Hackers exploit Pandoc CVE-2025-51591 to target AWS IMD and steal EC2 IAM credentials

Cloud security company Wiz has revealed that it has revealed its use in the Wild security flaws of a Linux utility called Pandoc as part of an attack designed to infiltrate Amazon Web Services (AWS) instance metadata service (IMDS). The vulnerability in question is CVE-2025-51591 (CVSS score: 6.5). This refers to a server-side request forfary […]
State-sponsored hackers exploiting the Libraesva Email Security Gateway vulnerability

September 24, 2025Ravi LakshmananVulnerability/Email Security Libraesva has released a security update to address vulnerabilities in its Email Security Gateway (ESG) solution. The CVSS score for the vulnerability tracked as CVE-2025-59689 is 6.1, indicating moderate severity. “Libraesva ESG is affected by command injection flaws triggered by malicious emails containing specially created compression attachments, allowing for the […]
Two new Super Micro BMC bugs allow malicious firmware to circumvent the trust security route

September 23, 2025Ravi LakshmananFirmware security/vulnerabilities Cybersecurity researchers have revealed details of two security vulnerabilities affecting Super Micro Baseboard Management Controller (BMC) firmware that could allow attackers to bypass critical verification steps and update the system with specially created images. Both list the moderate vulnerabilities that arise from inappropriate verification of cryptographic signatures below – CVE-2025-7937 […]
Eurojust arrested 100 million euro cryptocurrency investment fraud that spans 23 countries

September 23, 2025Ravi LakshmananFinancial Crimes/Cryptocurrency European law enforcement authorities have arrested five suspects in connection with a “elaborate” online investment fraud scheme that stole more than 100 million euros from more than 100 casualties in France, Germany, Italy and Spain. According to Eurojust, the coordinated action saw searches in Italy, Romania and Bulgaria in five […]
US Secret Service seizes 300 SIM servers and threatens 100K cards

September 23, 2025Ravi LakshmananNational Security/Threat Intelligence The US Secret Service said Tuesday it had eliminated a network of electronic devices across New York’s tri-state area that was used to threaten U.S. government officials, pose an imminent threat to national security. “This protection intelligence survey has discovered over 300 co-located SIM servers and 100,000 SIM cards […]
SolarWinds releases Hotfix due to a defect in Critical CVE-2025-26399 Remote Code Execution

September 23, 2025Ravi LakshmananVulnerability/Data Security SolarWinds has released a hot fix to address critical security flaws that affect web help desk software. The vulnerability tracked as CVE-2025-26399 (CVSS score: 9.8) is described as an instance of untrusted data deintervention that could lead to code execution. It affects SolarWinds Web Help Desk 12.8.7 and all previous […]
Why CISOS must reconsider incident repair

Large companies are getting smaller and CEOs want everyone to know about it. Wells Fargo has cut its workforce by 23% in five years, Bank of America has taken 88,000 employees since 2010, and Verizon CEO has recently boasted that its staff is “always down.” What once was a sign of corporate distress has become […]
Shadowv2 Misunderstood docker container for botnet exploit dos-for-hire service

Cybersecurity researchers have revealed details of a new botnet that allows customers to rent access to carry out denial-of-service (DDO) attacks introduced against targets of interest. According to Darktrace, Shadowv2 Botnet will primarily target Docker containers misunderstood by Amazon Web Services (AWS) cloud servers, turn infected systems into attack nodes, and deploy GO-based malware that […]
Github requires 2FA and short-lived tokens to enhance NPM supply chain security

September 23, 2025Ravi LakshmananSupply Chain Attacks/Malware Github announced on Monday it will change its authentication and publishing options for the “near future” in response to a recent wave of supply chain attacks targeting the NPM ecosystem, including the Shai-Hulud attack. This includes steps to address the threat posed by token abuse and steps to allow […]
BADIIS malware spreads through SEO addiction – redirect traffic and plant webshell

September 23, 2025Ravi LakshmananSEO addiction/Malware Cybersecurity researchers are focusing on Vietnam in particular, and are turning their attention to search engine optimization (SEO) addiction campaigns that are likely undertaken by Chinese-speaking threat actors, using malware called BADIIS in attacks targeting East and Southeast Asia. An activity called Operation Rewrite is tracked by Palo Alto Networks […]