One click allows you to turn Perplexity’s Comet AI Browser into Data Thief

October 4, 2025Ravi LakshmananAgent AI/Enterprise Security Cybersecurity researchers have revealed details of a new attack called CometJacking, which targets Perplexity’s agent AI browser Comet, by embedding malicious prompts within seemingly harmless links to Siphon-sensitive data from connection services such as emails and calendars. A sleazy prompt injection attack unfolds in the form of a malicious […]

Scan activity in the Palo Alto Network Portal jumps 500% in one day

October 4, 2025Ravi LakshmananVulnerability/Network Security Threat Intelligence Firm Greynoise revealed on Friday that a surge in scansing activities targeting Palo Alto Networks Login Portals has been observed. The company said it observed on October 3, 2025 that a nearly 500% increase in IP addresses scanning the Palo Alto Networks login portal was the highest recorded […]

Strela Stealer running detour dog running through a DNS-powered malware factory

The threat actor named Detour Dog was kicked out as a powerful campaign to distribute an information steeler known as Strela Stealer. This is according to Infoblox’s finding threat actors to maintain control over the domain hosting a backdoor called Staterfish, the first stage in Stealer. DNS threat intelligence company said it was tracking detour […]

Add device fingerprints, PNG steganography payload

The threat actors behind Rhadamanthys promote two other tools on their website, called the Elysium Proxy Bot and Crypt Service, despite being updated to support the ability of flagship information steelers to collect fingerprints and more on their devices and web browsers. “Rhadamanthys was initially promoted through a post on the Cybercrime Forum, but it […]

Researchers warn about self-reinforced WhatsApp malware named Sorvepotel

October 3, 2025Ravi LakshmananMalware/Online Security Brazilian users are emerging as targets for new self-propagation malware spread through the popular messaging app WhatsApp. The campaign codenamed Sorvepotel by Trend Micro, armed with trust on the platform to extend reach across Windows systems, adding that the attacks are “designed for speed and propagation” rather than data theft […]

How Passwork 7 addresses the complexities of enterprise security

Positioned as an on-premises unified platform for both password management and secret management, Passwork aims to address the increasing complexity of qualification storage and sharing in modern organizations. The platform recently received a major update that reworks all core mechanics. Passwork 7 introduces major changes to how credentials are organized, accessed and managed, reflecting feedback […]

New “Cavalry Werewolf” attack hits Russian agents with Fallshell and Stallion Rat

October 3, 2025Ravi LakshmananCybersecurity/Malware Threat actors known to share overlap with hacking groups called Yorotroopers have been observed to target the Russian public sector, which has malware families such as Foalshell and Stallionrat. Cybersecurity vendor bi.zone tracks activities under Monica Cavalry werewolves. It is also appreciated that it has similarities with clusters tracked as Sturgeon […]

Cisa Flags Meteobridge CVE-2025-4008An aggressively exploited flaw in the wild

October 3, 2025Ravi LakshmananVulnerability / IoT Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-strength security flaw affecting Meteobridge in smart beds in a known Exploited Vulnerability (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-4008 (CVSS score: 8.7), is a case of command injection in the Meteobridge web […]

Confucius hackers hit Pakistan with new Wooperstealer and Anonymous malware

October 2, 2025Ravi LakshmananMalware/Cyberspy The threat actor known as Confucius is attributed to a new phishing campaign targeting Pakistan, which has malware families such as Wooperstealer and Anondoor. “For the past decade, Confucius has repeatedly targeted government agencies, military organizations, defense contractors, especially important industries in Pakistan. Confucius has been active since 2013 and is […]

Malicious PYPI package SOOPSOCKS infects 2,653 systems before takedown

October 2, 2025Ravi LakshmananPython/Malware Cybersecurity researchers have flagged malicious packages in Python Package Index (PYPI) repository, claiming it provides the ability to create Socks5 Proxy services, and also offers features like stealth backdoors that drop additional payloads on Windows systems. The deceptive package named Soopsocks attracted a total of 2,653 downloads before being removed. It […]