WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More

Cybersecurity today is less about single attacks and more about chains of small weaknesses that connect into big risks. One overlooked update, one misused account, or one hidden tool in the wrong hands can be enough to open the door. The news this week shows how attackers are mixing methods—combining stolen access, unpatched software, and […]
Rethinking the security of scattered spiders

As businesses continue to move operations to their browsers, security teams face ever-growing cyber challenges. In fact, over 80% of security incidents come from web applications accessed through Chrome, Edge, Firefox, and other browsers. One of the scattered spiders, an especially evolving enemy, has fulfilled its mission to wreaking havoc for businesses by specifically targeting […]
Scarcruft uses Rokrat malware in Hankook Phantom manipulation targeting Korean scholars

Cybersecurity researchers have discovered a new phishing campaign run by a North Korean hacking group called Scarcruft (also known as APT37) to provide malware known as Rokrat. The activity has been called Operation Hankook Phantom by Seqrite Labs, and says the attack appears to be targeted at individuals associated with the National Intelligence Research Association, […]
Attackers abuse Velociraptor’s forensic tools for deploying Visual Studio code for C2 tunneling

Cybersecurity researchers have drawn attention to cyberattacks in which unknown threat actors deploy open source endpoint monitoring and digital forensic tools called velociraptor, demonstrating the ongoing abuse of legal software for malicious purposes. “In this incident, the threat actor used the tool to download and run Visual Studio code that could create tunnels on an […]
Whatsapp Issues Zero-Click Exploit Emergency Updates iOS and Macos Device Targeting

August 30, 2025Ravi LakshmananZero Day/Vulnerability WhatsApp addresses security vulnerabilities in messaging apps on Apple iOS and MacO, and could have been exploited in the wild along with the recently disclosed Apple flaws in a targeted zero-day attack. The vulnerability, CVE-2025-55177 (CVSS score: 8.0), is related to insufficient approval of linked device sync messages. It is […]
Whatsapp Issues Zero-Click Exploit Emergency Updates iOS and Macos Device Targeting

August 30, 2025Ravi LakshmananZero Day/Vulnerability WhatsApp addresses security vulnerabilities in messaging apps on Apple iOS and MacO, and could have been exploited in the wild along with the recently disclosed Apple flaws in a targeted zero-day attack. The vulnerability, CVE-2025-55177 (CVSS score: 8.0), is related to insufficient approval of linked device sync messages. It is […]
Researchers warn Sitecore exploit chain linking cache addiction and remote code execution

August 29, 2025Ravi LakshmananVulnerability / Web Security The Sitecore Experience platform discloses three new security vulnerabilities that will be utilized to enable disclosure and remote code execution. The defects per Watchtowr Labs are listed below – CVE-2025-53693-HTML Cache Poisoning with HTML Insecure Reflection CVE-2025-53691-Remote Code Execution (RCE). The first two shortcoming patches were released by […]
Amazon abuses APT29 watering campaign Abuses Microsoft device code authentication

August 29, 2025Ravi LakshmananThreat Intelligence/Malware On Friday, Amazon said it had flagged and confused what it described as an opportunistic waterhole campaign organized by the Russian-linked APT29 actor as part of its intelligence gathering efforts. The campaign is “designed to use compromised websites to redirect visitors to malicious infrastructure, and trick users into approving attacker-controlled […]
Abandoned Sogou Zhuyin Update Server Hijacking, weaponized campaign in the Thai One Spy Campaign

The abandoned update server associated with the Input Method Editor (IME) software Sogou Zhuyin was primarily used by threat actors as part of a spy campaign that provided several malware families, including C6DOOR and GTELAM, mainly targeting users in East Asia. “Attackers used sophisticated infection chains such as hijacked software updates and fake cloud storage […]
Can your security stack see chatgpt? Why network visibility is important

August 29, 2025Hacker NewsEnterprise Security/Artificial Intelligence Generation AI platforms such as ChatGpt, Gemini, Copilot, and Claude are becoming more and more common in organizations. These solutions improve overall task efficiency, but also present new data leak prevention against generative AI challenges. Sensitive information can be shared via chat prompts, files uploaded for AI-driven summaries, or […]