CloudFlare blocks record-breaking 11.5 TBPS DDOS attacks

September 3, 2025Ravi LakshmananThreat Intelligence/Network Security CloudFlare said Tuesday it automatically mitigates record-breaking volume distributed denial-of-service (DDOS) attacks, which peaked at 11.5 terabits per second (TBPS). “Over the past few weeks, we have autonomously blocked hundreds of ultrasound DDOS attacks reaching their peak peaks of 5.1 BPPS and 11.5 TBP. The entire attack lasted only […]

CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation

September 3, 2025Ravi LakshmananVulnerability/Mobile Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday affected the TP-Link TL-WA855RE Wi-Fi Ranger Extender product, affected the known exploitation catalogue, and cited evidence of active exploitation. The vulnerability, CVE-2020-24363 (CVSS score: 8.8) is related to cases where authentication is missing that could be abused to gain increased […]

SalesLoft takes drift offline after OAUTH token theft hits hundreds of organizations

September 3, 2025Ravi LakshmananData Breach/Threat Intelligence, SalesLoft on Tuesday announced that several companies will be temporarily collecting drifts offline in the “very near future” as they are caught up in a widespread supply chain attack targeting marketing software as a service, resulting in mass theft of certified tokens. “This provides the fastest path to comprehensively […]

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

September 2, 2025Ravi LakshmananMalware/Threat Intelligence North Korea-related threat actors known as the Lazarus Group are attributed to a social engineering campaign that distributes three different cross-platform malware, known as Pondrat, Themeforestrat and Remotepe. The attack observed by NCC Group’s Fox-IT in 2024 targeted organizations in the distributed finance (DEFI) sector, ultimately leading to compromises in […]

Researchers warning MyStrodx backdoor using DNS and ICMP triggers for Stealthy Control

September 2, 2025Ravi LakshmananCyberspy/Network Security Cybersecurity researchers have revealed a new stealthy backdoor called MyStrodx. It comes with a variety of features to capture sensitive data from compromised systems. “MyStrodx is a typical backdoor implemented in C++ and supports features like file management, port forwarding, reverse shell, socket management, and more,” Qianxin XLAB said in […]

An important part of enterprise AI governance

September 2, 2025Hacker NewsData Privacy / SaaS Security The harsh truth about AI adoption The MITS State of Business Report revealed that 40% of organizations purchase enterprise LLM subscriptions, while over 90% of employees actively use AI tools in their daily operations. Similarly, a Harmonic Security study found that 45.4% of sensitive AI interactions come […]

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

Cybersecurity researchers have flagged Ukrainian IP networks to engage in a massive brute force and password spray campaign targeting SSL VPNs and RDP devices from June to July 2025. This activity stemmed from the Ukraine-based autonomous system FDN3 (AS211736), each French cybersecurity company Intrinsec. “We believe FDN3 is part of a wider abusive infrastructure consisting […]

Silver Fox Exploit Microsoft Signature Watchdog Driver Deploys ValleyRat Malware

A threat actor known as Silver Fox is attributed to the abuse of previously unknown vulnerable drivers associated with Watchdog Anti-Malware as part of your own Vulnerable Driver (BYOVD) attacks aimed at disarming security solutions installed on compromised hosts. The vulnerable driver in question is “AMSDK.SYS” (version 1.0.600), a valid, 64-bit signed Windows kernel device […]

Malicious NPM Package nodejs-smtp mimic nodemailer, target atomic and exodus wallet

September 2, 2025Ravi LakshmananCryptocurrency/Malware Cybersecurity researchers have discovered a malicious NPM package with stealth capabilities to inject malicious code into desktop apps for cryptocurrency wallets such as Atomic and Exodus on Windows systems. A package named NodeJS-SMTP disguises legitimate email library node mail with the same catchphrase, page styling and README descriptions, and has collected […]

Android droppers now offer SMS steelers and spyware as well as banking Trojans

September 1, 2025Ravi LakshmananMobile Security/Malvercis Cybersecurity researchers have turned their attention to a new shift in Dropper apps, which are typically used to deliver bank Trojans, to distribute simpler malware, such as SMS steelers and basic spyware. These campaigns are being propagated through Dropper apps disguised as government or banking apps in India and other […]