Ukraine aid group targeted through fake Zoom meetings and weaponized PDF files

Cybersecurity researchers have detailed a coordinated spear-phishing campaign called PhantomCaptcha that targets organizations associated with war relief efforts in Ukraine and delivers a remote access Trojan that uses WebSockets for command and control (C2). The operation, which took place on 8 October 2025, targeted members of the International Society of the Red Cross, the Norwegian […]
Weeks after Microsoft’s July patch, Chinese attackers exploit ToolShell SharePoint flaw

October 22, 2025Ravi LakshmananCyber espionage/vulnerabilities After being published and patched in July 2025, Chinese-linked attackers exploited the ToolShell security vulnerability in Microsoft SharePoint to infiltrate telecommunications companies in the Middle East. In addition to government agencies in African countries, government agencies in South America and universities in the United States were also targeted, as well […]
Closing the remediation gap: Introducing Penera Resolve

From detection to resolution: why the gap persists A critical vulnerability has been identified in a public cloud asset. Within hours, five different tools surface the issue in their own way, each with different severity levels, metadata, and context: vulnerability scanner, XDR, CSPM, SIEM, and CMDB. What is missing is a behavioral system. How do […]
Fake Nethereum NuGet package uses homoglyph trick to steal crypto wallet keys

October 22, 2025Ravi LakshmananCryptocurrency/Software Integrity Cybersecurity researchers have discovered a new supply chain attack targeting the popular Ethereum .NET integration platform Nethereum’s NuGet package manager with malicious typosquats to steal victims’ cryptocurrency wallet keys. According to security firm Socket, the package ‘Netherеum.All’ was found to contain functionality that decodes command and control (C2) endpoints and […]
Why you need to exchange passwords and passphrases

October 22, 2025hacker newsData Breach/Enterprise Security This advice hasn’t changed for decades. Use a complex password that includes uppercase and lowercase letters, numbers, and symbols. The idea is to make it difficult for hackers to crack passwords using brute force techniques. However, more recent guidance indicates that the focus should be on password length rather […]
Researchers use Neursite and NeuralExecutor malware to identify PassiveNeuron APT

October 22, 2025Ravi LakshmananCyber espionage / network security Government, financial, and industrial organizations in Asia, Africa, and Latin America are being targeted by a new campaign called “PassiveNeuron,” according to Kaspersky Lab’s findings. The cyber espionage campaign was first flagged by a Russian cybersecurity vendor in November 2024, and in June revealed a series of […]
Async-Tar Rust library TARmageddon flaw could allow remote code execution

October 22, 2025Ravi LakshmananVulnerability/Data Protection Cybersecurity researchers have detailed a high-severity flaw affecting the popular async-tar Rust library and its forks, including tokio-tar. This flaw could allow remote code execution under certain conditions. The vulnerability, tracked as CVE-2025-62518 (CVSS score: 8.1), was codenamed TARmageddon by Edera, which discovered the issue in late August 2025. This […]
TP-Link patches four flaws in Omada gateway, two of which could lead to remote code execution

October 22, 2025Ravi LakshmananVulnerability/Network Security TP-Link has released a security update that addresses four security flaws affecting Omada Gateway devices, including two critical bugs that could lead to the execution of arbitrary code. The vulnerabilities in question are as follows. CVE-2025-6541 (CVSS score: 8.6) – Operating system command injection vulnerability. It could be exploited by […]
Meta launches new tools to protect WhatsApp and Messenger users from fraud

October 21, 2025Ravi LakshmananCryptocurrency/Encryption Meta announced Tuesday that it is introducing new tools to protect Messenger and WhatsApp users from potential scams. To that end, the company said it is introducing new warnings on WhatsApp to prevent sensitive information such as bank account details or verification codes from being leaked if users try to share […]
PolarEdge’s growing botnet campaign targets Cisco, ASUS, QNAP, and Synology Routers

October 21, 2025Ravi LakshmananMalware/vulnerabilities Cybersecurity researchers have uncovered the inner workings of a botnet malware called PolarEdge. PolarEdge was first documented by Sekoia in February 2025 as a campaign targeting Cisco, ASUS, QNAP, and Synology routers with the as-yet-unspecified goal of corralling these routers into their networks. At its core, TLS-based ELF implants are designed […]