Evolving Enterprise Defense to Secure the Modern AI Supply Chain

September 30, 2025Hacker NewsArtificial Intelligence/Data Protection The world of enterprise technology is undergoing dramatic changes. The adoption of Gen-AI is accelerating at an unprecedented pace, with SaaS vendors embedding powerful LLM directly into their platforms. Organizations employ AI-powered applications across all functions, from marketing and development to finance and HR. This transformation unlocks innovation and […]
British police seized £5.5 billion of Bitcoin – the world’s largest crypto bust

Chinese citizens were convicted of her role in a fraudulent cryptocurrency scheme after British law enforcement confiscated £5.5 billion (approximately $73.9 billion) during the raid of her London home. The cryptocurrency attack, worth 61,000 bitcoins, is considered the world’s biggest effort, metropolitan police said. Zhimin Qian, 47, aka Yadi Zhang, pleaded guilty to a crime […]
CISA alarms critical sudo defects actively utilized in Linux and UNIX systems

September 30, 2025Ravi LakshmananVulnerability / Linux The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw that affects SUDO command line utilities in operating systems like Linux and Unix. The vulnerability in question is CVE-2025-32463 (CVSS score: 9.3), which affects SUDO versions prior to 1.9.17P1. It was revealed in July […]
Evil malware is set in AI tools to infiltrate global organizations

Threat actors have been observed to use seemingly legitimate artificial intelligence (AI) tools and software to sneak slick malware for future attacks on organizations around the world. According to Trend Micro, the campaign uses productivity or AI-enhancing tools to provide malware targeting a variety of regions, including Europe, America, Asia, the Middle East and Africa […]
Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More

Sep 29, 2025Ravie LakshmananCybersecurity / Hacking News Cybersecurity never stops—and neither do hackers. While you wrapped up last week, new attacks were already underway. From hidden software bugs to massive DDoS attacks and new ransomware tricks, this week’s roundup gives you the biggest security moves to know. Whether you’re protecting key systems or locking down […]
AI status in SOC 2025

Security leaders accept AI for triage, detection engineering, and threat hunting as alert volumes and burnout hit points. A comprehensive survey of 282 security leaders from businesses across the industry reveals the harsh reality facing modern security operations centres. The alert volume reaches unsustainable levels, leaving the team uninvestigated critical threats. You can download the […]
SVG files created by LLM outmart email security

Microsoft is focusing on new phishing campaigns targeting US-based organizations that are likely to leverage code generated primarily using large-scale language models (LLM) to obfuscate payloads and avoid security defenses. “As it appears to be supported by large-scale language models (LLM), activities obfuscate behavior within SVG files and leverage business terminology and synthetic structures to […]
The first malicious MCP server found stealing emails with the Rogue Postarm-MCP package

September 29, 2025Ravi LakshmananMCP Server / Vulnerability Cybersecurity researchers have discovered what is described as the first instance of a model context protocol (MCP) server discovered in the wild, increasing the risk of the software supply chain. According to KOI Security, legally-looking developers were able to slip in malformed code within an NPM package called […]
China-linked Plugx and BookWorm Malware Attack Targets Asia Telecom and ASEAN Network

September 27, 2025Ravi LakshmananMalware/Network Security The telecommunications and manufacturing sectors in central and South Asian countries are emerging as the goal of an ongoing campaign to distribute new variants of known malware called Plugx (also known as Korplug or Sogu). “The new variant features overlap with both rainy days and Churian backdoors, including the same […]
Researchers reveal SVG and Purerat phishing threats targeting Ukraine and Vietnam

September 26, 2025Ravi LakshmananMalware/Cryptocurrency A new campaign has been observed to provide countloaders by impersonating Ukrainian government agencies in phishing attacks, which will then be used to drop Amaterasu Stirers and Pureminers. “The phishing email contains malicious scalable vector graphics (SVG) files designed to trick recipients into opening harmful attachments,” Yurren Wan, a researcher at […]