macOS’s new security layer targets admin errors before hackers

October 31, 2025hacker newsEndpoint security/network security A design company is editing a new campaign video on a MacBook Pro. A creative director opens a collaboration app that quietly requests microphone and camera permissions. MacOS is supposed to flag this, but the checks are lax in this case. The app gets access anyway. Another Mac in […]

Russian ransomware gang weaponizes open source AdaptixC2 for advanced attacks

October 30, 2025Ravi LakshmananMalware/Cybercrime The open-source command and control (C2) framework known as AdaptixC2 is being used by a growing number of threat actors, some of which are associated with Russian ransomware gangs. AdaptixC2 is an extensible post-exploitation and adversarial emulation framework designed for penetration testing. The server component is written in Golang, while the […]

New ‘brazen’ exploit instantly crashes Chromium browser with a single malicious URL

October 30, 2025Ravi LakshmananBrowser security/vulnerabilities A serious vulnerability disclosed in Chromium’s Blink rendering engine could cause many Chromium-based browsers to crash within seconds. Security researcher Jose Pino, who detailed the flaw, code-named it “Brash.” “By exploiting an architectural flaw in how certain DOM operations are managed, any Chromium browser can collapse in 15 to 60 […]

BAS is the power behind true defense

Security does not fail at the point of breach. It fails at the moment of impact. This sentence set the tone for this year’s Picus Breach and Simulation (BAS) Summit. There, researchers, practitioners, and CISOs all echoed the same theme: Cyber ​​defense is no longer about prediction. It’s about the evidence. When a new exploit […]

DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising

Oct 30, 2025Ravie LakshmananCybersecurity / Hacking News The comfort zone in cybersecurity is gone. Attackers are scaling down, focusing tighter, and squeezing more value from fewer, high-impact targets. At the same time, defenders face growing blind spots — from spoofed messages to large-scale social engineering. This week’s findings show how that shrinking margin of safety […]

126 PhantomRaven malware found in npm packages to steal GitHub tokens from developers

October 30, 2025Ravi LakshmananDevSecOps / Software Security Cybersecurity researchers have discovered another active software supply chain attack campaign targeting the npm registry that contains over 100 malicious packages that can steal authentication tokens, CI/CD secrets, and GitHub credentials from developer machines. The campaign has been codenamed PhantomRaven by Koi Security. This activity is estimated to […]

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

October 29, 2025Ravi LakshmananVulnerabilities / Internet of Things Cybersecurity researchers are warning of a surge in automated attacks targeting PHP servers, IoT devices, and cloud gateways from various botnets such as Mirai, Gafgyt, and Mozi. “These automated campaigns exploit known CVE vulnerabilities and cloud misconfigurations to take control of exposed systems and expand botnet networks,” […]

New cloaking attack targets AI to trick AI crawlers into citing misinformation as verified fact

October 29, 2025Ravi LakshmananMachine learning/AI safety Cybersecurity researchers have flagged a new security issue in agent web browsers such as OpenAI ChatGPT Atlas that exposes the underlying artificial intelligence (AI) model to context poisoning attacks. The attack, devised by AI security firm SPLX, allows malicious attackers to set up websites that serve different content to […]

Discover practical AI tactics for GRC — join our free expert webinar

October 29, 2025hacker newsArtificial intelligence/compliance Artificial intelligence (AI) is rapidly transforming governance, risk, and compliance (GRC). This is no longer a futuristic concept; it’s already here, and it’s already reshaping the way teams operate. The deep capabilities of AI speed up audits, alert you to critical risks faster, and significantly reduce time-consuming manual work. This […]