macOS’s new security layer targets admin errors before hackers

October 31, 2025hacker newsEndpoint security/network security A design company is editing a new campaign video on a MacBook Pro. A creative director opens a collaboration app that quietly requests microphone and camera permissions. MacOS is supposed to flag this, but the checks are lax in this case. The app gets access anyway. Another Mac in […]
Google’s AI defenses built into Android now block 10 billion fraudulent messages per month

Google on Thursday revealed that its built-in fraud protection features in Android protect users around the world from more than 10 billion potentially malicious calls and messages each month. The company also said it has blocked more than 100 million suspicious numbers from using its Rich Communications Service (RCS), an evolution of its SMS protocol, […]
Russian ransomware gang weaponizes open source AdaptixC2 for advanced attacks

October 30, 2025Ravi LakshmananMalware/Cybercrime The open-source command and control (C2) framework known as AdaptixC2 is being used by a growing number of threat actors, some of which are associated with Russian ransomware gangs. AdaptixC2 is an extensible post-exploitation and adversarial emulation framework designed for penetration testing. The server component is written in Golang, while the […]
New ‘brazen’ exploit instantly crashes Chromium browser with a single malicious URL

October 30, 2025Ravi LakshmananBrowser security/vulnerabilities A serious vulnerability disclosed in Chromium’s Blink rendering engine could cause many Chromium-based browsers to crash within seconds. Security researcher Jose Pino, who detailed the flaw, code-named it “Brash.” “By exploiting an architectural flaw in how certain DOM operations are managed, any Chromium browser can collapse in 15 to 60 […]
BAS is the power behind true defense

Security does not fail at the point of breach. It fails at the moment of impact. This sentence set the tone for this year’s Picus Breach and Simulation (BAS) Summit. There, researchers, practitioners, and CISOs all echoed the same theme: Cyber defense is no longer about prediction. It’s about the evidence. When a new exploit […]
DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising

Oct 30, 2025Ravie LakshmananCybersecurity / Hacking News The comfort zone in cybersecurity is gone. Attackers are scaling down, focusing tighter, and squeezing more value from fewer, high-impact targets. At the same time, defenders face growing blind spots — from spoofed messages to large-scale social engineering. This week’s findings show how that shrinking margin of safety […]
126 PhantomRaven malware found in npm packages to steal GitHub tokens from developers

October 30, 2025Ravi LakshmananDevSecOps / Software Security Cybersecurity researchers have discovered another active software supply chain attack campaign targeting the npm registry that contains over 100 malicious packages that can steal authentication tokens, CI/CD secrets, and GitHub credentials from developer machines. The campaign has been codenamed PhantomRaven by Koi Security. This activity is estimated to […]
Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

October 29, 2025Ravi LakshmananVulnerabilities / Internet of Things Cybersecurity researchers are warning of a surge in automated attacks targeting PHP servers, IoT devices, and cloud gateways from various botnets such as Mirai, Gafgyt, and Mozi. “These automated campaigns exploit known CVE vulnerabilities and cloud misconfigurations to take control of exposed systems and expand botnet networks,” […]
New cloaking attack targets AI to trick AI crawlers into citing misinformation as verified fact

October 29, 2025Ravi LakshmananMachine learning/AI safety Cybersecurity researchers have flagged a new security issue in agent web browsers such as OpenAI ChatGPT Atlas that exposes the underlying artificial intelligence (AI) model to context poisoning attacks. The attack, devised by AI security firm SPLX, allows malicious attackers to set up websites that serve different content to […]
Discover practical AI tactics for GRC — join our free expert webinar

October 29, 2025hacker newsArtificial intelligence/compliance Artificial intelligence (AI) is rapidly transforming governance, risk, and compliance (GRC). This is no longer a futuristic concept; it’s already here, and it’s already reshaping the way teams operate. The deep capabilities of AI speed up audits, alert you to critical risks faster, and significantly reduce time-consuming manual work. This […]