Securing AI to Profit from AI

Artificial intelligence (AI) holds great promise in improving cyber defenses and making security personnel’s lives easier. This helps teams eliminate alert fatigue, identify patterns faster, and achieve levels of scale that human analysts alone cannot match. But realizing that potential depends on protecting the systems that make it possible. All organizations experimenting with AI in […]

Google identifies three new Russian malware families created by COLDRIVER hackers

October 21, 2025Ravi LakshmananCyber ​​espionage/threat intelligence The new malware, attributed to a Russia-linked hacker group known as COLDRIVER, has been in development multiple times since May 2025, suggesting an increase in the “tempo of operations” by the threat actors. The findings come from the Google Threat Intelligence Group (GTIG), which states that in the same […]

Hackers use Snappybee malware and Citrix vulnerability to infiltrate European telecom networks

October 21, 2025Ravi LakshmananCyber ​​espionage / network security A European telecommunications organization is said to have been targeted by threat actors affiliated with a Chinese-aligned cyber-espionage group known as Salt Typhoon. According to Darktrace, the organization was targeted in the first week of July 2025, and the attackers gained initial access by exploiting the Citrix […]

Five new exploited bugs listed in CISA catalog – Oracle and Microsoft also targeted

October 20, 2025Ravi LakshmananThreat intelligence/data security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, formally confirming that a recently disclosed vulnerability affecting Oracle E-Business Suite (EBS) has been weaponized in a real-world attack. The security flaw in question is CVE-2025-61884 (CVSS score: […]

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

It’s easy to think your defenses are solid — until you realize attackers have been inside them the whole time. The latest incidents show that long-term, silent breaches are becoming the norm. The best defense now isn’t just patching fast, but watching smarter and staying alert for what you don’t expect. Here’s a quick look […]

3 reasons copy/paste attacks cause security breaches

ClickFix, FileFix, fake CAPTCHAs, or whatever you call them, attacks in which users manipulate malicious scripts in their web browsers are a rapidly increasing source of security breaches. ClickFix attacks prompt users to resolve some problem or issue on their browser. CAPTCHAs are the most common, but so are things like fixing errors on web […]

131 Chrome extensions found to be hijacking WhatsApp Web in massive spam campaign

October 20, 2025Ravi LakshmananBrowser security/malware Cybersecurity researchers discovered a coordinated campaign that leveraged 131 rebranded clones of the WhatsApp web automation extension for Google Chrome to spam users in Brazil at scale. According to supply chain security firm Socket, 131 spamware extensions share the same codebase, design patterns, and infrastructure. The browser add-on has approximately […]

MSS claims NSA used 42 cyber tools in multi-stage attack on Beijing Time System

October 20, 2025Ravi LakshmananCyber ​​espionage/national security China on Sunday described the United States as a “hacker empire” and “the biggest source of chaos in cyberspace” and accused the National Security Agency (NSA) of carrying out a “planned” cyberattack targeting the National Time Service Center (NTSC). The Ministry of State Security (MSS) said in a post […]

Europol dismantles SIM farm network running 49 million fake accounts worldwide

October 19, 2025Ravi LakshmananSIM exchange/virtual currency Europol on Friday announced the disruption of its advanced Cybercrime-as-a-Service (CaaS) platform that operated SIM farms and enabled customers to commit crimes ranging from phishing to investment fraud. The coordinated law enforcement operation, dubbed Operation SIMCARTEL, conducted 26 raids resulting in the arrest of seven suspects and the seizure […]

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

October 18, 2025Ravi LakshmananThreat Intelligence/Cybercrime Cybersecurity researchers have uncovered a new campaign likely targeting Russia’s automotive and e-commerce industries using a previously undocumented .NET malware called “CAPI Backdoor.” According to Seqrite Labs, the attack chain includes distributing phishing emails with ZIP archives as a method of causing infection. The cybersecurity firm’s analysis is based on […]