Large-scale ghost network operation exposes 3,000 YouTube videos as malware traps

October 24, 2025Rabi LakshmananMalware/Hacking News Malicious networks of YouTube accounts have been observed publishing and promoting videos that lead to malware downloads, essentially exploiting the popularity and trust associated with video hosting platforms to propagate malicious payloads. The network, which has been active since 2021, has published more than 3,000 malicious videos to date, with […]

Self-spreading ‘GlassWorm’ infects VS Code extensions, triggering widespread supply chain attacks

October 24, 2025Rabi LakshmananDevOps/Malware Cybersecurity researchers have discovered a self-propagating worm that spreads through the Open VSX Registry and Visual Studio Code (VS Code) extensions on the Microsoft Extension Marketplace. This highlights how developers are a prime target for attacks. This advanced threat, codenamed GlassWorm by Koi Security, is the second such supply chain attack […]

North Korean hacker lures defense engineer with fake job to steal drone secrets

October 23, 2025Rabi LakshmananCyber ​​espionage/threat intelligence A new wave of attacks targeting European companies in the defense industry, part of a long-running campaign known as Operation Dream Job, is believed to be the work of attackers with ties to North Korea. “Some of these companies are heavily involved in the unmanned aerial vehicle (UAV) space, […]

Protecting AI at scale and speed — learn the framework in this free webinar

October 23, 2025hacker newsArtificial intelligence/data protection AI is everywhere, and companies want it. Faster products, smarter systems, fewer bottlenecks. But when you’re in a safe environment, that excitement is often accompanied by a sinking feeling. Because while everyone else is rushing ahead, you must manage a growing web of AI agents that you didn’t create, […]

$176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More

Oct 23, 2025Ravie LakshmananCybersecurity / Hacking News Criminals don’t need to be clever all the time; they just follow the easiest path in: trick users, exploit stale components, or abuse trusted systems like OAuth and package registries. If your stack or habits make any of those easy, you’re already a target. This week’s ThreatsDay highlights […]

Why organizations abandon static secrets for managed identities

October 23, 2025hacker newsDevOps/Data Protection As machine identities explode across cloud environments, companies are reporting dramatic increases in productivity by eliminating static credentials. And legacy systems remain the only vulnerable part. For decades, organizations have relied on static secrets such as API keys, passwords, and tokens as unique identifiers for their workloads. Although this approach […]

‘Jingle Thief’ Hacker Abuses Cloud Infrastructure to Steal Millions of Dollars in Gift Cards

Cybersecurity researchers have uncovered a cybercrime group called Jingle Thief that has been observed targeting cloud environments associated with organizations in the retail and consumer services sectors for gift card fraud. “Jingle Thief attackers are using phishing and smishing to steal credentials and compromise organizations that issue gift cards,” Palo Alto Networks Unit 42 researchers […]

Over 250 Magento stores hit overnight as hackers exploit new flaw in Adobe Commerce

October 23, 2025Ravi LakshmananData breach/vulnerabilities E-commerce security firm Sansec has warned that attackers have begun exploiting recently revealed security vulnerabilities in the Adobe Commerce and Magento open source platforms, with more than 250 attack attempts recorded against multiple stores in the past 24 hours. The vulnerability in question is CVE-2025-54236 (CVSS score: 9.1), which has […]

CISA confirms critical bug in Lanscope Endpoint Manager was exploited in ongoing cyber attack

October 23, 2025Ravi LakshmananVulnerability/Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting Motex Lanscope Endpoint Manager to its Known Exploited Vulnerabilities (KEV) catalog, saying it is being exploited in the wild. This vulnerability, CVE-2025-61932 (CVSS v4 score: 9.3), affects on-premises versions of Lanscope Endpoint Manager, specifically […]

Iran-linked Muddy Water targets over 100 organizations in global espionage campaign

October 22, 2025Ravi LakshmananMalware/Cyber ​​Espionage The Iranian nation-state group known as MuddyWater has been implicated in a new campaign that leveraged compromised email accounts to distribute a backdoor called Phoenix to various organizations in the Middle East and North Africa (MENA) region, including more than 100 government agencies. Singapore cybersecurity firm Group IB said in […]