GPUGATE malware uses Google ads and fake Github commits to target IT companies

September 8th, 2025Ravi LakshmananAggravated/Encrypted Cybersecurity researchers detail new sophisticated malware campaigns that leverage paid advertising in search engines such as Google to provide malware to unsuspecting users looking for popular tools such as GITHUB desktops. Malvertising campaigns have become common in recent years, but the latest activities have given them a bit of a twist […]

Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & More

Cybersecurity never slows down. Every week brings new threats, new vulnerabilities, and new lessons for defenders. For security and IT teams, the challenge is not just keeping up with the news—it’s knowing which risks matter most right now. That’s what this digest is here for: a clear, simple briefing to help you focus where it […]

You weren’t phished – you carried an attacker

When Attackers Are Hired: Today’s New Identity Crisis What if the star engineer you just hired is actually an attacker in disguise, not an employee? This is not phishing. It is penetration through onboarding. Meet “Jordan, Colorado” with a strong resume, persuasive references, a clean background check, and a digital footprint to check out. On […]

Noisy Bear targets Kazakhstan energy sector with its Barrelfire Phishing campaign

The threat actors of Russian origin probably stem from a new set of attacks targeting Kazakhstan’s energy sector. The activity, known as the codename for Operation Barrelfire, is tied to a new threat group that Seqrite Labs tracks as a noisy bear. Threat actors have been active since at least April 2025. “The campaign is […]

Malicious NPM packages spoof as flashbots and steal Ethereum wallet keys

September 6, 2025Ravi LakshmananSoftware Security/Cryptocurrency In the NPM package registry, a new set of four malicious packages has been discovered with the ability to steal Cryptocurrency Wallet credentials from Ethereum Developers. “The package secretly removes private keys and mnemonic seeds to telegram bots controlled by threat actors, while exaggerating legal encryption utilities and flashbot MEV […]

CISA orders immediate patches of critical Sitecore vulnerabilities under aggressive exploitation

The Federal Civil Enforcement Division (FCEB) agency is advised to update its Sitecore instances by September 25, 2025. The vulnerability tracked as CVE-2025-53690 features a CVSS score of up to 9.0 out of 10.0, indicating critical severity. “Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain de-iralization of untrusted data […]

Tag-150 develops Castle Rats in Python and C, expanding Castle Loader malware operations

The Malware-as-a-Service (MAAS) framework and the threat actor behind the loader known as CastleLoader have also developed a remote access trojan known as Castlerat. “The core features of Castlerat available in both Python and C variants consist of collecting system information, downloading and running additional payloads, and running commands via CMD and Powershell,” says a […]

SAP S/4HANA Critical Vulnerability CVE-2025-42957 was exploited in the wild

September 5th, 2025Ravi LakshmananVulnerability/Enterprise Security Critical security vulnerabilities affecting SAP S/4HANA, the Enterprise Resource Planning (ERP) software, are subject to active exploitation in the wild. Tracked Command Injection Vulnerability CVE-2025-42957 (CVSS score: 9.9) was revised by SAP as part of last month’s monthly update. “SAP S/4HANA allows user privileged attackers to take advantage of vulnerabilities […]

Automation is redefineing pentest delivery

September 5th, 2025Hacker NewsPentest/Security Operations Pentesting is one of the most effective ways to identify real-world security weaknesses before your enemy does it. But as threatening landscapes evolve, there is no way we can bring results from our pentests. Most organizations still rely on traditional reporting methods (statistic PDFs, emailed documents, spreadsheet-based tracking). problem? These […]

Virustotal finds 44 undetected SVG files used to deploy base64 encoded phishing pages

September 5th, 2025Ravi LakshmananMalware/Cryptocurrency Cybersecurity researchers are flagging new malware campaigns that leverage scalable vector graphics (SVG) files as part of a phishing attack that impersonates the Colombian judicial system. According to Virustotal, SVG files are distributed via email and designed to run embedded JavaScript payloads. This will embellish the Base64-encoded HTML phishing page as […]