Google Patch Chrome Zero-Day CVE-2025-10585 Active V8 Exploits Threate Millions

September 18, 2025Ravi LakshmananVulnerability/Browser Security On Wednesday, Google will release a security update for its Chrome web browser to address four vulnerabilities. The zero-day vulnerability in question is CVE-2025-10585, which is described as a confusion problem with the type of V8 JavaScript and WebAssembly engine. Type confusion vulnerabilities can have serious consequences as they can […]
TA558 deploys Venom Rat to Brazilian hotel attacks using AI-generated scripts

The threat actor, known as the TA558, is attributed to a new set of attacks that offer a variety of remote access trojans (rats), such as Venom Rat, to beat hotels in Brazil and Spanish-speaking markets. Russian cybersecurity vendor Kaspersky will track the activities observed in the summer of 2025 and track them as Revengehotels. […]
China’s TA415 spies US economic policy experts using counter-code remote tunnels

September 17, 2025Ravi LakshmananCyber Spy/Malware The China Alliance threat actor, known as the TA415, is attributed to a spear fishing campaign aimed at US governments, think tanks, and academic organizations that use US economy-themed lures. “In this activity, the group served as the current chair of the Select Committee on Strategic Competition between the US […]
From quantum hacks to AI defense – an expert guide to building unbreakable cyber resilience

September 17, 2025Hacker NewsCyber Resilience/Webinar The working together with quantum computing and AI presents incredible opportunities. Together, this technology will help us scale innovation faster than ever. But imagine a flipside, hackers use quantum computers to crack company encryption overnight, exposing the most sensitive data, making it impossible to trust many of them. And when […]
Rethinking AI Data Security: A Buyer’s Guide

September 17, 2025Hacker NewsAI Security/Shadowinch Generating AI has become the foundation of corporate productivity in just a few years, curiosity. From copilots embedded in office suites to dedicated, large-scale language model (LLM) platforms, employees rely on these tools to determine coding, analysis, drafting, and decisions. However, for CISOs and security architects, the speed of adoption […]
Resurfacement of scattered spiders with financial sector attacks despite resignation claims

September 17, 2025Ravi LakshmananThreat Intelligence/Cybercrime Cybersecurity researchers have questioned the claims of “darkness” by tying new cyberattacks targeting financial services to the infamous cybercriminal group known as scattered spiders. Threat Intelligence Firm ReliaQuest said there have been indications that threat actors have shifted their focus to the financial sector. This is supported by an increase […]
Founder of DOJ Resentences Breachforums is a three-year founder for cybercrime and possession of CSAM

September 17, 2025Ravi LakshmananData Breach/Cybercrime The U.S. Department of Justice (DOJ) on Tuesday humiliated a former administrator of a three-year prison violation in connection with his role in running the Cybercrime Forum and owning Child Sexual Abuse Materials (CSAM). Conor Brian Fitzpatrick, 22, of Peakskill, New York, (aka Ponpamplin), pleaded guilty to one count of […]
RACCOONO365 Phishing Network is dismantled as Microsoft, CloudFlare defeats 338 domains

Microsoft’s Digital Crimes Unit said it has coordinated the seizure of 338 domains used by RACCOONO365, a financially motivated threat group that has been used since July 2024 to steal more than 5,000 Microsoft 365 qualifications from 94 countries. “Using a court order granted by the Southern District of New York, the DCU seized 338 […]
Chaos mesh critical graphical defects enable takeover of RCE and Fruc Bernate clusters

September 16, 2025Ravi LakshmananVulnerability/Cloud Security Cybersecurity researchers have uncovered multiple critical security vulnerabilities in the chaos mesh, which, if exploited successfully, could lead to cluster takeovers in the Kubernetes environment. “Attackers must exploit these vulnerabilities and minimize network access within the cluster to perform more malicious actions, such as platform failure injections (such as pod […]
Slopads Shrink Ring exploits 224 Android apps to drive 2.3 billion ad bids every day

September 16, 2025Ravi LakshmananAdvertising fraud / Mobile security Called massive ad fraud and click fraud operations, Slopads ran a cluster of 224 apps, attracting 308 million downloads in 228 countries and regions. “These apps use steganography to provide fraud payloads, create hidden web views, navigate to threaten actor-owned cash out sites, and generate impressions and […]