Asyncrat’s open source code causes a surge in dangerous malware variants around the world

Cybersecurity researchers show the evolution of widely used remote access called Asyncrat, which was first released on GitHub in January 2019 and has since served as the basis for several other variations. “Asyncrat has solidified its position as a cornerstone of modern malware and as a broad threat that has evolved into a vast network […]
North Korean hacker floods NPM registry with Xorindex malware in ongoing attack campaign

July 15th, 2025Ravi LakshmananMalware/Web Security North Korean threat actors linked to the infectious interview campaign have published another set of 67 malicious packages in the NPM registry, highlighting their ongoing attempts to poison the open source ecosystem via software supply chain attacks. The per-socket package attracts over 17,000 downloads and incorporates Xorindex, a previously undocumented […]
Unusual suspect: Git Repos

July 14, 2025Hacker NewsSecret Management / SAAS Security Phishing and ransomware dominate the headlines, but another serious risk follows quietly for most companies. The risk of quietly creating shadow access in the core system GIT is the backbone of modern software development, hosting millions of repositories and serving thousands of organizations around the world. However, […]
The new PHP-based interlock rat variant targets multiple industries using file fix delivery mechanisms

July 14, 2025Ravi LakshmananMalware/Web Security The threat actors behind the interlock ransomware group unlocked a new PHP variant of bespoke remote access Trojan (RAT) as part of a wide range of campaigns using a Clickfix variant called FileFix. “Since May 2025, interlock rat-related activities have been observed in connection with Landupdate808 (aka) Web Injection Threat […]
Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and More

In cybersecurity, precision matters—and there’s little room for error. A small mistake, missed setting, or quiet misconfiguration can quickly lead to much bigger problems. The signs we’re seeing this week highlight deeper issues behind what might look like routine incidents: outdated tools, slow response to risks, and the ongoing gap between compliance and real security. […]
CBI suspends £390k UK technical assistance fraud and arrests key operatives at Noida call centre

July 14, 2025Ravi LakshmananCybercrime/Law enforcement India’s Central Bureau of Investigation (CBI) has announced that it has taken steps to dismantle what it said was a cross-border cybercrime syndicate that carried out “sophisticated” technical assistance scams targeting citizens in Australia and the UK. The fraud scheme is estimated to have resulted in losses of more than […]
The ESIM vulnerability in Kigen’s EUICC card exposes billions of IoT devices to malicious attacks

July 14, 2025Ravi LakshmananMobile Security/Vulnerability Cybersecurity researchers have discovered new hacking techniques that take advantage of the weaknesses of ESIM technology used in modern smartphones and put users at serious risk. This issue affects Kigen EUICC cards. According to the Irish company’s website, as of December 2020, more than 1 billion SIMs are enabled for […]
New Rowhammer Attack Variant Degrades AI Models on Nvidia GPUs

July 12, 2025Ravi LakshmananAI Security/Vulnerability Nvidia is urging customers to enable system-level error correction codes (ECCs) as a defense against proven Rowhammer attack variants against graphics processing units (GPUs). “The risk of successful exploitation from a Rowhammer attack varies based on DRAM devices, platforms, design specifications and system settings,” GPU manufacturers said in an advisory […]
Over 600 laravel apps exposed to remote code execution due to app_keys leaked on github

Cybersecurity researchers weaponized Layave app_keys, which are leaking Laravel App_Keys, to discover serious security issues that allow hundreds of applications to gain remote code execution capabilities. “Laravel’s App_Key, essential for encrypting sensitive data, is often published (on GitHub, for example),” Gitguardian says. “If an attacker accesses this key, it can take advantage of the flaws […]
Fortinet releases patches for important SQL injection defects in Fortiweb (CVE-2025-25257)

July 11, 2025Ravi LakshmananUS Fortinet has released fixes for critical security flaws affecting FortiWeb. This allows an unauthorized attacker to execute arbitrary database commands on the sensitive instance. Tracked as CVE-2025-25257, the vulnerability has a CVSS score of 9.6 out of 10.0. Inappropriate neutralization of special elements used in SQL command (“SQL Injection”) vulnerabilities [CWE-89] […]