New HttpTroy backdoor disguises as VPN invoice in targeted cyber attack in South Korea

November 3, 2025Ravi LakshmananCybersecurity/Malware A North Korean-linked actor known as Kimsuky distributed a previously undocumented backdoor codenamed HttpTroy as part of a spear-phishing attack targeting a single victim in South Korea. Gen Digital, which revealed the details of the activity, did not say when the incident occurred, but the phishing email contained a ZIP file […]

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability

November 1, 2025Ravi LakshmananArtificial intelligence/vulnerabilities The Australian Signals Directorate (ASD) has issued information regarding an ongoing cyberattack targeting unpatched Cisco IOS XE devices in the country and a previously undocumented implant known as BADCANDY. According to the intelligence community, this activity included the exploitation of CVE-2023-20198 (CVSS score: 10.0), a critical vulnerability that allows a […]

GPT-5 agent that automatically detects and fixes code defects

October 31, 2025Ravi LakshmananArtificial intelligence/code security OpenAI has announced the launch of an “Agent Security Researcher” that leverages the GPT-5 Large-Scale Language Model (LLM) and is programmed to emulate human experts who can scan, understand, and patch code. The artificial intelligence (AI) company, called Aardvark, said the autonomous agent is designed to help developers and […]

Nation-state hackers deploy new Airstalk malware in suspected supply chain attack

October 31, 2025Ravi LakshmananMalware/Browser Security A suspected nation-state threat actor is believed to be involved in distributing a new malware called Airstalk as part of a supply chain attack. Palo Alto Networks Unit 42 said it is tracking the cluster, designated CL-STA-1009. “CL” stands for cluster, and “STA” stands for state-backed motives. “Airstalk exploits the […]

China-linked hackers exploit Windows shortcut flaw to target European diplomats

October 31, 2025Ravi LakshmananMalware/Threat Intelligence A China-linked threat actor known as UNC6384 is said to be responsible for new attacks targeting diplomatic and government organizations in Europe by exploiting unpatched Windows shortcut vulnerabilities between September and October 2025. Arctic Wolf said in a technical report released on Thursday that the operation targeted not only government […]

China-linked tick group exploits Lanscope zero-day to take over corporate systems

October 31, 2025Ravi LakshmananEndpoint security/cyber espionage The recently revealed exploitation of a critical security flaw in Motex Lanscope Endpoint Manager is believed to be the work of a cyber espionage group known as Tick. This vulnerability is tracked as CVE-2025-61932 (CVSS score: 9.3) and allows remote attackers to execute arbitrary commands with SYSTEM privileges on […]

MSP Cybersecurity Readiness Guide: Turn security into growth

October 31, 2025hacker newsBusiness continuity/risk management MSPs face increasing customer expectations for strong cybersecurity and compliance outcomes while threats become more complex and regulatory demands evolve. Meanwhile, clients are increasingly demanding comprehensive protection without the burden of managing security themselves. This change means great growth opportunities. By offering advanced cybersecurity and compliance services, MSPs can […]

CISA and NSA issue emergency guidance to protect WSUS and Microsoft Exchange servers

October 31, 2025Ravi LakshmananVulnerability/Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), along with international partners in Australia and Canada, have released guidance for hardening on-premises Microsoft Exchange Server instances from potential abuse. “By restricting administrative access, implementing multi-factor authentication, enforcing strict transport security configurations, and adopting Zero […]

Eclipse Foundation revokes leaked open VSX tokens following Wiz discovery

October 31, 2025Ravi LakshmananMalware/Secure Coding The Eclipse Foundation, which manages the open source Open VSX project, said it has taken steps to revoke a small number of tokens that were leaked within a Visual Studio Code (VS Code) extension published in the marketplace. This action follows a report from cloud security firm Wiz earlier this […]

CISA warns that VMware zero-day was exploited in active attack by China-linked hackers

October 31, 2025Ravi LakshmananVulnerability/Cyber ​​attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw affecting Broadcom VMware Tools and VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog after receiving reports of it being exploited in the wild. The vulnerability in question, CVE-2025-41244 (CVSS score: 7.8), could be […]