ClickFix Malware Campaign exploits CAPTCHAS to spread cross-platform infections

August 5, 2025Ravi LakshmananSocial Engineering/Malware A new finding from Garderio Labs shows that a combination of propagation methods, narrative refinement, and avoidance techniques has helped remove the way a social engineering tactic called Clickfix has been taking place over the past year. “Like a real-world virus variant, this new ‘clickfix’ strain quickly rose, eventually finally […]
Google’s August patch fixes two exploited Qualcomm vulnerabilities in the wild

August 5, 2025Ravi LakshmananVulnerability/Mobile Security Google has released a security update to address multiple security flaws in Android. This includes fixes for two Qualcomm bugs that were flagged as actively exploited in the wild. Vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5). Both were disclosed in line with CVE-2025-21480 (CVSS score: 8.6). […]
Cursor AI Code Editor Vulnerability enables RCE via malicious MCP file swap approval

August 5, 2025Ravi LakshmananAI Security/MCP Protocol Cybersecurity researchers have disclosed high-strength security flaws in code editor cursors powered by artificial intelligence (AI) that could lead to remote code execution. The vulnerability tracked as CVE-2025-54136 (CVSS score: 7.2) has been called McPoison by checkpoint investigations due to the fact that software exploits habits in a way […]
The costly confusion behind security risks

In SaaS security conversations, “misconfiguration” and “vulnerability” are often used interchangeably. But they are not the same thing. And misunderstanding the distinction can lead to quiet, real exposure. This confusion is more than just semantics. This reflects a deeper misconception of the shared responsibility model, especially in SaaS environments where the boundaries between vendor and […]
How to save their SOC from alert confusion so that top CISOs never miss real incidents

Why are SOC teams still owned to alerts after spending so much on security tools? False positives are piled up, stealth threats slip through, and serious incidents are buried in noise. Top CISOs aren’t adding more and more tools to their SOC workflows, but provide the speed and visibility needed to catch actual attacks before […]
Deliver 15,000 fake Tiktok Shop Domains malware and steal cryptography via AI-driven fraud campaigns

August 5, 2025Ravi LakshmananMalware/Mobile Security Cybersecurity researchers have unveiled it with a wide range of malicious campaigns targeting Tiktok shop users worldwide with the aim of stealing qualifications and distributing troilized apps. “Threat actors are leveraging the official in-app e-commerce platform through dual attack strategies targeting phishing and malware,” CTM360 said. “The core tactics include […]
SonicWall investigates potential SSL VPN zero day after more than 20 target attacks are reported

August 5, 2025Ravi LakshmananZero Day/Network Security Sonic Wall said it was actively investigating the report to determine whether there are new zero-day vulnerabilities, following an report on Akira ransomware actor Spike in late July 2025. “Over the past 72 hours, there has been a noticeable increase in both internal and external reported cyber incidents, including […]
Nvidia Triton bug causes unrecognized attackers to run code and hijack AI servers

August 4, 2025Ravi LakshmananAI Security/Vulnerability The newly disclosed set set of security flaws in Nvidia’s Triton Inference Server for Windows and Linux is an open source platform for running artificial intelligence (AI) models at scale and could potentially be utilized to take over sensitive servers. “If these flaws are chained together, remote, unauthorized attackers could […]
Vietnamese hackers use PXA steelers to hit 4,000 IPS and steal 200,000 passwords worldwide

August 4, 2025Ravi LakshmananMalware/Browser Security Cybersecurity researchers are turning their attention to a new wave of campaigns that distribute Python-based information steelers, known as Pyson-based information steelers. According to a joint report published by Beazley Security and Sentinelone and shared with Hacker News, it is rated as the job of Vietnamese-speaking cybercriminals who monetize stolen […]
VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & More

Aug 04, 2025Ravie LakshmananHacking News / Cybersecurity Malware isn’t just trying to hide anymore—it’s trying to belong. We’re seeing code that talks like us, logs like us, even documents itself like a helpful teammate. Some threats now look more like developer tools than exploits. Others borrow trust from open-source platforms, or quietly build themselves out […]