Important features that security leaders need to know

August 13, 2025Hacker NewsArtificial Intelligence/Threat Hunting Security operations were not a 9-5 job. For SOC analysts, the day often starts deep in a line of alerts, chasing what turns out to be false positives, or switching between half a dozen tools to stitch together contexts. The film is repetitive, time-consuming, high-stakes, and the SOC is […]

What will the next wave of AI cyberattacks look like and how to survive

August 13, 2025Hacker NewsArtificial Intelligence/Identity Security The AI revolution has not come. It’s already here. From copilots that write our emails to autonomous agents who can take action without lifting their fingers, AI is changing the way we work. But here is the unpleasant truth. Attackers are evolving just as fast. AI’s leap forward offers […]

Charon ransomware hits the Middle East sector using the right level of evasion tactics

August 13, 2025Ravi LakshmananEndpoint Security / Cybercrime Cybersecurity researchers have discovered a new campaign to adopt a previously undocumented family of ransomware called Charon to target the public sector and aviation industry in the Middle East. According to Trend Micro, the threat actors behind the activity demonstrated tactics that reflected the tactics of advanced persistent […]

Researchers find XZ Utils backdoors in dozens of Docker hub images to drive supply chain risk

August 12, 2025Ravi LakshmananMalware/Container Security A new study discovered Docker Images from Docker Hub, and images containing the infamous XZ Utils backdoor. Even more troublesome is the fact that other images are constructed on top of these infected basic images, effectively transmitting infections transitively, Binarly Research says in a report shared with Hacker News. The […]

Fortinet ssl vpns are hit by a wave of global brute force before attackers move to Forty Managher

August 12, 2025Ravi LakshmananThreat Intelligence/Enterprise Security Cybersecurity researchers have warned of “critical spikes” in brute force traffic targeting Fortinet SSL VPN devices. Coordinated activities per threat information company Greynoise were observed on August 3, 2025, with over 780 unique IP addresses participating in this effort. Up to 56 unique IP addresses have been detected in […]

Cybercrime group ShinyHunters, scattered spiders join forces against fearful attacks on businesses

August 12, 2025Ravi LakshmananCybercrime/Finance security The ongoing data terr campaign targeting Salesforce customers could quickly turn attention to financial and technology service providers as Shinyhunters and Spicider appear to be working hand in hand. “The wave of attacks that contributed to this latest Shina Hunter reveals dramatic changes in tactics and moves beyond the group’s […]

New “curly hair comrades” using ngen com hijacking in Georgia app attacks Moldova

August 12, 2025Ravi LakshmananCyberspy / Windows Security Previously called undocumented threat actors, the Curly comrades have been observed to target Georgia and Moldovan entities as part of a cyberspy campaign designed to promote long-term access to targeted networks. “They tried repeatedly to extract the NTDS database from the domain controller. This is the primary repository […]

Enterprise Browser vs Secure Browser Extension

August 12, 2025Hacker NewsBrowser Security/Zero Trust Most security tools can’t see what happens within the browser, but that’s where most of the work and the risks live now. Deciding how security leaders will close that gap is often faced with choice. Deploy a dedicated enterprise browser or add an enterprise-grade control layer to a browser […]

The Netherlands NCSC confirms aggressive exploitation of Citrix Netscaler CVE-2025-6543 in the critical sector

August 12, 2025Ravi LakshmananVulnerability/Threat Intelligence The Netherlands National Cybersecurity Centre (NCSC-NL) warns of cyberattacks that utilize recent disclosed critical security flaws to violate Citrix Netscaler ADC products. The NCSC-NL said it discovered exploitation of CVE-2025-6543 targeting several important organizations in the Netherlands, saying that the investigation is ongoing to determine the extent of the impact. […]