Silver Fox spreads Winos 4.0 attack to Japan and Malaysia via HoldingHands RAT

The attackers behind the malware family known as Winos 4.0 (aka ValleyRAT) have expanded their targeting from China and Taiwan to Japan and Malaysia using another remote access Trojan (RAT) tracked as HoldingHands RAT (aka Gh0stBins). “This campaign relied on phishing emails containing PDFs with embedded malicious links,” Pei Han Liao, a researcher at Fortinet’s […]
North Korean hacker combines BeaverTail and OtterCookie to create advanced JS malware

The North Korean threat actors involved in the Contagious Interview campaign have been observed merging some of the functionality of its two malware programs, indicating that the hacker group is actively refining its toolset. This is according to new research from Cisco Talos, which finds that the hacking group’s recent campaigns have brought BeaverTail and […]
first and last line of defense

October 17, 2025hacker newsArtificial intelligence/identity security The danger is not that AI agents will have bad days, but that they never will. They faithfully execute what they are doing, even if it is wrong. One mistake in logic or access can turn a perfect automation into a perfect disaster. This is not some dystopian fantasy. […]
Researchers discover bug in WatchGuard VPN that could allow attackers to take over your device

October 17, 2025Ravi LakshmananVulnerabilities / VPN Security Cybersecurity researchers have detailed a critical security flaw recently patched in WatchGuard Fireware that could allow unauthenticated attackers to execute arbitrary code. This vulnerability is tracked as CVE-2025-9242 (CVSS score: 9.3) and is described as an out-of-bounds write vulnerability affecting Fireware OS 11.10.2 and later 11.12.4_Update1, 12.0 and […]
Microsoft revokes 200 fraudulent certificates used in Rhysida ransomware campaign

October 17, 2025Ravi LakshmananMalware/Cybercrime Microsoft on Thursday said it has revoked more than 200 certificates used by Vanilla Tempest, an attacker it tracks to fraudulently sign malicious binaries in ransomware attacks. The Microsoft Threat Intelligence team said in a post shared on X that the certificate was “used in a fake Teams setup file to […]
North Korean hackers use EtherHiding to hide malware inside blockchain smart contracts

October 16, 2025Ravi LakshmananMalware/Blockchain Threat actors associated with the Democratic People’s Republic of Korea (also known as North Korea) have been observed leveraging the EtherHiding technique to distribute malware and enable the theft of cryptocurrencies, marking the first time a state-sponsored hacker group has employed this technique. This activity has been attributed to the threat […]
Hackers exploit blockchain smart contracts to spread malware via infected WordPress sites

A financially motivated attacker, codenamed UNC5142, has been observed exploiting blockchain smart contracts as a way to facilitate the distribution of information stealers such as Atomic (AMOS), Lumma, Rhadamanthys (aka RADTHIEF), and Vidar, targeting both Windows and Apple macOS systems. “UNC5142 is characterized by the use of ‘EtherHiding,’ a technique used to place and hide […]
LinkPro Linux rootkit uses eBPF to hide and activate via Magic TCP packets

October 16, 2025Ravi LakshmananVulnerabilities/Malware An investigation into a compromise of infrastructure hosted by Amazon Web Services (AWS) has uncovered a new GNU/Linux rootkit called LinkPro, according to Synacktiv findings. “This backdoor has functionality that relies on two eBPF installations. [extended Berkeley Packet Filter] “The module is intended, on the one hand, to hide itself, and […]
How to Assess and Choose the Right AI-SOC Platform

Scaling the SOC with AI – Why now? Security Operations Centers (SOCs) are under unprecedented pressure. According to SACR’s AI-SOC Market Landscape 2025, the average organization now faces around 960 alerts per day, while large enterprises manage more than 3,000 alerts daily from an average of 28 different tools. Nearly 40% of those alerts go […]
Hackers deploy Linux rootkits via Cisco SNMP flaw in ‘Zero Disco’ attack

October 16, 2025Ravi LakshmananVulnerabilities / Linux Cybersecurity researchers have revealed details of a new campaign that exploits recently disclosed security flaws affecting Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older, unprotected systems. The activity, codenamed “Operation Zero Disco” by Trend Micro, involves the weaponization of CVE-2025-20352 (CVSS score: 7.7), a […]