Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

July 5, 2025Ravi LakshmananNational Security / Privacy Taiwan’s National Security Agency (NSB) warns that China-developed applications such as Renote (aka Xiaohongshu), Weibo, Tiktok, Wechat and Baidu Cloud pose security risks due to excessive data collection and data transfer to China. This vigilance follows an inspection of these apps, carried out in coordination with the Judicial […]

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

Threat actors weaponize exposed Java Debug Wire Protocol (JDWP) interfaces to obtain code execution capabilities and deploy cryptocurrency miners to compromised hosts. “Attackers can use modified versions of XMRIG in hard “coded configurations to avoid suspicious command line arguments that are often flagged by defenders,” Wiz researchers Yaara Shriki and Gili Tikochinski said in a […]

Nighteagle apt exploits Microsoft Exchange flaws to target China’s military and technical sectors

July 4, 2025Ravi LakshmananZero Day / Cyber ​​Spy Cybersecurity researchers are shedding light on a previously undocumented threat actor called Nighteagle (aka APT-Q-95), which has been observed to target Microsoft Exchange Servers as part of a zero-day exploit chain targeting China’s government, defense and technology sectors. According to Qianxin’s Reddrip team, the threat actor has […]

AI Agent may be leaking data – Watch this webinar and learn how to stop it

July 4, 2025Hacker NewsAI Security/Enterprise Security Generic AI is changing how companies work, learn and innovate. But under the surface, something dangerous is happening. AI Agents and Custom Genei Workflows create new hidden ways for sensitive enterprise data to leak. Most teams don’t understand that. If you’re building, deploying or managing your AI system, is […]

A critical sudo vulnerability allows local users to gain root access to Linux and affect major distributions

July 4, 2025Ravi LakshmananVulnerability / Linux Cybersecurity researchers have disclosed two security flaws in SUDO command line utilities in operating systems like Linux and UNIX, allowing local attackers to escalate the privileges of rooting sensitive machines. A brief explanation of the vulnerability can be found below: CVE-2025-32462 (CVSS score: 2.8) – Use in a sudoers […]

Large Android scam business has been revealed: Iconads, KaleIdoscope, SMS Malware, NFC Scams Identified apps are designed to load out-of-context ads on users’ screens and hide icons from the device’s home screen launcher, making it difficult for victims to remove them according to the company’s Satori Threat Intelligence and Research team. The app was then removed from the Play Store by Google. Advertising fraud schemes accounted for 1.2 billion bid requests per day due to their high activity. The majority of Iconads-related traffic comes from Brazil, Mexico and the United States. Iconads is a variant of the threat tracked by other cybersecurity vendors under the name Hiddedads and Vapor, and since at least 2019, malicious apps have been sliding around the Google Play Store repeatedly. Some of the common features of these apps include the use of obfuscation for concealment…

Large Android scam business has been revealed: Iconads, KaleIdoscope, SMS Malware, NFC Scams Identified apps are designed to load out-of-context ads on users’ screens and hide icons from the device’s home screen launcher, making it difficult for victims to remove them according to the company’s Satori Threat Intelligence and Research team. The app was then […]

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Steal User Assets

July 3, 2025Ravi LakshmananBrowser Security/Cryptocurrency Cybersecurity researchers have discovered over 40 malicious browser extensions from Mozilla Firefox, designed to steal cryptocurrency wallet secrets and put users’ digital assets at risk. “These extensions impersonate legal wallet tools from widely used platforms such as Coinbase, Metamask, Trust Wallet, Phantom, Exodus, OKX, Keplr, Mymonero, Bitget, Leap, Ethereum Wallet, […]

The Hidden Weaknesses in AI SOC Tools that No One Talks About

If you’re evaluating AI-powered SOC platforms, you’ve likely seen bold claims: faster triage, smarter remediation, and less noise. But under the hood, not all AI is created equal. Many solutions rely on pre-trained AI models that are hardwired for a handful of specific use cases. While that might work for yesterday’s SOC, today’s reality is […]

Chinese hackers abuse Ivanti CSA Zero Day in attacks on French government, communications

July 3, 2025Ravi LakshmananThreat Intelligence/Vulnerability On Tuesday, the French cybersecurity agency revealed that many entities across the domestic government, telecommunications, media, finance and transportation sectors were affected by a malicious campaign undertaken by Chinese hacking groups by weaponizing zero-day vulnerabilities in Ivanti Cloud Services Appliances (CSA) devices. The campaign detected in early September 2024 is […]