New Coldriver Malware Campaign joins BO Team and Bearlyfy in a Russian-focused cyberattack

The Russian Advanced Persistent Threat (APT) group known as Coldriver is attributed to a Clickfix-style fresh attack designed to provide two new “lightweight” malware families tracked as Baitswitch and Simplefix. Zscaler Threatlabz, which detected a new multi-stage click fix campaign earlier this month, described Baitswitch as a downloader that ultimately drops SimpleFix, a PowerShell backdoor. […]

Why BAS is not a hypothesis, but a proof of defense

September 26, 2025Hacker NewsSecurity Verification / Enterprise Security Automakers don’t trust the blueprint. They crush the prototype into the wall. Over and over again. In controlled conditions. This is because the design specifications do not prove survival. Crash tests do that. They separate theories from reality. The same goes for cybersecurity. The dashboard overflows with […]

Flaws in fortra goanywhere cvss 10 were misused a week before public disclosure

September 26, 2025Ravi LakshmananVulnerability/Threat Intelligence Cybersecurity company Watchtowr Labs revealed on September 10, 2025, a week before its public disclosure, that there is “trustworthy evidence” of the aggressive exploitation of security flaws recently disclosed in Fortra Goany Where Managed File Transfer (MFT) software. “This is not “just” the flaw in CVSS 10.0, a solution that […]

The new macOS xcsset variant targets firefox with clippers and persistence modules

September 26, 2025Ravi LakshmananMalware/Browser Security Cybersecurity researchers have discovered an updated version of the known Apple MACOS malware called XCSSet, which was observed in limited attacks. “This new variant of XCSSet brings important changes related to browser targeting, clipboard hijacking and persistence mechanisms,” the Microsoft Threat Intelligence team said in a report Thursday. “It uses […]

Cisco ASA Firewall Zero Day Expolotz Deployment RayInitiator and Line Viper Malware

The UK National Cybersecurity Centre (NCSC) has revealed that threat actors will use recently disclosed security flaws as part of their zero-day attacks to provide previously undocumented families of malware, such as Rayinitator and Line Viper. “RayInitiatator and Line Viper malware represent a significant evolution of what was used in previous campaigns, both in its […]

Cisco Asa Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

September 25, 2025Ravi LakshmananZero Day/Vulnerability Cisco urges customers to patch two security flaws that affect the VPN web servers of the Cisco Secure Firewall Adaptive Security Appliance (ASA) software and Cisco Secure Firewall Threat Defense (FTD) software. The zero-day vulnerabilities in question are listed below – CVE-2025-20333 (CVSS score: 9.9) – Inappropriate validation of user-supported […]

Vane Viper generates 1 trillion DNS queries to power global malware and AD fraud networks

September 25, 2025Ravi LakshmananAggravated/Threat Intelligence A threat actor known as Vane Viper is out as a provider of malicious advertising technology (ADTECH). Meanwhile, it relies on the tangled web and opaque ownership structure of shell companies to deliberately circumvent liability. “Vane Viper has been providing core infrastructure for the spread of widespread fraud, AD fraud […]

Salesforce Patches Critical ForcedLeak Bug Publish CRM Data via AI Prompt Injection

September 25, 2025Ravi LakshmananVulnerability / AI Security Cybersecurity researchers have revealed a serious flaw affecting Salesforce AgentForce, the platform for building artificial intelligence (AI) agents. The vulnerability is codenamed CodeNed ForcedLeak (CVSS score: 9.4) by NOMA Security, which discovered and reported the issue on July 28, 2025. Use Salesforce AgentForce with the Web-to-LEAD feature to […]

North Korean hackers are targeting global crypto developers using the new Akdoortea backdoor

North Korea-related threat actors associated with the infectious interview campaign are attributed to previously undocumented backdoors called Akdoortea and tools such as tsunamis and Tropidoor. Slovak cybersecurity company ESET tracks activity under the name DeceptedIvedeververment, but said the campaign targets software developers for all operating systems, Windows, Linux and MacO, especially software developers involved in […]

CTEM Core: Prioritization and Verification

Despite a coordinated investment in time, effort, planning and resources, even modern cybersecurity systems continue to fail. every day. why? It’s not because the security team doesn’t look good enough. It’s exactly the opposite. All security tools spit out thousands of research findings. I’ll patch it to this. Block it. We’ll investigate this. It’s a […]