Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More

Sep 25, 2025Ravie LakshmananCybersecurity / Hacking News Welcome to this week’s Threatsday Bulletin—your Thursday check-in on the latest twists and turns in cybersecurity and hacking. The digital threat landscape never stands still. One week it’s a critical zero-day, the next it’s a wave of phishing lures or a state-backed disinformation push. Each headline is a […]

Malicious Rusty Crate Steals Solana and Ethereum Keys – 8,424 Downloads confirmed

September 25, 2025Ravi LakshmananSoftware Security/Malware Cybersecurity researchers have discovered two malicious rusty crates that are impersonating a legal library called fast_log to steal Solana and Ethereum wallet keys from the source code. The crates named Faster_log and async_println were published by threat actors under the alias Rustguruman, according to software supply chain security company Socket, […]

Cisco warns that it is actively exploiting SNMP vulnerabilities that allow RCE or DOS in iOS software

September 25, 2025Ravi LakshmananVulnerability/Network Security Cisco warns of advanced security flaws in iOS and iOS XE software that allow remote attackers to execute arbitrary code under certain circumstances or trigger denial of service (DOS) conditions. The company added that the vulnerability, CVE-2025-20352 (CVSS score: 7.7), has been utilized in the wild, and has been noticed […]

China’s hacker red noveler target global government using pantegana and cobalt strike

September 24, 2025Ravi LakshmananVulnerability/Network Security The suspected cyberespionage cluster, previously discovered to target global government and private sector organizations across Africa, Asia, North America, South America and Oceania, is rated as a state-sponsored threat actor. Recorded Future, who was tracking activities under the Moniker Tag-100, graduated to a hacking group called Rednovember. It is also […]

Two important defects revealed in Wondershare Repaid and reveals user data and AI models

Cybersecurity researchers have disclosed two security flaws in Wondershare Repaist that could expose private user data and potentially expose systems to artificial intelligence (AI) tampering and supply chain risks. The vulnerabilities in critical assessment of issues discovered by Trend Micro are listed below – CVE-2025-10643 (CVSS score: 9.1) – Authentication bypass vulnerability present within permissions […]

How one bad password ended business 158 years ago

Most businesses aren’t past their fifth birthday – research shows that around 50% of small businesses failed within the first five years. Therefore, when the KNP Logistics Group (formerly Night of Old) celebrated its operations for over a century and a half, it was mastering the art of survival. For 158 years, the KNP has […]

The new Yibackdoor malware shares major code duplication with IcedID and Latrodectus

September 24, 2025Ravi LakshmananMalware/Windows Security Cybersecurity researchers have revealed details about a new family of malware called eyebackdoors, and have found that “critical” source code overlaps with Iced and Latrodectus. “The exact connection to Yibackdoor is not yet clear, but it can be used in conjunction with Latrodectus or IcedID during an attack,” Zscaler Threatlabz […]

Death Spots Promote Payment Skimmer Attacks

Do you think payment iframes are safe by design? Think about it again. The sophisticated attacker has quietly evolved malicious overlay techniques by exploiting checkout pages and bypassing the very security policy designed to steal credit card data. Download the complete IFRAME security guide here. TL;DR: IFRAME Security Release Payment IFRAME is actively exploited by […]