Critical Mitel flaws allow hackers bypass logins and fully access the Mivoice MX-One system

July 24, 2025Ravi LakshmananVulnerability/Network Security Mitel has released a security update to address critical security flaws in the Mivoice MX-One, which allows attackers to bypass authentication protection. “Auth bypass vulnerability has been identified in the provisioning manager component of MITEL MIVOICE MX-ONE, which allows inaccurate attackers to carry out authentication bypass attacks with inappropriate access […]

Fire Ant Abuse Compromising vmware defective ESXi host and vcenter environment

July 24, 2025Ravi LakshmananVirtualization/Network Security Virtualization and networking infrastructure are targeted by threat actors called fire ants as part of a long-term cyberspy campaign. The activity observed this year is currently being designed primarily to infiltrate organizations’ VMware ESXi and vCenter environments, as well as network appliances, Sygnia said in a new report published today. […]

CastleLoader Malware Infected 469 Device Using Fake Github Repos and Clickfix Phishing

July 24, 2025Ravi LakshmananMalware/Cybercrime Cybersecurity researchers are shedding light on a new, versatile malware loader called Castle Loaders, used in campaigns that distribute a variety of information steelers and remote access trojans (rats). The activity employs a CloudFlare-themed Clickfix phishing attack and a fake Github repository opened in the name of a legitimate application, Swiss […]

Sophos and Sonicwall Patches Critical RCE flaws affect firewalls and SMA 100 devices

July 24, 2025Ravi LakshmananNetwork Security/Vulnerabilities Sophos and SonicWall warn users of the Sophos Firewall’s critical security flaws and Secure Mobile Access (SMA) 100 Series appliances that can be exploited to achieve remote code execution. Below is a list of two vulnerabilities affecting the Sophos firewall – CVE-2025-6704 (CVSS Score: 9.8) – An arbitrary file write […]

Do you have a pen test once a year? no. It’s time to build offensive SOCs

You won’t run your blue team once a year, so why accept this substandard schedule for your offensive? Cybersecurity teams are under intense pressure to become proactive and find weaknesses in their network before their enemies do so. However, in many organizations, offensive security is still treated as a one-off event. Annual Pentest, Quarterly Red […]

China-based APTS will deploy fake Dalai Lama apps to spy on Tibetan communities

July 24, 2025Ravi LakshmananCyber Spy/Malware The Tibetan community was targeted by Chinese and Nexus cyberspy groups as part of two campaigns run last month ahead of the Dalai Lama’s 90th birthday on July 6, 2025. Multi-stage attacks are codenamed Operation GhostChat and Phantomprayers Operations by Zscaler Threatlabz. “The attackers breached a legal website, redirected users […]

Storm-2603 exploits a flaw in SharePoint to deploy Warlock ransomware on unearned systems

July 24, 2025Ravi LakshmananVulnerability/Ransomware Microsoft has revealed that one of the threat actors behind the aggressive exploitation of SharePoint flaws is deploying Warlock ransomware on target systems. The tech giant said in an update shared on Wednesday that the findings are based on “analysis and increased threat intelligence from continuous surveillance of Storm-2603’s exploitation activities.” […]

Europol arrests XSS Forum Administrators on Kyiv after 12 years of operating cybercrime market

Europol announced on Monday the arrest of suspected administrators of XSS.IS (formerly Damagelab), the infamous Russian-speaking cybercrime platform. The arrests made in Kiev, Ukraine on July 222, 2025 were led by French police and Paris prosecutors, in cooperation with Ukrainian authorities and Europol. The lawsuit is the result of an investigation launched by French police […]

Hackers deploy stealth backdoors to WordPress Mu-Plugins to maintain administrator access

July 24, 2025Ravi LakshmananCybersecurity/Websecurity Cybersecurity researchers discover new stealth backdoors hidden within the “Mu-Plugins” directory of WordPress sites, grant threat access and allow any action to be performed. Required plugins (aka MU-Plugins) are special plugins that are automatically activated on all WordPress sites in your installation. By default, it is located in the “WP-Content/Mu-Plugins” directory. […]