Russia’s APT28 launches “NotDoor” Outlook backdoor for companies in NATO countries

September 4, 2025Ravi LakshmananCybersecurity/Malware The Russian state-sponsored hacking group tracked as APT28 is attributed to a new Microsoft Outlook Backdoor called NotDoor, an attack targeting multiple companies in various sectors of NATO member countries. According to S2 Grupo’s Lab52 Threat Intelligence team, NotDoor is an Outlook VBA macro designed to monitor incoming emails with specific […]

Using the GhoStredirector Hacks 65 Windows Server Rungan Backdoor and Gamshen IIS Module

Cybersecurity researchers have lifted the lid of a previously undocumented threat cluster called Ghostredirector, which compromised at least 65 Windows servers, mainly in Brazil, Thailand and Vietnam. An attack by Slovak cybersecurity company ESET led to the deployment of a passive C++ backdoor called Rungan and a Native Internet Information Services (IIS) module CodeNead Gamshen. […]

Cybercriminals exploit X’s Grok AI to bypass advertising protection and spread malware to millions

September 4, 2025Ravi LakshmananArtificial Intelligence/Malware Cybersecurity researchers are flagging new techniques cybercriminals have adopted to bypass fraud protection on social media platform X and use Artificial Intelligence (AI) Assistant Grok to propagate malicious links. The findings were highlighted by Nati Tal, Head of Guardio Labs, in a series of posts on X. This technique is […]

Google has fined $379 million from French regulators for breach of cookie consent

September 4, 2025Ravi LakshmananGDPR/Data Privacy The French Data Protection Agency fined Google and Chinese e-commerce giant Shein to $379 million (Euro 325 million) and $175 million (Euro 150 million) respectively for violating cookie rules. Without ensuring consent, the companies have set ad cookies on users’ browsers, the National Committee on Informatics and Freedom (CNIL) said. […]

CISA Flags TP-Link Router Defects CVE-2023-50224 and CVE-2025-9377

September 4, 2025Ravi LakshmananVulnerability/Network Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws that affect TP-link wireless routers to its known Exploited Vulnerabilities (KEV) catalogue, noting that there is evidence that they are being exploited in the wild. The vulnerabilities in question are listed below – CVE-2023-50224 (CVSS score: […]

Malicious NPM packages are misused by crypto developers targeting Ethereum smart contracts

September 3, 2025Ravi LakshmananMalware/Social Engineering Cybersecurity researchers have discovered two new malicious packages on the NPM registry. This shows that it uses smart contracts from the Ethereum blockchain to perform malicious actions on compromised systems, distribute malware with constant vision for threat action trends, and fly under radar. “The two NPM packages abuse smart contracts […]

Threat actor weaponizes Hexstrike AI to exploit Citrix’s flaws within a week of disclosure

September 3, 2025Ravi LakshmananArtificial Intelligence/Vulnerability Threat actors are leveraging newly released artificial intelligence (AI) attack security tools to leverage recently disclosed security flaws. Hexstrike AI is pitched as an AI-driven security platform for automating reconnaissance and vulnerability discovery, with the aim of acquiring licensed red teaming operations, bug bounty hunting and flag (CTF) challenges, according […]

Data leaks before a disaster

In January 2025, cybersecurity experts at WIZ Research discovered that Chinese AI expert DeepSeek was suffering from data leaks, putting more than a million sensitive log streams at risk. According to the Wiz Research team, they have identified a publicable Clickhouse database belonging to DeepSeek. This “gives complete control over database operations, including the ability […]

Google Patch 120 defect. This includes two zero days during attack

September 3, 2025Ravi LakshmananMobile Security/Vulnerability As part of the monthly fixes for September 2025, Google has sent out a security update to address 120 security flaws in the Android operating system. The vulnerabilities are listed below – CVE-2025-38352 (CVSS score: 7.4) – Privilege escalation flaw in Linux kernel component CVE-2025-48543 (CVSS score: N/A) – Privilege […]

Iranian hackers misuse email accounts of over 100 embassies in global phishing targeting diplomats

September 3, 2025Ravi LakshmananData Breach/Cyberspy The Iranian and Nexus groups are linked to “coordinated” and “multiwave” spear fishing campaigns targeting embassies and consulates in Europe and other regions around the world. The activity stems from operators lined with Iranians associated with the broader range of offensive cyber activities carried out by a group known as […]