Konni hacker turns Google’s Find Hub into remote data erasure weapon

A North Korean-linked actor known as Konni (also known as Earth Imp, Opal Sleet, Osmium, TA406, and Vedalia) is believed to be responsible for a new series of data theft and remote control attacks targeting both Android and Windows devices. “The attackers posed as psychological counselors and North Korean human rights activists and distributed malware […]
Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and More

Cyber threats didn’t slow down last week—and attackers are getting smarter. We’re seeing malware hidden in virtual machines, side-channel leaks exposing AI chats, and spyware quietly targeting Android devices in the wild. But that’s just the surface. From sleeper logic bombs to a fresh alliance between major threat groups, this week’s roundup highlights a clear […]
New Browser Security Report Reveals New Threats to Enterprises

According to the new Browser Security Report 2025, security leaders are realizing that most identity, SaaS, and AI-related risks are concentrated in one place: the user’s browser. However, traditional controls such as DLP, EDR, and SSE still operate one layer below. What is revealed is more than just a blind spot. This is the surface […]
Massive ClickFix phishing attack using PureRAT malware targets hotel systems

Cybersecurity researchers have called attention to a large-scale phishing campaign targeting the hospitality industry that lures hotel managers to ClickFix-style pages and collects credentials by deploying malware such as PureRAT. “The attacker’s modus operandi included using compromised email accounts to send malicious messages to multiple hotel properties,” Sequoia said. “This campaign utilizes spear-phishing emails impersonating […]
GlassWorm malware found in three VS Code extensions that were installed thousands of times

November 10, 2025Ravi LakshmananMalware/Threat Intelligence Cybersecurity researchers have published a new set of three extensions related to the GlassWorm campaign. This marks an ongoing attempt by some threat actors to target the Visual Studio Code (VS Code) ecosystem. The extension in question is still available for download and is listed below. GlassWorm, first documented by […]
Microsoft discovers ‘whisper leak’ attack that identifies AI chat topics in encrypted traffic

Microsoft has revealed details of a new side-channel attack targeting remote language models. Under certain circumstances, this attack could allow a passive attacker with the ability to observe network traffic to gather details about a model’s conversation topics despite cryptographic protection. The company noted that this leakage of data exchanged between humans and language models […]
Samsung’s zero-click flaw is exploited to deploy LANDFALL Android spyware via WhatsApp

November 7, 2025Ravi LakshmananMobile security/vulnerability A patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day in a targeted attack in the Middle East to deliver “commercial-grade” Android spyware called LANDFALL. According to Palo Alto Networks Unit 42, this activity involves exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in […]
From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools

China-affiliated actors are believed to have engaged in cyberattacks targeting U.S. nonprofit organizations with the goal of establishing long-term sustainability as part of a broader campaign targeting U.S. organizations related to or engaged in policy issues. The organization “actively seeks to influence U.S. government policy on international issues,” according to a report by Broadcom’s Symantec […]
Logic bomb hidden in malware-laden NuGet package is set to explode several years after installation

November 7, 2025Ravi LakshmananSupply chain attacks/malware A set of nine malicious NuGet packages were identified that can disrupt industrial control systems by dropping time-delayed payloads and interfering with database operations. According to software supply chain security firm Socket, the packages were published by a user named “shanhai666” in 2023 and 2024 and are designed to […]
Enterprise credentials are at risk – are they the same now?

November 7, 2025hacker newsData protection/cloud security Imagine this. Sarah, an accountant, receives periodic password reset-like emails from her organization’s cloud provider. She clicks the link, enters her credentials, and returns to the spreadsheet. However, without realizing it, she made a big mistake. Sarah accidentally gives her login information to a cybercriminal. Cybercriminals go as far […]