Critical Golden DMSA Attacks in Windows Server 2025 allow cross-domain attacks and permanent access

July 16, 2025Ravi LakshmananWindows Server / Enterprise Security Cybersecurity researchers have revealed what they say is a “significant design flaw” in the Delegated Managed Service Account (DMSA) introduced in Windows Server 2025. “This flaw can cause impactful attacks, allowing cross-domain lateral movement, allowing permanent access to all managed service accounts and their resources indefinitely across […]
AI agents act like employees with root access – here’s how to get back control

July 16, 2025Hacker NewsIdentity Management / AI Security The AI Gold Rush is lit. But without identity-first security, all deployments are open doors. Most organizations protect native AI like web apps, but act like junior employees with root access and no manager. From hype to high stakes Generated AI has moved beyond the hype cycle. […]
Deep fake. Fake recruiter. Clone CFOS – Learn how to stop AI-driven attacks in real time

July 16, 2025Hacker NewsAI Security/Fraud Detection The attack on social engineering has entered a new era. And they are fast, smart, and deeply personalized. It’s not just suspicious emails in your spam folder. Today’s attackers mimic executives, hijack social channels, create websites, emails, and even audio, mimic executives, mimic executives, use stolen branding assets, Deep […]
The new konfety malware variant variant avoids detection by manipulating APKs and dynamic code

Cybersecurity researchers have discovered a new, sophisticated variant of known Android malware called Konfety, which utilizes evil twin techniques to enable ad fraud. The sleazy approach essentially involves a scenario in which two variants of an application share the same package name. The benign “decoy” app hosted by the Google Play Store and its evil […]
Google releases CVE-2025-6558 crucial chrome update to wild and active exploits

July 16, 2025Ravi LakshmananBrowser Security / Zero Day On Tuesday, Google rolled out fixes for six security issues in the Chrome web browser. The high-strength vulnerability in question is CVE-2025-6558 (CVSS score: 8.8). This is described as an incorrect verification of browser angles and untrusted input of GPU components. “Insufficient validation of angles and GPU […]
Google AI “Big Sleep” stops exploitation of critical SQLite vulnerabilities before hacker law

July 16, 2025Ravi LakshmananAI Security/Vulnerability Google revealed on Tuesday that its Large Language Model (LLM)-assisted Vulnerability Discovery Framework discovered security flaws in the SQLite open source database engine before being exploited in the wild. The vulnerability tracked as CVE-2025-6965 (CVSS score: 7.2) is a memory corruption flaw that affects all versions prior to 3.50.2. It […]
Ultra-Volume Measurement DDOS Attack has reached record 7.3 TBPS and targets major global sectors

July 15, 2025Ravi LakshmananBotnet/Network Security CloudFlare said Tuesday it mitigated a 7.3 million distributed denial-of-service (DDOS) attack in the second quarter of 2025, significantly lowering its 20 million DDOS attack, which it lost in the last quarter. “Overall, the second quarter of 2025 saw a surge in ultra-volume DDOS attacks,” said Omer Yoachimik and Jorge […]
The newly launched global group Raas will expand operations with AI-driven negotiation tools

Cybersecurity researchers have shed light on a new ransomware (RAAS) operation, called a global group that targets a wide range of sectors in Australia, Brazil, Europe and the United States since its emergence in early June 2025. Global Group has been promoted at the RAMP4U forum by a threat actor known as “$$$,” said Arda […]
State-backed HagyBeacon malware uses AWS Lambda to steal data from SE Asian government

July 15th, 2025Ravi LakshmananCyber Spy/Threat Intelligence Government organizations in Southeast Asia are targeting new campaigns aimed at collecting sensitive information using previously undocumented Windows backdoors. This activity is tracked by Palo Alto Networks Unit 42, where “CL” represents “cluster” and “STA”, “CL” represents “motivation for state responsibility”, and “CL” represents “CL”. “The threat actors behind […]
How to protect invisible identity access

July 15th, 2025Hacker NewsAutomation/Risk Management AI agents are committed to automating everything from financial adjustments to incident response. However, every time an AI agent rotates a workflow, it needs to be authenticated somewhere. Often, you use a High-Privilege API key, OAuth token, or service account that Defenders cannot easily view. These “invisible” nonhuman identities (NHIS) […]