Sonic Wall is checking for patch vulnerabilities behind recent VPN attacks rather than zero day

August 7, 2025Ravi LakshmananNetwork Security/Vulnerabilities SonicWall has revealed that the recent surge in activity targeting new firewalls with Gen 7 and SSL VPN support is related to old, currently Pasteur bugs and password reuse. “We are currently confident that recent SSL VPN activity is not connected to zero-day vulnerabilities,” the company said. “Instead, there is […]
How to stop Python supply chain attacks and the expert tools you need

August 7, 2025Hacker Newsdevsecops/Supply Chain Security Python is everywhere in modern software. From machine learning models to production microservices, your code and your business may depend on Python packages you have not written. However, in 2025, that trust will pose serious risks. Every few weeks, you’ll see fresh headings about malicious packages uploaded to the […]
Researchers reveal Ecscape’s flaws in Amazon ECS that allow cross-task qualification theft

August 6, 2025Ravi LakshmananDEVOPS/Container Security Cybersecurity researchers have demonstrated an “end-to-end privilege escalation chain” with Amazon Elastic Container Services (ECS). This could be exploited to attackers to access horizontal movements, access sensitive data and seize control of the cloud environment. The attack technology was called Ecscape by sweet security researcher Naor Haziz. “We have identified […]
Fake VPN and spam blocker apps associated with vextrio used in ad fraud, subscription scams

A malicious ad technician known as Vextrio Viper has developed several malicious apps published on Apple and Google’s official App Storefronts, and is being developed under the guise of seemingly useful applications. These apps pretend to be VPNs, device apps, RAM cleaners, dating services, and spam blockers. DNSThreatIntelligence Firm Infoblox says in a thorough analysis […]
AI slashes VCISO workloads by 68% as SMBS demands more – new report reveals

August 6, 2025Hacker NewsCompliance/Security Operations As cyber threats and risks grow in greater volume and refinement, cybersecurity has become mission-critical for businesses of all sizes. To address this shift, SMB has urgently turned its attention to VCISO services to meet urgent threats and compliance demands. A recent report by Cynomi found that 79% of MSPs […]
Microsoft launches Project IRE to autonomously classify malware using AI tools

August 6, 2025Ravi LakshmananArtificial Intelligence/Threat Detection On Tuesday, Microsoft announced an autonomous artificial intelligence (AI) agent that can analyze and classify software without assistance in moving forward with malware detection efforts. Currently, an autonomous malware classification system with a prototype, Large-scale Language Model (LLM), is known as the project codename by Tech Giant. The system […]
Trend Micro confirms aggressive misuse of key vertices in on-premises systems

August 6, 2025Ravi LakshmananVulnerability/Endpoint Security Trend Micro has released a mitigation to address a critical security flaw in the on-premises version of the Apex One management console, which is said to have been exploited in the wild. Both vulnerabilities rated 9.4 in the CVSS scoring system (CVE-2025-54948 and CVE-2025-54987) are described as flaws in management […]
CERT-UA warns against C# malware attacks that drive HTA using court subpoena lures

August 6, 2025Ravi LakshmananCyber Spy/Malware The Ukrainian Computer Emergency Response Team (CERT-UA) has warned of cyberattacks carried out by threat actors called UAC-0099, targeting domestic government agencies, defense forces and businesses in the Defense Industrial Parks. Attacks that use phishing email as an initial compromise vector are used to provide malware families such as MatchBoil, […]
AI Is Transforming Cybersecurity Adversarial Testing

When Technology Resets the Playing Field In 2015 I founded a cybersecurity testing software company with the belief that automated penetration testing was not only possible, but necessary. At the time, the idea was often met with skepticism, but today, with 1200+ of enterprise customers and thousands of users, that vision has proven itself. But […]
CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report

August 6, 2025Ravi LakshmananVulnerability/Firmware Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three old security flaws affecting D-Link routers to its known Exploited Vulnerabilities (KEV) catalogue based on evidence of aggressive wild exploitation. High-strength vulnerabilities from 2020 and 2022 are listed below – CVE-2020-25078 (CVSS score: 7.5) – Unspecified vulnerability in […]