China-linked evasive panda runs DNS poisoning campaign delivering MgBot malware

A China-linked Advanced Persistent Threat (APT) group has been implicated in targeted cyber espionage operations. In this campaign, adversaries compromised domain name systems (DNS) and requested delivery of its signature MgBot backdoor in attacks targeting victims in Turkiye, China, and India. Kaspersky said the activity was observed from November 2022 to November 2024. The activity […]
Critical vulnerability in LangChain core exposes secrets via serialization injection

December 26, 2025Ravi LakshmananAI Security / DevSecOps A critical security flaw has been revealed in LangChain Core. It can also be exploited by an attacker to steal sensitive secrets and influence large-scale language model (LLM) responses through prompt injection. LangChain Core (i.e. langchain-core) is a core Python package that is part of the LangChain ecosystem […]
Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories

Dec 25, 2025Ravie LakshmananCybersecurity / Hacking News It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and even AI assistants. What used to feel like clear-cut “hacker stories” now looks more like a mirror of […]
LastPass 2022 breach led to years of crypto theft, TRM Institute finds

December 25, 2025Ravi LakshmananData breach/financial crime Encrypted vault backups stolen in the 2022 LastPass data breach allowed attackers to exploit weak master passwords to crack passwords and exfiltrate cryptocurrency assets, according to new research from TRM Labs. The blockchain intelligence firm said there is evidence that Russian cybercriminals are involved in this activity, and that […]
Fortinet warns of active exploitation of FortiOS SSL VPN 2FA bypass vulnerability

December 25, 2025Ravi LakshmananVulnerabilities / Enterprise Security Fortinet announced Wednesday that it has seen “recent exploitation” of a five-year-old security flaw in FortiOS SSL VPN under certain configurations. The vulnerability in question, CVE-2020-12812 (CVSS score: 5.2), is an improper authentication vulnerability in SSL VPN in FortiOS that could allow a user to successfully log in […]
CISA reports remote code execution vulnerability in Digiever NVR is being actively exploited

December 25, 2025Ravi LakshmananVulnerabilities / Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw affecting the Digiever DS-2105 Pro network video recorder (NVR) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This vulnerability is tracked as CVE-2023-52163 (CVSS score: 8.8) and is related to a […]
New MacSync macOS stealer uses signed apps to bypass Apple gatekeeper

December 24, 2025Ravi LakshmananMalware/Endpoint Security Cybersecurity researchers have discovered a new variant of the macOS information stealer called MacSync, which is delivered by digitally signed and notarized Swift applications disguised as messaging app installers that bypass Apple’s Gatekeeper checks. “Unlike previous MacSync Stealer variants that primarily rely on device dragging and ClickFix-style techniques, this sample […]
Nomani investment scams using AI deepfake ads on social media soar to 62%

December 24, 2025Ravi LakshmananOnline fraud/artificial intelligence According to ESET data, the fraudulent investment scheme known as Nomani has increased by 62%, and campaigns distributing this threat have expanded beyond Facebook to other social media platforms such as YouTube. A Slovak cybersecurity company said it has blocked more than 64,000 unique URLs related to the threat […]
3 ways to protect your business in 2026

December 24, 2025hacker newsPassword management/access control Every year, cybercriminals discover new ways to steal money and data from businesses. Breaking into business networks, extracting sensitive data, and selling it on the dark web has become a reliable source of income. But in 2025, data breaches affecting small and medium-sized businesses (SMBs) challenged our conventional wisdom […]
SEC charges more than $14 million in crypto fraud using fake AI-themed investment tips

December 24, 2025Ravi LakshmananArtificial intelligence/virtual currency The U.S. Securities and Exchange Commission (SEC) has charged multiple companies with engaging in an elaborate cryptocurrency scam that defrauded retail investors of more than $14 million. The complaint also charges crypto trading platforms Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc., as well as investment […]