AMD warns about new temporary scheduler attacks affecting a wide range of CPUs

July 10, 2025Ravi LakshmananVulnerability/Hardware Security Semiconductor Company AMD warns of a new set of vulnerabilities affecting a wide range of chipsets that could lead to information disclosure. A flaw, collectively known as transient scheduler attacks (TSAs), manifests in the form of a speculative side channel of a CPU that takes advantage of the timing of […]
ServiceNow Flaw CVE-2025-3648 can lead to data exposure via misunderstood ACLS

ServiceNow’s platform discloses high-strength security flaws, which, if exploited successfully, could lead to data exposure and removal. The vulnerability tracked as CVE-2025-3648 (CVSS score: 8.2) is described as a case of data inference on current platforms through conditional access control list (ACL) rules. There was a codename (ER) strike. “Vulnerabilities are currently being identified on […]
Gold Melody IAB exploits exposed ASP.NET machine keys to unauthorized access to targets

July 9, 2025Ravi LakshmananCyber Threats/Malware The first access broker (IAB), known as Gold Melody, is attributed to a campaign where they leak ASP.NET machine keys to gain unauthorized access to their organizations and gain access to other threat access people. This activity is tracked by Palo Alto Networks Unit 42 under the moniker TGR-CRI-0045, in […]
donot apt expands operations and targets the European Ministry of Foreign Affairs with lopticmod malware

July 9, 2025Ravi LakshmananMalware/Cyberspy Threat leaders suspected of ties with India have been observed targeting the European Foreign Office using malware that can harvest sensitive data from compromised hosts. This activity stems from a highly persistent threat (APT) group called the DONOT team, also known as the APT-C-35, Mint Tempest, Origami Elephant, Sector02, and Viceroy […]
North Korea Andariel Hacker Behind US Sanctions Fraudulent IT Worker Scheme

The U.S. Treasury Department’s Foreign Assets Administration Department (OFAC) approved members of a North Korean hacking group called Andariel on Tuesday for their role in the infamous Remote Information Technology (IT) worker scheme. The Treasury Ministry said Song Kum Heeok, a 38-year-old North Korean national with an address in Jiling Province, China, has enabled fraudulent […]
How to automate ticket creation, device identification, and threat triage with tines

July 9, 2025Hacker NewsSecurity Operations/Automation Run by teams on workflow orchestration and AI platform Tines, the Tines library features over 1,000 pre-built workflows shared by security practitioners from across the community. The latest standouts are workflows that handle malware alerts on Cloud Strike, Oomnitza, Github, and Pagerduty. The workflow developed by Lucas Cantor, creator of […]
Chinese hacker Xu Zewei has been arrested for linking between silk typhoon groups and US cyberattacks

July 9, 2025Ravi LakshmananCyber Spy/Threat Intelligence Chinese citizens were arrested in Milan, Italy for ties with a state-sponsored hacking group known as the Silk Typhoon and for carrying out cyberattacks on American organizations and government agencies. Xu Zewei, 33, was charged with nine wire fraud and conspiracy damage by committing unauthorized access to a protected […]
Includes Microsoft Patch 130 vulnerabilities, important flaws in SPNEGO and SQL Server

For the first time in 2025, Microsoft’s patch Tuesday update did not bundle fixes for exploited security vulnerabilities, but acknowledged that one of the flaws addressed was publicly known. The patch resolves a whopping 130 vulnerabilities along with Visual Studio, AMD, and 10 other non-microsoft CVEs that affect its chrome-based edge browsers. Of these 10, […]
Hackers use leaked shelter tool licenses to spread Lumma Stealer and Sectoprat malware

July 8, 2025Ravi LakshmananMalware/Cybercrime In yet another example of threat actors reusing legal tools for malicious purposes, hackers have been found using a popular red teaming tool called shelters to distribute steeler malware. The company behind the software said that the company that recently purchased a Shellter Elite license leaked a copy, urging malicious actors […]
Anatsa Android Banking Trojan hits 90,000 users with fake PDF apps on Google Play

July 8, 2025Ravi LakshmananMalware/Mobile Security Cybersecurity researchers have discovered an Android banking malware campaign that utilizes a Trojan horse named Anatsa, which targets North American users, using a malicious app published on Google’s official app marketplace. The malware, which pretends to be a “PDF update” to the document viewer app, provides a deceptive overlay when […]