RondoDox botnet exploits more than 50 flaws across more than 30 vendors, researchers warn

The malware campaign distributing the RondoDox botnet has expanded its reach, exploiting more than 50 vulnerabilities across more than 30 vendors. Trend Micro said the campaign resembles an “exploit shotgun” approach, targeting a wide range of internet-exposed infrastructure, including routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and various other […]
Microsoft locks down IE mode after hackers turn legacy feature into backdoor

October 13, 2025Ravi LakshmananBrowser security / Windows security Microsoft announced in August 2025 that it has revamped the Internet Explorer (IE) mode in its Edge browser after receiving “credible reports” that unknown attackers were exploiting backward compatibility features to gain unauthorized access to users’ devices. “Threat actors utilized basic social engineering techniques alongside unpatched (zero-day) […]
Astaroth banking Trojan exploits GitHub and continues to operate even after removal

October 13, 2025Ravi LakshmananMalware/Financial Security Cybersecurity researchers are warning of a new campaign distributing the Astaroth banking Trojan that employs GitHub as the backbone of its operations to remain resilient in the face of infrastructure outages. “Rather than relying solely on traditional command-and-control (C2) servers that can be taken down, these attackers are leveraging GitHub […]
New Rust-based malware ‘ChaosBot’ hijacks Discord channels and takes control of victims’ PCs

October 13, 2025Ravi LakshmananRansomware/Windows Security Cybersecurity researchers have revealed details of a new Rust-based backdoor called ChaosBot. This allows operators to perform reconnaissance and execute arbitrary commands on compromised hosts. “Threat actors exploited compromised credentials mapped to both Cisco VPN and an overprivileged Active Directory account named ‘serviceaccount,’” eSentire said in a technical report published […]
New bug in Oracle E-Business Suite could allow hackers to access data without logging in

October 12, 2025Ravi LakshmananVulnerability/Threat Intelligence Oracle on Saturday issued a security alert warning of new security flaws affecting its E-Business Suite that could potentially allow unauthorized access to sensitive data. This vulnerability is tracked as CVE-2025-61884 and has a CVSS score of 7.5, indicating high severity. Affected versions are 12.2.3 to 12.2.14. “Easily exploitable vulnerability […]
Experts warn of widespread SonicWall VPN breach affecting over 100 accounts

October 11, 2025Ravi LakshmananCloud security / network security Cybersecurity firm Huntress on Friday warned of a “widespread compromise” of SonicWall SSL VPN devices used to access multiple customer environments. “Threat actors are rapidly authenticating multiple accounts across compromised devices,” the report said. “The speed and scale of these attacks suggests that the attackers appear to […]
Hackers turn Velociraptor DFIR tool into a weapon in LockBit ransomware attack

October 11, 2025Ravi LakshmananNetwork security/vulnerabilities Threat actors are exploiting Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in connection with ransomware attacks believed to be orchestrated by Storm-2603 (also known as CL-CRI-1040 or Gold Salem), known for deploying Warlock and LockBit ransomware. The use of security utilities by threat actors was documented by […]
Stealit malware exploits a single executable feature in Node.js via game and VPN installers

October 10, 2025Ravi LakshmananRansomware/Data Theft Cybersecurity researchers have revealed details of an active malware campaign called Stealit that leverages Node.js’ Single Executable Application (SEA) feature as a way to distribute its payload. According to Fortinet FortiGuard Labs, some iterations also employ the open-source Electron framework for malware delivery. The malware is assessed to be propagating […]
Microsoft warns of ‘payroll pirates’ who take over HR SaaS accounts to steal employee paychecks

October 10, 2025Ravi LakshmananSaaS Security/Threat Intelligence A threat actor known as Storm-2657 has been observed hijacking employee accounts with the ultimate goal of diverting payroll payments to accounts controlled by the attacker. “Storm-2657 is actively targeting employees of various US-based organizations, particularly in sectors such as higher education, and gaining access to third-party human resources […]
Fortra reveals complete timeline of CVE-2025-10035 exploit

October 10, 2025Ravi LakshmananVulnerability/Network Security Fortra disclosed its findings on CVE-2025-10035 on Thursday. CVE-2025-10035 is a critical security flaw in GoAnywhere Managed File Transfer (MFT) that has been assessed to have been actively exploited since at least September 11, 2025. The company said it began an investigation on September 11 after a “potential vulnerability” reported […]