake travel websites to steal hotel guests’ payment data

The Russian-speaking threat behind an ongoing massive phishing campaign has resulted in over 4,300 domain names being registered since the beginning of the year. According to Andrew Brandt, a security researcher at Netcraft, this activity is designed to target customers in the hospitality industry, particularly hotel guests who may have made travel reservations through spam […]
Fake Chrome extension “Safery” uses Sui blockchain to steal Ethereum wallet seed phrases

November 13, 2025Ravi LakshmananBrowser security/threat intelligence Cybersecurity researchers have discovered a malicious Chrome extension that has the ability to steal users’ seed phrases while masquerading as a legitimate Ethereum wallet. The extension is named “Safery: Ethereum Wallet,” and the attackers describe it as “a secure wallet for managing your Ethereum cryptocurrency with flexible settings.” It […]
Why 2026 will be the year of machine speed security

Competition per new CVE Based on multiple industry reports in 2025, approximately 50 to 61 percent of newly disclosed vulnerabilities had exploit code weaponized within 48 hours. Using CISA’s Known and Exploited Vulnerabilities Catalog as a reference, we have seen hundreds of software flaws being actively targeted within days of publication. Every new announcement sparks […]
Operation Endgame dismantles Rhadamanthys, Venom RAT, and Elysium botnets in global crackdown

November 13, 2025Ravi LakshmananBotnet/Cybercrime Malware families including Rhadamanthys Stealer, Venom RAT, and Elysium botnet were disrupted as part of a coordinated law enforcement operation led by Europol and Eurojust. The operation, which will take place from November 10 to 13, 2025, marks the latest phase of Operation Endgame, an ongoing operation aimed at shutting down […]
Cisco 0-Days, AI Bug Bounties, Crypto Heists, State-Linked Leaks and 20 More Stories

Nov 13, 2025Ravie LakshmananCybersecurity / Hacking News Behind every click, there’s a risk waiting to be tested. A simple ad, email, or link can now hide something dangerous. Hackers are getting smarter, using new tools to sneak past filters and turn trusted systems against us. But security teams are fighting back. They’re building faster defenses, […]
CISA reports critical flaw in WatchGuard Fireware, exposing 54,000 Fireboxes to no-login attack

November 13, 2025Ravi LakshmananVulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting WatchGuard Fireware to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerability in question is CVE-2025-9242 (CVSS score: 9.3), an out-of-bounds write vulnerability affecting Fireware OS 11.10.2 and later […]
Over 46,000 fake npm packages flood registries with worm-like spam attacks

Cybersecurity researchers are warning of a massive spam campaign that has flooded the npm registry with thousands of fake packages since early 2024, likely as part of a financially motivated effort. “Packages were systematically exposed over an extended period of time, flooding the npm registry with junk packages that survived in the ecosystem for almost […]
Google sues China-based hackers behind $1 billion Lighthouse phishing platform

November 12, 2025Ravi LakshmananCybercrime/Malware Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against China-based hackers behind a massive phishing-as-a-service (PhaaS) platform called Lighthouse that has captivated more than 1 million users in 120 countries. PhaaS kits are used to run large-scale SMS phishing attacks […]
Amazon discovers zero-day flaw in attacks exploiting Cisco ISE and Citrix NetScaler

November 12, 2025Ravi LakshmananNetwork security/zero day Amazon’s threat intelligence team revealed Wednesday that it observed sophisticated threat actors exploiting two then-current zero-day security flaws in Cisco Identity Service Engine (ISE) and Citrix NetScaler ADC products as part of an attack aimed at delivering custom malware. “This discovery highlights a trend in threat actors’ focus on […]