Fake Madgicx Plus and SocialMetrics extension hijacking metabusiness accounts

September 11, 2025Ravi Lakshmananmalvertising/browser security Cybersecurity researchers have disclosed two new campaigns that use malicious advertising and fake websites to serve fake browser extensions, stealing sensitive data. The per-BitDefender Malvertising campaign is designed to push a fake “meta-validation” browser extension named SocialMetrics Pro, which claims to unlock Blue Check Badge on Facebook and Instagram profiles. […]

Asyncrat exploits ConnectWise ScreenConnect to steal credentials and ciphers

September 11, 2025Ravi LakshmananMalware/Certifications Cybersecurity researchers reveal details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) software, delivering a meatless loader that drops a remote access Trojan (RAT), called Asyncrat, to steal sensitive data from a reduced-down host. “The attacker used ScreenConnect to gain remote access and ran […]

Chinese apt deploys egg stream fireless malware to infringe Philippine military systems

September 10, 2025Ravi LakshmananCybersecurity/Malware The Advanced Persistent Threat (APT) group from China is attributed to a compromise by a Philippines-based military company using a previously undocumented fies-less malware framework called Eggstreme. “This multi-stage toolset delivers sustained and modest espionage by injecting malicious code directly into memory and leveraging DLL sideloads to execute payloads,” Bitdefender researcher […]

Chillyhell Macos backdoor and Zinorrat rats threaten Macos, Windows and Linux Systems

Cybersecurity researchers have discovered two new families of malware, including a modular Apple MacOS backdoor called Chillyhell, named Zinorrat, which can target both Windows and Linux systems, and a Go-based remote access Trojan (RAT). According to an analysis by JAMF Threat Labs, Chillyhell is written in C++ and is developed for Intel Architectures. Chillyhell is […]

Microsoft fixes 80 defects – Includes SMB PrivesC and Azure CVSS 10.0 bugs

On Tuesday, Microsoft addressed a set of 80 security flaws in the software, including one vulnerability revealed to be public at the time of release. Of the 80 vulnerabilities, eight are rated as important and 72 are rated as important in severity. There are no drawbacks that are not exploited as zero-days in the wild. […]

Apple iPhone Air and iPhone 17 Function A19 Chips, Spyware-resistant Memory Safety

September 10, 2025Ravi LakshmananSpyware/Vulnerability On Tuesday, Apple unveiled a new security feature called Memory Integrity Enforcement (MIE) built into newly introduced iPhone models, including the iPhone 17 and iPhone Air. According to The Tech Giant, by designing the A19 and A19 Pro chips with this aspect in mind, Mie provides “always always memory safety” across […]

Automating VCISO and Compliance Services

introduction Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) are putting pressure on them to provide strong cybersecurity outcomes in a landscape characterized by rising threats and evolving compliance requirements. At the same time, clients want better protection without controlling cybersecurity itself. Service providers need to balance these growing demands and work efficiently, […]

New fishing kits for US and EU businesses

September 10, 2025Hacker NewsMalware Analysis/Enterprise Security The Phishing-as-a-Service (PHAAS) platform continues to evolve and offers attackers a faster, cheaper way to infiltrate corporate accounts. Now, Any.run researchers have discovered a new participant called Salty2FA, a phishing kit designed to bypass multiple two-factor authentication methods and slide beyond traditional defenses. Already discovered in US and EU […]

Adobe Commerce Flaw CVE-2025-54236 Hackers can take over customer accounts

September 10, 2025Ravi LakshmananVulnerabilities/Software Security Adobe has warned of critical security flaws in its commercial and Magento’s open source platform, allowing attackers to control customer accounts. The vulnerability tracked as CVE-2025-54236 (aka SessionReaper) carries a CVSS score of up to 9.1 out of 10.0. It is described as a defect in inappropriate input verification. Adobe […]