The new filefix method appears as a threat following a 517% increase in clickfix attacks

June 26, 2025Ravi LakshmananCyber Attacks/Malware Analysis According to ESET data, ClickFix social engineering tactics as initial access vectors using fake capture validation increased by 517% between the second half of 2024 and the first half of this year. “The list of threats led by Clickfix attacks grows day by day, including Infostealers, Ransomware, Remot Access […]
Why is the built-in protection in modern data resilience not enough?

SaaS adoption is rising rapidly, and resilience is not continuing to walk The SaaS platform has revolutionized the way businesses operate. Simplify collaboration, accelerate deployment, and reduce the overhead of managing your infrastructure. But as they rise, there are subtle and dangerous assumptions. The convenience of the Thirds extends to resilience. it’s not. These platforms […]
Iranian APT35 hacker targeting Israeli technical experts in AI-powered phishing attacks

June 26, 2025Ravi LakshmananCyber Spy/Malware The Iranian state-sponsored hacking group associated with the Islamic Revolutionary Security Force (IRGC) is linked to a spear phishing campaign targeting journalists, well-known cybersecurity experts and Israeli computer science professors. “In some of these campaigns, Israeli technology and cybersecurity experts were approached by attackers who pretended to be fictitious assistants […]
Cybercriminals are leveraging open source tools to compromise on financial institutions in Africa

June 26, 2025Ravi LakshmananThreat Intelligence/Ransomware Cybersecurity researchers have been bringing attention to a series of cyberattacks targeting African financial organizations since at least July 2023, using a combination of open source and public tools to maintain access. Palo Alto Networks Unit 42 refers to “Cl” to “Cluster”, and “CRI” to “Crimer Votivation” and “Cl” to […]
Cisa adds 3 flaws to the Kev catalog, affecting Ami Megarac, D-Link and Fortinet

June 26, 2025Ravi LakshmananVulnerability/Firmware Security The US Cybersecurity and Infrastructure Security Agency (CISA) added three security flaws on Wednesday. Each influenced Ami Megarac, D-Link Dir-859 router, and Fortinet Fortios, and was added to the Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Here’s the list of vulnerabilities – CVE-2024-54085 (CVSS score: 10.0) […]
WhatsApp adds AI-powered message summaries for faster chat previews

June 26, 2025Ravi LakshmananArtificial Intelligence/Data Protection Popular messaging platform WhatsApp has added a new AI-based feature that leverages internal solution meta AI to summarise unread messages in chat. Called a Message Summary, this feature is currently rolling out in English to US users, with plans to bring it to other regions and languages later this […]
Noauth’s vulnerability still affects 9% of Microsoft Entra SaaS apps two years after discovery

June 25th, 2025Ravi LakshmananSAAS Security/Vulnerabilities New research reveals the ongoing risks from known security weaknesses in Microsoft’s Entra ID, allowing malicious actors to achieve account acquisitions with sensitive software (SAAS) applications. Identity security company Semperis has found in an analysis of 104 SaaS applications that nine of them are vulnerable to cross-tenant Noauth abuse of […]
Citrix releases emergency patch for CVE-2025-6543 actively utilized in Netscaler ADC

June 25th, 2025Ravi LakshmananVulnerability/Network Security Citrix has released a security update to address critical flaws affecting Netscaler ADCs that are said to have been exploited by Wild. The CVSS score for vulnerabilities tracked as CVE-2025-6543 is 9.2 out of a maximum of 10.0. It is described as a case of memory overflow that can result […]
A defect in Citrix Bleed 2 allows token theft. SAP GUI is flawed in the risk of sensitive data exposure

June 25th, 2025Ravi LakshmananData Privacy/Vulnerability Cybersecurity researchers have detailed two currently patched security flaws in the SAP graphical user interface (GUI) for Windows and Java. The vulnerabilities tracked as CVE-2025-0055 and CVE-2025-0056 (CVSS score: 6.0) were patched by SAP as part of the January 2025 monthly update. “The study found that SAP GUI input history […]
Pro-Iranian hacktivist group leaks personal records from the 2024 Saudi Arabian game

The personal records of thousands of people allegedly linked to athletes and visitors to the Saudi Arabian game are published online by a group of hacktivists in Pruilla called Cyberfatta. The return of the cybersecurity company said that the violation was announced on Telegram in the form of a SQL database dump on June 22, […]