Transparent tribes target the Indian government with desktop shortcuts weaponized via phishing

August 25, 2025Ravi LakshmananMalware/Cyber ​​Attacks It has been observed that the Advanced Persistent Threat (APT) actor, known as the Transparent Tribe, is targeted both Windows and Boss (Bharat Operating System Solutions) Linux systems with malicious desktop shortcut files in attacks targeting Indian government agencies. “Initial access is achieved through spear fishing emails,” Cyfirma said. “The […]

Malicious GO modules pose as SSH brute force tool and steal credentials via Telegram bot

August 24, 2025Ravi LakshmananMalware/Supply Chain Security Cybersecurity researchers have discovered a malicious GO module that presents its status as a brute force tool for SSH, but in reality it includes the ability to carefully remove credentials from its creators. “In the first successful login, the package sends the target IP address, username and password to […]

Push Geoserver Exploits, Polarradege, Gayfemboy Push Cybercrime beyond traditional botnets

Cybersecurity researchers are bringing attention to multiple campaigns that leverage known security vulnerabilities and expose Redis servers to a variety of malicious activities. The first set of attacks involves the use of CVE-2024-36401 (CVSS score: 9.8). This is a critical remote code execution vulnerability affecting OSGEO Geoserver Geotools, which has been weaponized in cyber attacks […]

Linux malware delivered via malicious RAR filenames avoids antivirus detection

Cybersecurity researchers are using phishing email to shed light on a new attack chain that offers an open source backdoor called VShell. “Linux-specific malware infection chain starting with spam emails containing malicious RAR archive files,” Trellix researcher Sagar Bade said in a technical article. “The payload is not hidden within the file content or macros. […]

Automation is redefineing pentest delivery

August 22, 2025Hacker NewsPenetration Testing/Security Operations Pentesting is one of the most effective ways to identify real-world security weaknesses before your enemy does it. But as threatening landscapes evolve, there is no way we can bring results from our pentests. Most organizations still rely on traditional reporting methods (statistic PDFs, emailed documents, spreadsheet-based tracking). problem? […]

Interpol arrests 1,209 cybercriminals in 18 African countries in global crackdown

August 22, 2025Ravi LakshmananOnline fraud / financial crime Interpol announced Friday that authorities from 18 countries across Africa have arrested 1,209 cybercriminals targeting 88,000 casualties. “The crackdown recovers $97.4 million, dismantling 11,432 malicious infrastructure, highlighting the global scope of cybercrime and the urgent need for cross-border cooperation,” the agency said. The effort is the second […]

Chinese hacker, muddy, Genesis, Glacier panda escalates clouds and communications spying

Cybersecurity researchers are bringing attention to malicious activities organized by Chinese and Nexus cyberspy groups known as muddy pandas, which involve abuse of trustworthy relationships in the cloud and violating enterprise networks. “The enemy also demonstrates considerable ability to rapidly weaponize N-DAY and zero-day vulnerabilities, and frequently achieves initial access to targets by leveraging internet-oriented […]

A Pre-Auth Exploit chain found in Commvault could allow remote code execution attacks

August 21, 2025Ravi LakshmananVulnerabilities/Software Security Commvault has released an update to address four security gaps that can be exploited to achieve remote code execution on sensitive instances. The list of vulnerabilities identified in the Commvault version before 11.36.60 is as follows: CVE-2025-57788 (CVSS score: 6.9) – A known login mechanism vulnerability allows unauthenticated attackers to […]

Cybercriminals Deploy Cornflake.v3 Backdoor Clickfix Tactics and Fake Captcha Pages

August 21, 2025Ravi LakshmananMalware/Cryptocurrency It has been observed that threat actors who harness deceptive social engineering tactics known as Clickfix will deploy the versatile backdoor code name Cornflake.v3. Mandiant, owned by Google, described the activity it tracks as UNC5518. This is described as part of the access scheme as access as a service that uses […]