Hackers abuse Miles routers to send phishing SMS to European users

October 1, 2025Ravi LakshmananVulnerability/Malware Unknown threat actors have abused the Milesight Industrial Cellular Router since at least February 2022 to send SMS messages as part of an SMS campaign targeting users in European countries. French cybersecurity firm Sekoia said attackers are leveraging Cellular Router’s API to send malicious SMS messages containing phishing URLs, and campaigns […]

New Android Banking Trojan “Klopatra” uses hidden VNC to control infected smartphones

A previously undocumented Android Banking Trojan called Cropatra has compromised over 3,000 devices, with the majority of infections reported in Spain and Italy. Cleafy, an Italian fraud prevention company that discovered sophisticated malware and remote access trojans (RATs) in late August 2025, leverages hidden virtual network computing (VNC) for remote control of infected devices, leveraging […]

Ukraine warns cabinetrat backdoor + xll add-in spreads through signal zips

October 1, 2025Ravi LakshmananMalware/Incident Response The Ukrainian Computer Emergency Response Team (CERT-UA) is using a backdoor called the Cabinettrat to warn of new, targeted cyberattacks in the country. The activity observed in September 2025 is attributed to a threat cluster tracking as UAC-0245. The agency said it discovered the attack after a software tool that […]

$50 batter ram attack breaks Intel and AMD cloud security protections

A group of scholars at the University of Birmingham have demonstrated a new vulnerability called Batting RAM to bypass the latest defenses of Intel and AMD cloud processors. “We quietly sat in the memory path and built a simple $50 interposer that behaves transparently during startups and passes all trust checks,” researchers Jesse de Muhlemes, […]

New China-linked hacker group attacks government with stealth malware

September 30, 2025Ravi LakshmananCyber ​​Spy/Malware Governments and telecommunications organizations in Africa, the Middle East and Asia have emerged for the past two and a half years as targets of previously undocumented Chinese Alliance actors, known as the Phantom Taurus. “The main areas of focus for the Phantom Taurus include foreign affairs, embassies, geopolitical events and […]

Researchers disclose the flaws in Google Gemini AI, enabling rapid injection and cloud exploits

September 30, 2025Ravi LakshmananArtificial Intelligence/Vulnerability Cybersecurity researchers have revealed three currently patched security vulnerabilities affecting Google’s Gemini Artificial Intelligence (AI) assistant. “They have made Gemini vulnerable to search injection attacks against search personalization models. Log-to-prompt injection attacks against GeminiCloudAssist, and removal of user stored information and location data through Gemini browsing tools.” The vulnerability is […]

Microsoft expands Sentinel to Agent Security Platform with Unified Data Lake

September 30, 2025Ravi LakshmananArtificial Intelligence/Threat Detection On Tuesday, Microsoft announced the expansion of Sentinel Security Incidents and Event Management Solution (SIEM) as a unified agent platform with general availability for Sentinel Data Lake. Additionally, Tech Giant said it has also released a public preview of the Sentinel Graph and Sentinel Model Context Protocol (MCP) servers. […]

Context is the key to effective incident response

September 30, 2025Hacker NewsArtificial Intelligence/Threat Detection Problem: Legacy SOCS and endless alert noise All SOC leaders know their emotions. Hundreds of alerts are poured in, dashboards lit up like slot machines, and analysts are rushing to keep pace. The more they try to expand their people or buy new tools, the faster the chaos increases. […]

China-linked hackers have been using the new VMware Zero Day since October 2024

September 30, 2025Ravi LakshmananZero Day/Vulnerability Newly patched security flaws affecting Broadcom VMware tools and VMware Aria operations have been exploited as zero days in the wild, as zero days since mid-October 2024, and since mid-October 2024, newly patched security flaws affecting Broadcom VMware tools and VMware Aria operations, according to NVISO Labs. The vulnerability in […]

New Android Trojan “Datzbro” Tricking ai Generated Facebook Travel Events for Seniors

Cybersecurity researchers have flagged a previously undocumented Android Banking Trojan called Datzbro, which allows them to perform device takeover (DTO) attacks, prey on older people and engage in fraudulent transactions. The Dutch mobile security company threat said it discovered the campaign in August 2025 after reporting a scammer who manages Facebook groups that promote “active […]