Ransomware Defense Using the Wazuh Open Source Platform

Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide. A ransomware attack typically begins when the malware infiltrates a system through various […]
Operation SkyCloak introduces Tor-enabled OpenSSH backdoor targeting defense sector

November 4, 2025Ravi LakshmananMalware/Cyber Espionage Threat actors are leveraging weaponized attachments distributed through phishing emails to deliver malware likely targeting defense sectors in Russia and Belarus. According to multiple reports from Cyble and Seqrite Labs, the campaign is designed to deploy a persistent backdoor on compromised hosts using OpenSSH in conjunction with a customized Tor […]
Google’s AI ‘Big Sleep’ discovers five new vulnerabilities in Apple’s Safari WebKit

November 4, 2025Ravi LakshmananArtificial intelligence/vulnerabilities Google’s artificial intelligence (AI)-powered cybersecurity agent, called Big Sleep, has been credited by Apple with discovering up to five different security flaws in the WebKit component used in the Safari web browser that, if successfully exploited, could cause the browser to crash or corrupt memory. Here is the list of […]
US prosecutors indict cybersecurity insider accused in BlackCat ransomware attack

November 4, 2025Ravi LakshmananRansomware/Cybercrime U.S. federal prosecutors have charged the trio with hacking the networks of five U.S. companies with BlackCat (also known as ALPHV) ransomware and extorting them between May and November 2023. Ryan Clifford Goldberg, Kevin Tyler Martin, and an unnamed Florida-based co-conspirator (also known as “Co-conspirator 1”), all U.S. nationals, allegedly used […]
Microsoft detects ‘SesameOp’ backdoor that uses OpenAI API as a stealth command channel

November 4, 2025Ravi LakshmananArtificial intelligence/malware Microsoft has revealed details of a new backdoor called SesameOp that uses the OpenAI Assistants application programming interface (API) for command-and-control (C2) communications. “Instead of relying on traditional techniques, the attackers behind this backdoor are exploiting OpenAI as a C2 channel as a way to covertly communicate and coordinate malicious […]
Malicious VSX extension ‘SleepyDuck’ uses Ethereum to keep command server alive

November 3, 2025Ravi LakshmananCryptocurrency/Threat Intelligence Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry that harbors a remote access Trojan called SleepyDuck. According to John Tuckner of Secure Annex, the extension in question, juan-bianco.solidity-vlang (version 0.0.7), was first published as a completely benign library on October 31, 2025, then reached 14,000 […]
Cybercriminals exploit remote monitoring tools to infiltrate logistics and cargo networks

November 3, 2025Ravi LakshmananCybercrime/Supply Chain Attack Criminals are increasingly practicing targeting trucking and logistics companies to infect remote monitoring and management (RMM) software and ultimately steal cargo for financial gain. According to Proofpoint, this threat cluster is believed to have been active since at least June 2025 and is said to be working with organized […]
Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & More

Nov 03, 2025Ravie LakshmananCybersecurity / Hacking News Cyberattacks are getting smarter and harder to stop. This week, hackers used sneaky tools, tricked trusted systems, and quickly took advantage of new security problems—some just hours after being found. No system was fully safe. From spying and fake job scams to strong ransomware and tricky phishing, the […]
How Continuous Exposure Management Transforms Security Operations

November 3, 2025hacker news Security operations centers (SOCs) are currently overwhelmed. Analysts process thousands of alerts every day and spend much of their time tracking down false positives and adjusting detection rules reactively. SOCs often lack the environmental context and relevant threat intelligence needed to quickly verify which alerts are truly malicious. As a result, […]
Researchers discover BankBot-YNRK and DeliveryRAT Android Trojans that steal financial data

Cybersecurity researchers have uncovered two different Android Trojans called BankBot-YNRK and DeliveryRAT that can collect sensitive data from compromised devices. According to CYFIRMA, which analyzed three different samples of BankBot-YNRK, the malware has built-in functionality to evade analysis efforts by first checking for execution within a virtualized or emulated environment and then extracting device details […]