Hackers exploit SAP vulnerabilities to deploy automatic color malware in violation of Linux systems

July 30, 2025Ravi LakshmananVulnerability/Threat Intelligence Threat officials have been observed to exploit the currently patched critical SAP NetWeaver flaws to deliver auto-collar backdoors in an attack targeting US-based chemical companies in April 2025. “For three days, threat actors have accessed their clients’ networks, attempted to download some suspicious files, and communicated with malicious infrastructure linked […]

wiz discovers critical access bypass flaws in AI-powered vibe coding platform base 44

July 29, 2025Ravi LakshmananLLM Security/Vulnerability Cybersecurity researchers are currently revealing important security flaws patched, a popular vibe coding platform called Base44, which allows unauthorized access to private applications built by users. “The vulnerabilities we discovered could have resulted in the attacker creating a validated account for private applications on the platform by providing only non-secret […]

Pypi warns of ongoing phishing campaigns using fake verification emails and Lookalike Domain

July 29, 2025Ravi LakshmananPhishing/Developer Security A maintainer of the Python Package Index (PYPI) repository has issued a warning about an ongoing phishing attack targeting users to redirect them to forge Pypi sites. Attacks involve sending an email message with a subject line.”[PyPI] Email confirmation: “This will be sent from your email address noreply@pypj[.]org (note that […]

Chaos Raas appears after Blacksuit Takedown and demands $300,000 from US victims

The newly emerging ransomware (RAAS) gang, known as chaos, could be made up of former members of the black suit crew, as the latter’s dark web infrastructure is subject to law enforcement seizures. Born in February 2025, Chaos is the latest participant in the ransomware landscape, carrying out big game hunting and double horror attacks. […]

How browsers became the battlefield for the main cyber

Until recently, the cyberattacker methodology behind the biggest violations of the past decade or so has been fairly consistent. Compromising endpoints via software exploits or by social engineering users to run malware on their devices. Find ways to move horizontally within the network and compromise your privileged identity. Repeat as needed until you can carry […]

Cybercriminal uses fake apps to steal data and threaten users across Asian mobile networks

Cybersecurity researchers have discovered a new, massive mobile malware campaign targeting Android and iOS platforms with fake dating, social networking, cloud storage and car service apps, and stole sensitive personal data. The cross-platform threat is called Sarangtrap by Zimperium Zlabs. It seems that Korean users are the main focus. “This massive campaign includes over 250 […]

New JavaScript Injection Playbook

React Conqued XSS? Think about it again. This is the reality facing JavaScript developers in 2025, bypassing the very framework designed to help attackers quietly evolve their injection technology to leverage everything from prototype pollution to AI-generated code and keep their applications safe. A complete 47-page guide with framework-specific defenses (PDF, free). JavaScript conquered the […]

CISA adds papercut NG/MF CSRF vulnerability to KEV catalogue amid aggressive exploitation

July 29, 2025Ravi LakshmananVulnerabilities/Software Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-strength security vulnerability affecting PaperCutng/MF print management software to its known exploitation of exploitation in the wild, citing evidence of aggressive exploitation. The vulnerability tracked as CVE-2023-2533 (CVSS score: 8.4) is a cross-site request forgery (CSRF) bug that […]

Hackers Breach Toptal Github reveals 10 malicious NPM packages with 5,000 downloads

July 28, 2025Ravi LakshmananMalware/Developer Tools The latest instance of software supply chain attacks allowed unknown threat actors to compromise Toptal’s GitHub organizational accounts, leveraging access to expose ten malicious packages to the NPM registry. The package contained code to remove GitHub authentication tokens and destroy the victim system, Socket said in a report released last […]