Fake WhatsApp API package on npm steals messages, contacts, and login tokens

Cybersecurity researchers have revealed details of a new malicious package on the npm repository. This package serves as a fully functional WhatsApp API, but also includes the ability to intercept all messages and link the attacker’s device to the victim’s WhatsApp account. The package named ‘lotusbail’ has been downloaded more than 56,000 times since it […]
Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

Dec 22, 2025Ravie LakshmananHacking News / Cybersecurity Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious breaches. The real danger now isn’t just one major […]
How to browse the web more sustainably with a green browser

As the Internet becomes an indispensable part of daily life, its environmental impact continues to increase. Data centers, constant connectivity, and resource-intensive browsing habits all contribute to energy consumption and digital waste. Although individual users may not feel this impact directly, the collective impact of daily browsing is significant. Choosing a browser designed with sustainability […]
Android malware operations massively merge dropper, SMS theft, and RAT capabilities

In a mobile attack targeting users in Uzbekistan, attackers were observed leveraging a malicious dropper app disguised as a legitimate application to deliver an Android SMS stealer called Wonderland. “Until now, users received ‘pure’ Trojan APKs that functioned as malware as soon as they were installed,” Group-IB said in an analysis published last week. “Attackers […]
Iran’s Infy APT resurfaces with new malware activity after years of silence

December 21, 2025Ravi LakshmananMalware/Cyber Espionage Nearly five years after the hacking group was observed targeting victims in Sweden, the Netherlands, and Turkey, threat hunters have discovered new activity linked to the Iranian threat actor known as Infy (also known as Prince of Persia). “The scale of Prince of Persia’s activities is more significant than we […]
US Department of Justice charges $54 for ATM jackpotting scheme using Ploutus malware

December 20, 2025Ravi LakshmananCybercrime/ATM Security The US Department of Justice (DoJ) announced this week that it has indicted 54 people in connection with a multi-million dollar ATM jackpot scheme. This massive conspiracy involved deploying malware named Ploutus to hack Automated Teller Machines (ATMs) across the United States and force them to withdraw cash. The indicted […]
Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025Ravi LakshmananCyber security/cloud security A group believed to be affiliated with Russia is believed to be behind a phishing campaign that uses device code authentication workflows to steal victims’ Microsoft 365 credentials and conduct account takeover attacks. This activity, which has been ongoing since September 2025, is tracked by Proofpoint under the name […]
Cracked software and YouTube videos spread CountLoader and GachiLoader malware

Cybersecurity researchers have revealed details of a new campaign that used a cracked software distribution site as a distribution vector for a new version of a modular stealth loader known as CountLoader. The Cyderes Howler Cell Threat Intelligence team said in its analysis that the campaign “uses CountLoader as the first tool in a multi-stage […]
WatchGuard warns of active exploitation of critical Fireware OS VPN vulnerability

December 19, 2025Ravi LakshmananVulnerability/Network Security WatchGuard has released a fix that addresses a critical security flaw in Fireware OS that was allegedly exploited in a real-world attack. The vulnerability is tracked as CVE-2025-14733 (CVSS score: 9.3) and is described as a case of an out-of-bounds write impacting the iked process, potentially allowing a remote unauthenticated […]
Nigeria arrests RaccoonO365 phishing developer involved in Microsoft 365 attack

December 19, 2025Ravi LakshmananCybercrime/Law Enforcement Nigerian authorities announced the arrest of three “prominent internet fraud suspects” suspected of involvement in phishing attacks targeting major companies, including the main developer of the RaccoonO365 phishing-as-a-service (PhaaS) scheme. The Nigeria Police National Cyber Crime Center (NPF-NCCC) said an investigation conducted in collaboration with Microsoft and the Federal Bureau […]