CSA issues warning about critical remote code execution bug in SmarterMail

December 30, 2026Ravi LakshmananVulnerabilities / Email Security The Cyber Security Authority of Singapore (CSA) has issued a bulletin warning of a maximum severity security flaw in the SmarterTools SmarterMail email software that could be exploited to lead to remote code execution. This vulnerability is tracked as CVE-2025-52691 and has a CVSS score of 10.0. This […]
Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

The threat actor known as Silver Fox has shifted its focus to India, using income tax-themed decoys in phishing campaigns to distribute a modular remote access Trojan called ValleyRAT (also known as Winos 4.0). “This sophisticated attack utilizes a complex kill chain that includes DLL hijacking and a modular Valley RAT to ensure persistence,” CloudSEK […]
How to integrate AI into modern SOC workflows

Artificial intelligence (AI) is rapidly being introduced into security operations, but many practitioners still struggle to turn early experiments into consistent operational value. This is because SOCs are implementing AI without a deliberate approach to operational integration. Some teams treat this as a shortcut for broken processes. Some people try to apply machine learning to […]
Mustang Panda uses signed kernel-mode rootkit to load TONESHELL backdoor

December 30, 2026Ravi LakshmananMalware/Cyber Espionage A Chinese hacker group known as Mustang Panda utilized a previously undocumented kernel-mode rootkit driver to deliver a new variant of a backdoor called TONESHELL in a cyberattack detected targeting unspecified organizations in Asia in mid-2025. The findings, published by Kaspersky Lab, observed new backdoor variants in cyberespionage operations by […]
MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

Dec 29, 2026Ravie LakshmananHacking News / Cybersecurity Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common theme ran through it all […]
27 malicious npm packages used as phishing infrastructure to steal login credentials

Cybersecurity researchers have revealed details of what they say is a “persistent and targeted” spear-phishing campaign that published more than 20 packages in the npm registry to facilitate credential theft. According to Socket, the activity uploaded 27 npm packages from six different npm aliases and primarily targeted sales and sales personnel at organizations adjacent to […]
MongoDB vulnerability CVE-2025-14847 is being actively exploited worldwide

December 29, 2026Ravi LakshmananDatabase security/vulnerabilities A recently disclosed security vulnerability in MongoDB has been exploited in the wild, with over 87,000 potentially vulnerable instances identified worldwide. The vulnerability in question, CVE-2025-14847 (CVSS score: 8.7), could allow an unauthenticated remote attacker to leak sensitive data from the memory of a MongoDB server. The code name is […]
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, ChatGPT vulnerabilities allowed unauthorized extraction of user data from AI memory. The result: 23.77 million secrets were leaked through AI […]
New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory

December 27, 2025Ravi LakshmananDatabase security/vulnerabilities A high-severity security flaw has been identified in MongoDB that could allow an unauthenticated user to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), is described as a case of improper handling of length parameter mismatch. Length parameter mismatch occurs when a program fails to adequately […]
Trust Wallet Chrome Extension Compromise Causes $7M in Cryptocurrency Loss due to Malicious Code

December 26, 2025Ravi LakshmananCryptocurrency/Incident Response TrustWallet is urging users to update their Google Chrome extension to the latest version following what it calls a “security incident” that resulted in approximately $7 million in losses. The issue affects version 2.68, according to the multichain non-custodial cryptocurrency wallet service. According to the Chrome Web Store listing, the […]