SideWinder deploys new ClickOnce-based attack chain targeting South Asian diplomats

October 28, 2025Ravi LakshmananCyber ​​espionage/malware The European embassy in India’s capital, New Delhi, and multiple organizations in Sri Lanka, Pakistan, and Bangladesh emerged as targets of a new campaign organized by the threat actor known as SideWinder in September 2025. Trellix researchers Ernesto Fernández Provecho and Pham Duy Phuc said in a report published last […]

X warns users with security keys to re-register by November 10 to avoid lockout

October 27, 2025Ravi LakshmananData protection/authentication Social media platform To do so, users are asked to use their existing security key or register a new security key and complete re-registration by November 10, 2025. “If you have not re-enrolled your security key since November 10th, your account will be locked until you re-enroll, choose a different […]

New ChatGPT Atlas browser exploit allows attackers to embed persistent hidden commands

October 27, 2025Ravi LakshmananArtificial intelligence/vulnerabilities Cybersecurity researchers have discovered a new vulnerability in OpenAI’s ChatGPT Atlas web browser. This vulnerability could allow a malicious attacker to inject malicious instructions into the memory of an artificial intelligence (AI)-powered assistant and potentially execute arbitrary code. “This exploit could allow an attacker to infect a system with malicious […]

WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach Widens

Oct 27, 2025Ravie LakshmananCybersecurity / Hacking News Security, trust, and stability — once the pillars of our digital world — are now the tools attackers turn against us. From stolen accounts to fake job offers, cybercriminals keep finding new ways to exploit both system flaws and human behavior. Each new breach proves a harsh truth: […]

Qilin ransomware, a hybrid attack that combines Linux payload and BYOVD exploit

The ransomware group known as Qilin (also known as Agenda, Gold Feather, and Water Galura) has claimed more than 40 victims every month since the beginning of 2025, with the exception of January, and the number of posts on the data breach site reached a high of 100 in June. The development comes as ransomware-as-a-service […]

ChatGPT Atlas browser can be tricked into executing hidden commands with fake URLs

The newly released OpenAI Atlas web browser has been found to be susceptible to prompt injection attacks that can jailbreak its omnibox by disguising a malicious prompt as a seemingly benign URL. “The omnibox (a combination of address and search bar) interprets input as either a URL to navigate to or as a natural language […]

Smishing Triad links to 194,000 malicious domains in global phishing operation

October 24, 2025Ravi LakshmananData breach/cyber crime The attackers behind a large-scale, ongoing smishing campaign are believed to have engaged in more than 194,000 malicious domains targeting a wide range of services around the world since January 1, 2024, according to new research from Palo Alto Networks Unit 42. Security researchers Reethika Ramesh, Zhanhao Chen, Daiping […]

Critical, newly patched Microsoft WSUS flaw exploited

October 24, 2025Rabi LakshmananVulnerability/Network Security Microsoft on Thursday released an out-of-band security update that patches a critical severity vulnerability in Windows Server Update Service (WSUS) using a publicly available proof-of-concept (POC) exploit. This exploit has been used in the wild. The vulnerability in question is CVE-2025-59287 (CVSS score: 9.8). This is a remote code execution […]

APT36 targets Indian government with Golang-based DeskRAT malware campaign

October 24, 2025Ravi LakshmananCyber ​​espionage/malware Pakistan-linked attackers were observed targeting Indian government agencies as part of a spear-phishing attack aimed at delivering Golang-based malware known as DeskRAT. The activity, which Sekoia observed in August and September 2025, is believed to be the work of Transparent Tribe (also known as APT36), a state-sponsored hacking group known […]

Why do managers and practitioners view risk differently?

October 24, 2025hacker newsCyber ​​resilience/data protection Is your organization suffering from a cybersecurity awareness gap? The results of the Bitdefender 2025 Cybersecurity Assessment suggest the answer is probably yes, but many leaders may not be aware of it. This disconnect is important. Small differences in perception today can develop into large blind spots tomorrow. After […]