Alert fatigue, data overload, and traditional SIEM falls

July 31, 2025Hacker NewsSecurity Operations/Threat Detection Security Operations Centers (SOCs) have grown to the limit. Log volumes are surged, the threat landscape is becoming more complicated and security teams are chronically understaffed. Analysts face daily battles with alert noise, fragmented tools and visibility of incomplete data. At the same time, more vendors are phased out […]
Hackers exploit critical WordPress theme flaws to hijacking sites via remote plugins

July 31, 2025Ravi LakshmananVulnerability/Website Security Threat actors actively harness the critical security flaws of “only – Charity’s multipurpose non-profit WordPress theme” to take over sensitive sites. The CVSS score for vulnerabilities tracked as CVE-2025-5394 is 9.8. Security researcher Thái An is believed to have discovered and reported the bug. According to WordFence, this drawback is […]
2025 Gartner® MagicQuadrant™ Endpoint Protection

Gartner, Magic Quadrant of Endpoint Protection Platform, Evgeny Mirololyubov, Franz Hinner, Deepak Mishra, July 14, 2025. Gartner does not endorse any vendors, products or services portrayed in research publications, and does not advise technology users to select only vendors with the highest ratings or other designations. Gartner’s research publications are composed of the opinions of […]
Hackers use Facebook ads to spread JSCEAL malware via fake cryptocurrency trading apps

July 30, 2025Ravi LakshmananCryptocurrency/Browser Security Cybersecurity researchers can bring attention to the ongoing campaigns that distribute fake cryptocurrency trading apps and deploy compiled V8 JavaScript (JSC) malware called JSCEAL to capture data from their credentials and wallets. According to Checkpoint, activity leverages thousands of malicious ads posted to Facebook to redirect unsuspecting victims to fake […]
Funksec Ransomware Decryptor was published for free after the group was dormant

July 30, 2025Ravi LakshmananEncryption/Ransomware Cybersecurity experts have released a ransomware stock decryptor called Funksec to allow victims to recover access to their files for free. “The ransomware is now considered dead, so we released a decryptor for publication,” said Gen digital researcher Ladislav Zezula. According to data from Ransomware.live, Funksec, which emerged towards the end […]
Enabling remote hijacking via critical duffer camera defect ONVIF and file upload exploit

July 30, 2025Ravi LakshmananFirmware security/vulnerabilities Cybersecurity researchers have disclosed critical security flaws that have now been patched in the firmware of Dahua smart cameras, allowing attackers to hijack control of sensitive devices. “The flaws affecting the device’s ONVIF protocol and file upload handlers allow unauthorized attackers to execute arbitrary commands remotely and effectively take over […]
Chinese companies linked to Silk Typhoons have filed more than 15 patents for Cyberspy Tool

July 30, 2025Ravi LakshmananEndpoint Security / Cyberspy Chinese companies, linked to a state-sponsored hacking group known as Silk Timbus (aka Hafnium), have been identified as behind dozens of technology patents, shed light on the shadowy cyber contract ecosystem and its attack capabilities. The patent covers encrypted endpoint data collection, Apple device forensics, and forensics and […]
Look inside Pillar’s AI security platform

This article provides a brief overview of the Pillar Security platform to help you better understand how you tackle AI security challenges. Pillar Security builds a platform that covers the entire software development and deployment lifecycle with the aim of providing trust to AI systems. The platform uses its holistic approach to showcase new ways […]
Apple Patches Safari vulnerability was also exploited as zero day in Google Chrome

July 30, 2025Ravi LakshmananVulnerability/Zero Day On Tuesday, Apple released security updates for its entire software portfolio. This includes fixing a vulnerability that Google exploited as zero-day in the Chrome web browser earlier this month. The vulnerability tracked as CVE-2025-6558 (CVSS score: 8.8) is incorrect verification of browser angles and untrusted input of GPU components, resulting […]
Google launches DBSC Open Beta in Chrome and increases patch transparency via Project Zero

July 30, 2025Ravi LakshmananDevice Security / AI Security Google has announced that it is creating a security feature called Device Bound Session Credentials (DBSC) in open beta to help users be protected against session cookie theft attacks. First introduced as a prototype in April 2024, DBSC is designed to combine authentication sessions into devices to […]