New bug in SAP NetWeaver allows attackers to take over servers without logging in

October 15, 2025Ravi Lakshmanan Enterprise software/vulnerabilities SAP has published security fixes for 13 new security issues, including additional hardening for a maximum severity bug in SAP NetWeaver AS Java that could lead to arbitrary command execution. This vulnerability is tracked as CVE-2025-42944 and has a CVSS score of 10.0. This is described as a case […]
Chinese hackers have been exploiting ArcGIS Server as a backdoor for over a year

October 14, 2025Ravi LakshmananCyber espionage / network security For more than a year, Chinese-linked attackers are believed to be behind a new campaign to compromise ArcGIS systems and turn them into backdoors. According to ReliaQuest, this activity is the work of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal […]
How Threat Hunting Builds Readiness

Every October, everything goes pumpkin spice in stores and cafes, and my inbox is flooded with reminders, webinars, and checklists. Halloween may be around the corner, but for those of us in cybersecurity, Security Awareness Month is a seasonal milestone. Without a doubt, as a security professional, I love this month. Launched in 2004 by […]
A single 8-byte write shatters AMD’s SEV-SNP Confidential Computing security

October 14, 2025Ravi LakshmananVulnerability/Hardware Security Chipmaker AMD has released a fix to address a security flaw called RMPocalypse that can be exploited to undermine the confidential computing guarantees provided by Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). According to researchers Benedict Schlüter and Shweta Shinde from ETH Zurich, the attack exploits AMD’s imperfect protections […]
New Pixnapping flaw in Android could allow malicious apps to steal 2FA codes without permission

October 14, 2025Ravi LakshmananVulnerabilities / Mobile Security Android devices from Google and Samsung have been found to be vulnerable to side-channel attacks that can be exploited to secretly steal two-factor authentication (2FA) codes, Google Maps timelines, and other sensitive data pixel by pixel without the user’s knowledge. The attack was codenamed “Pixnapping” by a group […]
What AI reveals about web applications and why it matters

Before sending a payload, attackers have already done the work of understanding how the environment is structured. They look at login flows, JavaScript files, error messages, API documentation, and GitHub repositories. These are all clues that help you understand how the system works. AI is greatly accelerating reconnaissance, allowing attackers to map their environments faster […]
npm, PyPI, and RubyGems packages found to be sending developer data to Discord channels

October 14, 2025Ravi LakshmananMalware/Typosquatting Cybersecurity researchers have identified several malicious packages across the npm, Python, and Ruby ecosystems that leverage Discord as a command-and-control (C2) channel to send stolen data to actor-controlled webhooks. Discord’s webhooks are a way to post messages to channels within the platform without requiring bot users or authentication, making them an […]
Researchers expose MonsterV2 malware capabilities and attack chain on TA585

October 14, 2025Ravi LakshmananMalware/Social Engineering Cybersecurity researchers have uncovered that a previously undocumented threat actor known as TA585 has been observed distributing off-the-shelf malware called MonsterV2 through phishing campaigns. The Proofpoint Threat Research team described this cluster of threat activity as sophisticated, leveraging web injections and filtering checks as part of the attack chain. “TA585 […]
WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

Oct 13, 2025Ravie LakshmananCybersecurity / Hacking News Every week, the cyber world reminds us that silence doesn’t mean safety. Attacks often begin quietly — one unpatched flaw, one overlooked credential, one backup left unencrypted. By the time alarms sound, the damage is done. This week’s edition looks at how attackers are changing the game — […]
Why unmonitored JavaScript is the biggest security risk during the holiday season

Think your WAF has you covered? Think again. Not monitoring JavaScript this holiday season is a critical oversight that allows attackers to steal payment data while WAFs and intrusion detection systems are unaware. With the 2025 shopping season just weeks away, you need to close the visibility gap now. Get your complete holiday security handbook […]