New HTTP/2 ‘Madyoureset’ vulnerability allows large-scale DOS attacks

August 14, 2025Ravi LakshmananServer Security/Vulnerabilities Multiple HTTP/2 implementations are known to be susceptible to new attack technology called Madyoureset, which can be investigated to carry out powerful denial of service (DOS) attacks. “Madyoureset bypasses a typical server-imposed limit of 100 simultaneous HTTP/2 requests per TCP connection from a client. This limit is intended to mitigate […]

Hackers expanding the reach of cobalt strike beacons to Linux and macos using Crossc2

August 14, 2025Ravi LakshmananThreat Intelligence / Linux On Sunday, the Japan Certificate Regulation Center (JPCERT/CC) revealed on Thursday that an incident was observed involving the use of a command-and-control (C2) framework called CrossC2. The agency said the activity was detected between September and December 2024 and targeted multiple countries, including Japan, based on an analysis […]

Have you turned off the virtual oven?

Make sure the windows are closed before you leave the house. Go back to the kitchen and make sure the oven and stove are definitely off. Maybe go back and go back again to make sure your front door is properly closed. Don’t worry, as you know these automatic safety checks are unlikely to forget, […]

New Android Malware Wave Hit Banking, Call Hijacking, Root Exploits via NFC Relay Scam

Cybersecurity researchers have disclosed a new Android Trojan called Phantomcard, which abuses near field communications (NFCs) to carry out relay attacks to promote fraudulent transactions in attacks targeting Brazilian bank customers. “Phantomcard relays NFC data from victims’ bank cards to fraudsters’ devices,” Threatfabric said in the report. “Phantomcard is based on its Chinese as a […]

Simple steps to reduce the surface of attacks

August 14, 2025Hacker NewsEndpoint Security/Application Security Story Teaser Text: Cybersecurity leaders are pressured to stop attacks before they can launch them, and the best defense could come down to the setting they chose on the first day. In this article, Yuriy Tsibere explores how default policies such as Deny-by-Default, MFA Enforcement, and Application Ringfening can […]

Google requires crypto app licenses in 15 regions to warn the FBI of $9.9 million fraud loss

August 14, 2025Ravi LakshmananCryptocurrency/financial crime Google said it is implementing a new policy that requires cryptocurrency exchanges and wallet developers to obtain government licenses before publishing apps in 15 jurisdictions. This policy applies to markets such as Bahrain, Canada, Hong Kong, Indonesia, Israel, Japan, the Philippines, South Africa, South Korea, Switzerland, Thailand, the United Arab […]

CISA adds two n-able n-central flaws to a known exploited vulnerability catalog

August 14, 2025Ravi LakshmananVulnerability/Network Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws affecting N-Abable N-Central to its known Exploited Vulnerabilities (KEV) catalogue, citing evidence of aggressive exploitation. N-Able N-Central is a remote monitoring and management (RMM) platform designed for managed service providers (MSPs), allowing customers to efficiently manage […]

New PS1bot malware campaign deploys in-memory attacks in multistage using Malvertisingising

August 13, 2025Ravi LakshmananAggravated / Cryptocurrency Cybersecurity researchers have discovered a new Malvertising campaign designed to infect victims with a multi-stage malware framework called PS1BOT. “The PS1bot has a modular design, and several modules are delivered and used to perform a variety of malicious activities on infected systems, including information theft, key logs, reconnaissance, and […]

Zoom and Xerox releases critical security update fix privilege escalation and RCE flaws

August 13, 2025Ravi LakshmananVulnerabilities/Software Security Zoom and Xerox address critical security flaws in Windows and FreeFlow Core zoom clients that allow privilege escalation and remote code execution. The vulnerability affecting Windows Zoom clients tracked as CVE-2025-49457 (CVSS score: 9.6) is related to cases of untrusted search paths that could pave the way for privilege escalation. […]

Fortinet warns about Fortisiem vulnerability (CVE-2025-25256) in the Wild in the Wild Exploit Code

August 13, 2025Ravi LakshmananVulnerability/Network Security Fortinet warns customers about Fortisiem’s critical security flaws that say exploitation exists in the wild. The vulnerability tracked as CVE-2025-25256 has a CVSS score of 9.8 out of a maximum of 10.0. Inappropriate neutralization of special elements used in “OS commands (“OS command injection”) vulnerabilities [CWE-78] “Fortisiem may allow unrecognized […]