SonicWall SSL VPN flaws and false obscurity are being actively exploited by Akira Ransomware hackers

Threat actors belonging to Akira Ransomware Group continue to target Sonicwall devices for initial access. Cybersecurity company Rapid7 said it observed following a surge in intrusions involving Sonicwall appliances over the past month, particularly reports on updated Akira ransomware activity since late July 2025. SonicWall then revealed that SSL VPN activity targeting the firewall was […]
Fake Madgicx Plus and SocialMetrics extension hijacking metabusiness accounts

September 11, 2025Ravi Lakshmananmalvertising/browser security Cybersecurity researchers have disclosed two new campaigns that use malicious advertising and fake websites to serve fake browser extensions, stealing sensitive data. The per-BitDefender Malvertising campaign is designed to push a fake “meta-validation” browser extension named SocialMetrics Pro, which claims to unlock Blue Check Badge on Facebook and Instagram profiles. […]
Asyncrat exploits ConnectWise ScreenConnect to steal credentials and ciphers

September 11, 2025Ravi LakshmananMalware/Certifications Cybersecurity researchers reveal details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) software, delivering a meatless loader that drops a remote access Trojan (RAT), called Asyncrat, to steal sensitive data from a reduced-down host. “The attacker used ScreenConnect to gain remote access and ran […]
Chinese apt deploys egg stream fireless malware to infringe Philippine military systems

September 10, 2025Ravi LakshmananCybersecurity/Malware The Advanced Persistent Threat (APT) group from China is attributed to a compromise by a Philippines-based military company using a previously undocumented fies-less malware framework called Eggstreme. “This multi-stage toolset delivers sustained and modest espionage by injecting malicious code directly into memory and leveraging DLL sideloads to execute payloads,” Bitdefender researcher […]
Chillyhell Macos backdoor and Zinorrat rats threaten Macos, Windows and Linux Systems

Cybersecurity researchers have discovered two new families of malware, including a modular Apple MacOS backdoor called Chillyhell, named Zinorrat, which can target both Windows and Linux systems, and a Go-based remote access Trojan (RAT). According to an analysis by JAMF Threat Labs, Chillyhell is written in C++ and is developed for Intel Architectures. Chillyhell is […]
Microsoft fixes 80 defects – Includes SMB PrivesC and Azure CVSS 10.0 bugs

On Tuesday, Microsoft addressed a set of 80 security flaws in the software, including one vulnerability revealed to be public at the time of release. Of the 80 vulnerabilities, eight are rated as important and 72 are rated as important in severity. There are no drawbacks that are not exploited as zero-days in the wild. […]
Apple iPhone Air and iPhone 17 Function A19 Chips, Spyware-resistant Memory Safety

September 10, 2025Ravi LakshmananSpyware/Vulnerability On Tuesday, Apple unveiled a new security feature called Memory Integrity Enforcement (MIE) built into newly introduced iPhone models, including the iPhone 17 and iPhone Air. According to The Tech Giant, by designing the A19 and A19 Pro chips with this aspect in mind, Mie provides “always always memory safety” across […]
Automating VCISO and Compliance Services

introduction Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) are putting pressure on them to provide strong cybersecurity outcomes in a landscape characterized by rising threats and evolving compliance requirements. At the same time, clients want better protection without controlling cybersecurity itself. Service providers need to balance these growing demands and work efficiently, […]
New fishing kits for US and EU businesses

September 10, 2025Hacker NewsMalware Analysis/Enterprise Security The Phishing-as-a-Service (PHAAS) platform continues to evolve and offers attackers a faster, cheaper way to infiltrate corporate accounts. Now, Any.run researchers have discovered a new participant called Salty2FA, a phishing kit designed to bypass multiple two-factor authentication methods and slide beyond traditional defenses. Already discovered in US and EU […]
Adobe Commerce Flaw CVE-2025-54236 Hackers can take over customer accounts

September 10, 2025Ravi LakshmananVulnerabilities/Software Security Adobe has warned of critical security flaws in its commercial and Magento’s open source platform, allowing attackers to control customer accounts. The vulnerability tracked as CVE-2025-54236 (aka SessionReaper) carries a CVSS score of up to 9.1 out of 10.0. It is described as a defect in inappropriate input verification. Adobe […]