FORTRA releases critical patches for CVSS 10.0 GOANY WHERE MFT Vulnerability

September 19, 2025Ravi LakshmananVulnerability/Threat Intelligence FORTRA has revealed details of key security flaws in GoAny Where Managed File Transfer (MFT) software that can result in the execution of any command. The vulnerability tracked as CVE-2025-10035 has a CVSS score of 10.0, indicating the greatest severity. “A decolorization vulnerability in Fortra’s Goany Where MFT license servlet […]
17,500 phishing domains target 316 brands in 74 countries worldwide for PHAAS surges

Phishing As-a-Service (PHAAS), known as Lighthouse and Lucid, is linked to over 17,500 phishing domains covering 316 brands from 74 countries. “The deployment of Phishing Ash Services (PHAAS) has been rising significantly recently,” Netcraft said in a new report. “PHAAS operators will charge you a monthly fee for phishing software with pre-installed templates. Lucid was […]
How to use Tines to automate alert triage with AI agents and confluence SOPS

September 19, 2025Hacker NewsAI Automation/Security Operations Run by teams on workflow orchestration and AI platform Tines, the Tines library features over 1,000 pre-built workflows shared by security practitioners from across the community. Our emphasis on workflows streamline security alert processing by automatically identifying and executing the appropriate standard operating procedures (SOPs) from Confluence. When an […]
Russian hackers Gamaredon and Turla are working together to deploy Kazuar Backdoor in Ukraine

Cybersecurity researchers have identified evidence that two Russian hacking groups Gamaredon and Turla work together to target and collaborate with Ukrainian groups. Slovak Cybersecurity Company ESET said that in February 2025 the Gamaredon Tools Pterographin and Pteroodd, which are used to run the Kazuar Backdoor of Turla Group on Ukrainian endpoints, were observed. “Pterographin was […]
UK arrests two teen scattered spider hackers linked in August 2024 TFL Cyber Attack

September 19, 2025Ravi LakshmananRansomware/Cybercrime UK law enforcement has arrested two teenage members of a scattered spider-hacking group in connection with alleged participation in an August 2024 cyberattack targeting London Transport (TFL), the city’s public transport system. Thalha Jubair (aka Earthtostar, Brad, Austin, and @Autistic), 19, Owen Floses, 18, of Walsall, West Midlands, was arrested Tuesday […]
CISA warns two malware strains that utilize Ivanti EPMM CVE-2025-4427 and CVE-2025-4428

September 19, 2025Ravi LakshmananData Breaches/Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) released details on two malware discovered in the network of unknown organizations following the exploitation of security flaws in Ivanti Endpoint Manager Mobile (EPMM). “Each set includes loaders for malicious listeners that allow cyberthreat actors to execute arbitrary code on compromised servers,” […]
SonicWall prompts password reset after a cloud backup violation affecting less than 5% of customers

September 18, 2025Ravi LakshmananData Breaches/Network Security SonicWall urges customers to reset their credentials after the firewall configuration backup files are exposed in a security breaches affecting MySonicWall accounts. The company said that suspicious activity targeting the firewall’s cloud backup service was recently detected, with unknown threat actors accessing backup firewall priority files stored in the […]
Countloader uses multiversion malware loader to broaden Russian ransomware operations

Cybersecurity researchers have discovered a code-named countloader called the new malware loader used by Russian ransomware gangs to provide post-explosion tools such as Cobalt Strike and AdaptixC2 and remote access trojans known as PureHVNC rats. “Countloader is used as part of the Initial Access Broker (IAB) toolset or by ransomware affiliates with ties to Lockbit, […]
Silentsync rats are delivered via two malicious Pypi packages targeting Python developers

September 18, 2025Ravi LakshmananMalware/Supply Chain Attacks Cybersecurity researchers have discovered two new malicious packages in the Python Package Index (PYPI) repository that are designed to provide a remote access trojan called SilentsYnc in Windows Systems. “Silentsync allows you to execute remote commands, remove files, and screen capture,” said Manisha Ramcharan Prajapati and Satyam Singh of […]
How CISOS drives effective AI governance

The growing role of AI in enterprise environments has increased the urgency for the Chief Information Security Officer (CISO) to promote effective AI governance. When it comes to new technologies, governance is difficult, but effective governance is even more difficult. For most organizations, the first instinct is to respond with strict policies. We hope that […]