The new filefix variant delivers stealc malware through multilingual phishing sites

September 16, 2025Ravi LakshmananMalware/Social Engineering Cybersecurity researchers are warning about new campaigns that are leveraging variants of FileFix social engineering tactics to provide STEALC information steeler malware. “The observed campaign uses highly compelling multilingual phishing sites (e.g., fake Facebook security pages) and avoid detection with anti-analytics technology and advanced obfuscation,” Acronis security researcher Eliad Kimhy […]
Apple backport fix for CVE-2025-43300 exploited in sophisticated spyware attacks

September 16, 2025Ravi LakshmananVulnerability/Spyware On Monday, Apple confirmed the fix to a recently patched security flaw that is actively utilised in the wild. The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8). This is an out-of-range issue with Imageio components that can lead to memory corruption when processing malicious image files. “Apple is aware of […]
Introducing the AI Agent Control Plane from Astrix

September 16, 2025Hacker NewsAI Security/Enterprise Security AI agents are rapidly becoming a core part of the enterprise, embedded throughout the enterprise workflow, autonomous and deciding which systems to access and what systems to use. But so are risk and threats as agents grow in power and autonomy. Recent research shows that 80% of companies already […]
Phoenix Rowhammer Attack bypasses advanced DDR5 memory protection in 109 seconds

September 16, 2025Ravi LakshmananHardware security/vulnerabilities A team of scholars from EthZürich and Google have discovered a new variant of the Rowhammer attack targeting the double data rate 5 (DDR5) memory chips of Korean semiconductor vendor SK Hynix. The Rowhammer Attack Variant, known as the codename Phoenix (CVE-2025-6202, CVSS score: 7.1), can bypass advanced protective mechanisms […]
40 npm packages compromised in supply chain attacks using bundle.js steal credentials

September 16, 2025Ravi LakshmananMalware/Cyber Attacks Cybersecurity researchers have flagged fresh software supply chain attacks targeting NPM registry that affected more than 40 packages belonging to multiple maintainers. “The compromised version includes a function (npmmodule.updatePackage) that downloads the package’s talball, changes the package, injects local scripts (bundle.js), reissue the archive, reissue, and enable automatic trojunization of […]
Mustang Panda deploys snakedisk usb worms to deliver a Yukkuri backdoor on Thai IPS

September 15th, 2025Ravi LakshmananMalware/Network Security It has been observed that the Chinese threat actor known as the Mustang Pandas have called updated versions of the backdoor called Toneshell and previously undocumented USB worms Snakedisk. “The worm runs only on devices with IP addresses based in Thailand and drops yokai backdoors,” IBM X-Force researchers GoloMühr and […]
Six browser-based attack security teams need to prepare now

In recent years, attacks targeting web browser users have seen an unprecedented increase. In this article, we explore what “browser-based attacks” are and why they have been proven to be extremely effective. What is a browser-based attack? First, it is important to establish what a browser-based attack is. In most scenarios, attackers do not consider […]
Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

Sep 15, 2025Ravie LakshmananCybersecurity / Hacking News In a world where threats are persistent, the modern CISO’s real job isn’t just to secure technology—it’s to preserve institutional trust and ensure business continuity. This week, we saw a clear pattern: adversaries are targeting the complex relationships that hold businesses together, from supply chains to strategic partnerships. […]
AI-powered Villager Pen Testing Tool hits 11,000 Pypi downloads amid abuse concerns

The new artificial intelligence (AI)-powered penetration testing tool linked to the China-based company has collected nearly 11,000 downloads in the Python Package Index (PYPI) repository, raising concerns that it could be reused by Cyber Criminal for malicious purposes. The framework, called Villager, is rated as Cyberspike’s work, deploying The Turss as a red teaming solution […]
HiddenGh0st, Winos and Kkrat Exploit SEO, github page for Chinese malware attacks

Chinese-speaking users are the target of search engine optimization (SEO) addiction campaigns that use fake software sites to distribute malware. “The attackers manipulated search rankings with domains for registered looks that closely mimic SEO plugins and legitimate software sites,” said Pei Han Liao, a researcher at Fortinet Fortiguard Labs. “By using persuasive language and small […]