Critical Mitel flaws allow hackers bypass logins and fully access the Mivoice MX-One system

July 24, 2025Ravi LakshmananVulnerability/Network Security Mitel has released a security update to address critical security flaws in the Mivoice MX-One, which allows attackers to bypass authentication protection. “Auth bypass vulnerability has been identified in the provisioning manager component of MITEL MIVOICE MX-ONE, which allows inaccurate attackers to carry out authentication bypass attacks with inappropriate access […]
Fire Ant Abuse Compromising vmware defective ESXi host and vcenter environment

July 24, 2025Ravi LakshmananVirtualization/Network Security Virtualization and networking infrastructure are targeted by threat actors called fire ants as part of a long-term cyberspy campaign. The activity observed this year is currently being designed primarily to infiltrate organizations’ VMware ESXi and vCenter environments, as well as network appliances, Sygnia said in a new report published today. […]
CastleLoader Malware Infected 469 Device Using Fake Github Repos and Clickfix Phishing

July 24, 2025Ravi LakshmananMalware/Cybercrime Cybersecurity researchers are shedding light on a new, versatile malware loader called Castle Loaders, used in campaigns that distribute a variety of information steelers and remote access trojans (rats). The activity employs a CloudFlare-themed Clickfix phishing attack and a fake Github repository opened in the name of a legitimate application, Swiss […]
Sophos and Sonicwall Patches Critical RCE flaws affect firewalls and SMA 100 devices

July 24, 2025Ravi LakshmananNetwork Security/Vulnerabilities Sophos and SonicWall warn users of the Sophos Firewall’s critical security flaws and Secure Mobile Access (SMA) 100 Series appliances that can be exploited to achieve remote code execution. Below is a list of two vulnerabilities affecting the Sophos firewall – CVE-2025-6704 (CVSS Score: 9.8) – An arbitrary file write […]
Watch this webinar to reveal hidden flaws in login, AI, and digital trusts and fix them

July 24, 2025Hacker News Is managing customer logins and data a headache? You are not alone! Today, we all look forward to an ultra-fast, secure, and personalized online experience. But be honest, be careful about how you use your data. If something feels bad, trust can quickly fade away. Plus, there is the lightning change […]
Do you have a pen test once a year? no. It’s time to build offensive SOCs

You won’t run your blue team once a year, so why accept this substandard schedule for your offensive? Cybersecurity teams are under intense pressure to become proactive and find weaknesses in their network before their enemies do so. However, in many organizations, offensive security is still treated as a one-off event. Annual Pentest, Quarterly Red […]
China-based APTS will deploy fake Dalai Lama apps to spy on Tibetan communities

July 24, 2025Ravi LakshmananCyber Spy/Malware The Tibetan community was targeted by Chinese and Nexus cyberspy groups as part of two campaigns run last month ahead of the Dalai Lama’s 90th birthday on July 6, 2025. Multi-stage attacks are codenamed Operation GhostChat and Phantomprayers Operations by Zscaler Threatlabz. “The attackers breached a legal website, redirected users […]
Storm-2603 exploits a flaw in SharePoint to deploy Warlock ransomware on unearned systems

July 24, 2025Ravi LakshmananVulnerability/Ransomware Microsoft has revealed that one of the threat actors behind the aggressive exploitation of SharePoint flaws is deploying Warlock ransomware on target systems. The tech giant said in an update shared on Wednesday that the findings are based on “analysis and increased threat intelligence from continuous surveillance of Storm-2603’s exploitation activities.” […]
Europol arrests XSS Forum Administrators on Kyiv after 12 years of operating cybercrime market

Europol announced on Monday the arrest of suspected administrators of XSS.IS (formerly Damagelab), the infamous Russian-speaking cybercrime platform. The arrests made in Kiev, Ukraine on July 222, 2025 were led by French police and Paris prosecutors, in cooperation with Ukrainian authorities and Europol. The lawsuit is the result of an investigation launched by French police […]
Hackers deploy stealth backdoors to WordPress Mu-Plugins to maintain administrator access

July 24, 2025Ravi LakshmananCybersecurity/Websecurity Cybersecurity researchers discover new stealth backdoors hidden within the “Mu-Plugins” directory of WordPress sites, grant threat access and allow any action to be performed. Required plugins (aka MU-Plugins) are special plugins that are automatically activated on all WordPress sites in your installation. By default, it is located in the “WP-Content/Mu-Plugins” directory. […]