[Webinar] See how leading security teams use DASR to reduce attack surface exposure

November 12, 2025hacker newsThreat detection/risk management Security teams face the same challenges every day: too many risks, too many alerts, and not enough time. Solving one problem creates three more. I feel like I’m always one step behind. But what if there was a smarter way to stay ahead without adding more work or stress? […]
Why critical infrastructure needs strong security

Active Directory remains the authentication backbone for over 90% of Fortune 1000 companies. As enterprises adopt hybrid and cloud infrastructures, AD is growing in importance and complexity. All applications, users, and devices trace back to AD for authentication and authorization, making it their ultimate target. For attackers, this represents the holy grail. Compromising Active Directory […]
Microsoft fixes 63 security flaws, including zero-days, in Windows kernel under active attack

November 12, 2025Ravi LakshmananVulnerabilities/Tuesday Patch Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software. This includes vulnerabilities that are actually being exploited. Of the 63 deficiencies, 4 were rated as critical and 59 were rated as critical. 29 of these vulnerabilities are related to privilege escalation, followed by 16 for […]
Google launches ‘Private AI Computing’ – secure AI processing with on-device level privacy

November 12, 2025Ravi LakshmananArtificial intelligence/encryption Google on Tuesday announced a new privacy-enhancing technology called “Private AI Compute” that processes artificial intelligence (AI) queries on a secure platform in the cloud. The company said it built Private AI Compute to “maximize the speed and power of the Gemini cloud model for AI experiences, while ensuring the […]
WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

Threat hunters have discovered similarities between banking malware called Coyote and a newly released malicious program called Maverick that was propagated via WhatsApp. According to a report by CyberProof, both malware are written in .NET, target users and banks in Brazil, and have identical functionality to target and decrypt bank URLs and monitor bank applications. […]
GootLoader is back, uses new font tricks to hide malware on WordPress sites

November 11, 2025Ravi LakshmananMalware/Network Security According to new research from Huntress, the malware known as GootLoader has reemerged after a brief spike in activity in early March of this year. The cybersecurity firm announced that it has observed three GootLoader infections since October 27, 2025, two of which resulted in manual keyboard intrusion, and a […]
CISO’s expert guide to AI supply chain attacks

AI-powered supply chain attacks increased by 156% last year. Learn why traditional defenses are failing and what CISOs must do now to protect their organizations. Download the entire CISO’s expert guide to AI supply chain attacks here. TL;DR AI-powered supply chain attacks are exploding in size and sophistication. Malicious package uploads to open source repositories […]
Researchers detect malicious npm package targeting GitHub-owned repositories

November 11, 2025Ravi LakshmananSoftware supply chain/malware Cybersecurity researchers have discovered a malicious npm package named “@acitons/artifact” that typosquats the legitimate “@actions/artifact” package in order to target repositories owned by GitHub. “We believe the purpose was to run this script during the build of a GitHub-owned repository, extract tokens available in the build environment, and use […]
Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram into Hacker Hub

Cybersecurity researchers have revealed details of a new Android remote access Trojan (RAT) called Fantasy Hub that is marketed on Russian-speaking Telegram channels based on a Malware-as-a-Service (MaaS) model. According to the seller, the malware allows control and espionage of the device, allowing attackers to collect SMS messages, contacts, call logs, images, and videos, as […]
Hackers exploit Triofox flaw to install remote access tools via antivirus

November 10, 2025Ravi LakshmananVulnerability/Incident Response Google’s Mandiant Threat Defense announced Monday that it has discovered an n-day exploit of a now-patched security flaw in Gladinet’s Triofox file sharing and remote access platform. This critical vulnerability, tracked as CVE-2025-12480 (CVSS score: 9.1), allows an attacker to bypass authentication and access the configuration page, which could result […]