Threatening actor Mimo deploys crypto miners and proxyware targeting magento and dockers

July 23, 2025Ravi LakshmananMalware/Cryptocurrency The threat actors behind the exploitation of vulnerable Craft Content Management System (CMS) instances have shifted their tactics to target Docker instances that were misunderstood as Magento CMS. This activity is attributed to threat actors tracked as MIMO (also known as HEZB). It has a long history of leveraging N-DAY security […]

New Coyote Malware Variants Abuse Windows UI Automation to Steal Bank Credentials

July 23, 2025Ravi LakshmananWindows Security/Cryptocurrency Windows Banking Trojan, known as Coyote, has become the first known malware strain to harvest sensitive information using a Windows accessibility framework called UI Automation (UIA). “The new Coyote variant is targeting Brazilian users and uses the UIA to extract web addresses from 75 bank labs and credentials linked to […]

A new approach to the challenges of 10 years ago

Security experts have been talking about KerberoAsting for over a decade, and this attack continues to circumvent the typical defense method. why? This is because existing detection relies on brittle heuristics and static rules, and is not retained to detect potential attack patterns for highly variable Kerberos traffic. They often generate false positives or miss […]

Google launches OSS Rebuild to expose malicious code in widely used open source packages

July 23, 2025Ravi LakshmananSoftware Integrity / devsecops Google has announced the launch of a new initiative called OSS Rebuild to enhance security in its open source package ecosystem and to prevent software supply chain attacks. “As supply chain attacks continue to target widely used dependencies, OSS Rebuild provides strong data to security teams and provides […]

Sysaid flaws under active attacks enable remote file access and SSRF

July 23, 2025Ravi LakshmananVulnerabilities/Software Security Based on evidence of active exploitation, the US Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws that affect Sysaid IT support software to its known exploited vulnerabilities (KEV) catalog. The vulnerabilities in question are listed below – CVE-2025-2775 (CVSS score: 9.3) – Reference vulnerability in the XML […]

CISA orders emergency patch after Chinese hackers exploit SharePoint flaws in live attacks

July 23, 2025Ravi LakshmananVulnerability/Threat Intelligence On July 22, 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) added two Microsoft SharePoint Flaws, CVE-2025-49704 and CVE-2025-49706, to its known available vulnerabilities (KEV) catalog, based on evidence of active exploitation. Therefore, a Federal Civil Enforcement Division (FCEB) agency is required to fix the vulnerabilities identified by July […]

Microsoft Link Exploits to 3 Chinese Hacker Groups in SharePoint ongoing

July 22, 2025Ravi LakshmananVulnerability/Threat Intelligence On July 7, 2025, Microsoft officially linked the exploitation of security flaws in SharePoint Server instances for the Internet to two Chinese hacking groups called Linen Typhoon and Violet Typhoon, supporting an early report. Tech Giant also observed a third China-based threat actor tracking Storm-2603, saying it would weaponize the […]

Cisco checks active exploits targeting defects in ISE and allows for unrecognized root access

July 22, 2025Ravi LakshmananNetwork Security/Vulnerabilities On Monday, Cisco updated its advisory for a set of recently disclosed security flaws for the Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) to acknowledge its aggressive exploitation. “In July 2025, Cisco Psirt [Product Security Incident Response Team]has noticed attempts to exploit some of these vulnerabilities […]

Allakore, Purerat and Hijack Loader’s stolen qualifications and remote access to grow

Mexican organizations are being targeted by threat actors to provide modified versions of Arakorerat and SystemBC as part of their long-term campaign. This activity stems from a financially motivated hacking group called Greedy Sponge by Arctic Wolf Labs. It is believed to have been active since early 2021 and indiscriminately targets a wide range of […]

How to proceed from SOC Manager to CISO?

Moving from managing a Security Operations Center (SOC) to becoming a Chief Information Security Officer (CISO) is an important career leap. Not only does it require a solid foundation of technical knowledge, but it also requires leadership skills and business smarts. This article will guide you through the practical steps and skills needed to take […]