Transparent tribes target the Indian government with desktop shortcuts weaponized via phishing
August 25, 2025Ravi LakshmananMalware/Cyber Attacks It has been observed that the Advanced Persistent Threat (APT) actor, known as the Transparent Tribe, is targeted both Windows and Boss (Bharat Operating System Solutions) Linux systems with malicious desktop shortcut files in attacks targeting Indian government agencies. “Initial access is achieved through spear fishing emails,” Cyfirma said. “The […]
Malicious GO modules pose as SSH brute force tool and steal credentials via Telegram bot

August 24, 2025Ravi LakshmananMalware/Supply Chain Security Cybersecurity researchers have discovered a malicious GO module that presents its status as a brute force tool for SSH, but in reality it includes the ability to carefully remove credentials from its creators. “In the first successful login, the package sends the target IP address, username and password to […]
Push Geoserver Exploits, Polarradege, Gayfemboy Push Cybercrime beyond traditional botnets

Cybersecurity researchers are bringing attention to multiple campaigns that leverage known security vulnerabilities and expose Redis servers to a variety of malicious activities. The first set of attacks involves the use of CVE-2024-36401 (CVSS score: 9.8). This is a critical remote code execution vulnerability affecting OSGEO Geoserver Geotools, which has been weaponized in cyber attacks […]
Linux malware delivered via malicious RAR filenames avoids antivirus detection

Cybersecurity researchers are using phishing email to shed light on a new attack chain that offers an open source backdoor called VShell. “Linux-specific malware infection chain starting with spam emails containing malicious RAR archive files,” Trellix researcher Sagar Bade said in a technical article. “The payload is not hidden within the file content or macros. […]
Automation is redefineing pentest delivery

August 22, 2025Hacker NewsPenetration Testing/Security Operations Pentesting is one of the most effective ways to identify real-world security weaknesses before your enemy does it. But as threatening landscapes evolve, there is no way we can bring results from our pentests. Most organizations still rely on traditional reporting methods (statistic PDFs, emailed documents, spreadsheet-based tracking). problem? […]
Interpol arrests 1,209 cybercriminals in 18 African countries in global crackdown

August 22, 2025Ravi LakshmananOnline fraud / financial crime Interpol announced Friday that authorities from 18 countries across Africa have arrested 1,209 cybercriminals targeting 88,000 casualties. “The crackdown recovers $97.4 million, dismantling 11,432 malicious infrastructure, highlighting the global scope of cybercrime and the urgent need for cross-border cooperation,” the agency said. The effort is the second […]
Chinese hacker, muddy, Genesis, Glacier panda escalates clouds and communications spying

Cybersecurity researchers are bringing attention to malicious activities organized by Chinese and Nexus cyberspy groups known as muddy pandas, which involve abuse of trustworthy relationships in the cloud and violating enterprise networks. “The enemy also demonstrates considerable ability to rapidly weaponize N-DAY and zero-day vulnerabilities, and frequently achieves initial access to targets by leveraging internet-oriented […]
The former developer jailed for four years for obstructing an Ohio employer with kill switch malware

August 22, 2025Ravi LakshmananCybercrime/Malware The 55-year-old Chinese citizen has been sentenced to four years of prison and three years of supervised release to deploy a kill switch that blocked the previous employer’s network with custom malware and locked out employees when their accounts were disabled. Davis Lou, 55, of Houston, Texas, was found guilty in […]
A Pre-Auth Exploit chain found in Commvault could allow remote code execution attacks

August 21, 2025Ravi LakshmananVulnerabilities/Software Security Commvault has released an update to address four security gaps that can be exploited to achieve remote code execution on sensitive instances. The list of vulnerabilities identified in the Commvault version before 11.36.60 is as follows: CVE-2025-57788 (CVSS score: 6.9) – A known login mechanism vulnerability allows unauthenticated attackers to […]
Cybercriminals Deploy Cornflake.v3 Backdoor Clickfix Tactics and Fake Captcha Pages

August 21, 2025Ravi LakshmananMalware/Cryptocurrency It has been observed that threat actors who harness deceptive social engineering tactics known as Clickfix will deploy the versatile backdoor code name Cornflake.v3. Mandiant, owned by Google, described the activity it tracks as UNC5518. This is described as part of the access scheme as access as a service that uses […]