Encrypthub targets Web3 developers using fake AI platforms to deploy Fickle Stealer malware

July 20, 2025Ravi LakshmananAI Security / Infostealers The financially motivated threat actor known as Encrypthub (aka Larva-208 and Water Gamayun) is attributed to a new campaign aimed at Web3 developers getting infected with information Stealer malware. “Larva-208 uses fake AI platforms (such as Norlax AI, TeamPilot imitations) to evolve tactics and invite victims with job […]

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

July 20, 2025Ravi LakshmananZero Day/Vulnerability Critical security vulnerabilities in Microsoft SharePoint servers have been weaponized as part of an “active and massive” exploitation campaign. The zero-day flaw tracked as CVE-2025-53770 (CVSS score: 9.8) is described as a variant of CVE-2025-49706 (CVSS score: 6.3). “The untrusted data descent on on-premises Microsoft SharePoint Server allows unauthorized attackers […]

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

July 20, 2025Ravi LakshmananDevOps/Threat Intelligence Cybersecurity researchers have warned against supply chain attacks targeting common NPM packages via phishing campaigns designed to steal NPM tokens from project maintainers. Using captured tokens, I published the packages of myary versions directly to the registry without the source code committing or pulling requests in their respective GitHub repositories. […]

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

July 20, 2025Ravi LakshmananVulnerability/Threat Intelligence Crushftp’s newly disclosed critical security flaws are subject to aggressive exploitation in the wild. CVE identifier CVE-2025-54309 is assigned, and the vulnerability has a CVSS score of 9.0. “If the DMZ proxy feature is not used, 10.8.5 and 11.3.4_23 and 10.8.5 and 11 before 11.8.5 and 11 before 11.3.4_23 and […]

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

July 18, 2025Ravi LakshmananMonitoring/Mobile Security Cybersecurity researchers shed light on a mobile forensic tool used by Chinese law enforcement, called Massistant, and collect information from seized mobile devices. The hacking tool considered to be the successor to MFSocket is SDIC Intelligence Xiamen Information Co., Ltd, formerly known as Meiya Pico. It was developed by a […]

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

July 18, 2025Ravi LakshmananCyber Spy/Malware Several sectors in China, Hong Kong and Pakistan are targeted by threat activity clusters tracked as UNG0002 (aka unknown group 0002) as part of a broader cyber espionage activity. “This threat entity shows a strong preference for using shortcut files (LNK), VBScript, and post-explosion tools such as cobalt strikes and […]

Ivanti Zero-Days was exploited to drop MdifyLoader and launch a cobalt strike attack in memory

July 18, 2025Ravi LakshmananMalware/Vulnerabilities Cybersecurity researchers have revealed details of a new malware called MdifyLoader, which was observed alongside cyberattacks that harness the security flaws of Ivanti Connect Secure (ICS) appliances. According to a report released today by JPCERT/CC, the threat actors behind the exploitation of CVE-2025-0282 and CVE-2025-22457 of intrusions observed between December 2024 […]

A critical nvidia container toolkit flaw allows privilege escalation in AI cloud services

July 18, 2025Ravi LakshmananCloud Security / AI Security Cybersecurity researchers have revealed a critical container escape vulnerability in the NVIDIA Container Toolkit. The vulnerability tracked as CVE-2025-23266 has a CVSS score of 9.0 out of 10.0. It is codenamed nvidiascape by Cloud Security Company Wiz, owned by Google. “The NVIDIA Container Toolkit for all platforms […]

CERT-UA uses LLM for Phishing Campaigns to discover Lamehug Malware linked to APT28

July 18, 2025Ravi LakshmananCyber Attacks/Malware The Ukrainian Computer Emergency Response Team (CERT-UA) has revealed details of a phishing campaign designed to provide glitter pufferfish, the malware codename. “A clear feature of Lamehug is the use of LLM (Large Language Model), which is used to generate commands based on textual representations (descriptions),,” Cert-UA said in its […]

Google sues 25 Chinese companies via Badbox 2.0 botnet affecting 10m Android devices

July 18, 2025Ravi LakshmananBotnet/Network Security Google announced Thursday that it is pursuing legal action in New York federal court against 25 unnamed individuals or entities in China who allegedly operate the Badbox 2.0 botnet and housing proxy infrastructure. “The Badbox 2.0 botnet has compromised over 10 million unclear devices running Android Open Source Project, which […]