Cyberark and HashiCorp flaws allow remote vault takeover without credentials

Cybersecurity researchers have discovered more than 12 vulnerabilities in enterprise secure vaults from Cyberark and Hashicorp. According to a report by Identity security company Cyata, 14 vulnerabilities, collectively named Vault Faults, affect Cyberark Secrets Manager, Self-Hosted, and Convisur Open Source and Hashicorp Vault. Following the responsible disclosure in May 2025, the defects are addressed in […]
AI Tools Fuel Brazilian Phishing Scam, Efimer Trojan steals codes from 5,000 victims

Cybersecurity researchers are turning their attention to new campaigns using website building tools using legitimately generated artificial intelligence (AI) to create replica phishing pages that mimic Brazilian government agencies as part of a financially motivated campaign. This activity includes creating sites that look like those that mimic the Brazilian Ministry of State Transport and Education. […]
What are the attackers doing with them?

If your organization’s credentials are leaked, immediate results are rare, but the long-term impact is far-reaching. Far from the cloak and dagger tactics seen in fiction, many real-world cyber violations begin with the seemingly simple thing: usernames and passwords. According to Verizon’s 2025 Data Breach Investigation Report, leaked credentials accounted for 22% of violations in […]
Rubygems, forced crypto, security changes hit on malicious packages that steal credentials

A fresh set of 60 malicious packages has been revealed, targeting the Rubygems ecosystem, by equipping them with harmless automation tools to steal credentials from unsuspecting users, as harmless automation tools for social media, blogging, or messaging services. The activity has been rated active since at least March 2023, according to software supply chain security […]
greedybear uses 150+ malicious Firefox wallet extensions to steal $1 million in crypto.

A newly discovered campaign called GreedyBear leverages over 150 malicious extensions on the Firefox market, designed to steal more than $1 million in digital assets by impersonating a popular cryptocurrency wallet. According to Tuval Admoni, a security researcher at KOI, published browser add-on masquerades such as Metamask, Tronlink, Exodus and Rabby Wallet, are What is […]
Socgholish malware spreads through AD tools. Provides access to Lockbit, Evil Corp and more

August 7, 2025Ravi LakshmananMalware/Threat Intelligence It has been observed that threat actors behind Socgholish malware leverage traffic delivery systems (TDSSs) such as Parrot TDS and Keitaro TDS to filter and redirect unsuspecting users to rough content. “The core of their operations is the malware as a service (MAAS) model, with infected systems being sold as […]
Malicious GO, NPM package provides cross-platform malware and triggers remote data wipes

August 7, 2025Ravi LakshmananMalware/Threat Intelligence Cybersecurity researchers have discovered a set of 11 malicious GO packages designed to download additional payloads from remote servers and run them on both Windows and Linux systems. “At runtime, the code quietly generates a shell, pulls two-stage payloads from the exchangeable set of .icu and .tech command-and-control (C2) endpoints […]
Microsoft discloses defects in Exchange Server that allow silent cloud access in hybrid setups

August 7, 2025Ravi LakshmananVulnerability/Threat Detection Microsoft has released an advisory for high-strength security flaws affecting on-premises versions of Exchange Server, allowing attackers to gain increased privileges under certain conditions. The CVSS score for vulnerabilities tracked as CVE-2025-53786 is 8.0. Dirk-Jan Molema with outsider security has been recognized for reporting a bug. “In a replacement hybrid […]
The 6,500 axis server exposes the remote protocol. 4,000 people in the US are vulnerable to exploitation

August 7, 2025Ravi LakshmananVulnerability/Threat Intelligence Cybersecurity researchers have disclosed multiple security flaws in video surveillance products from Axis Communications, which, if successfully exploited, can now take over the attack. “This attack will have pre-certified remote code execution in Axis Device Manager, servers used to configure and manage camera fleets, and Axis camera stations for client […]
I’m teaching you about cloud defense in 2025

With 2025 in mind, cloud attacks have evolved faster than ever, with artificial intelligence (AI) being both weapons and shields. As AI rapidly changes how enterprises innovate, security teams are subject to a triple burden. Secure AI embedded in every part of your business. Use AI to defend faster and smarter. Fight AI-powered threats that […]