New UEFI flaw allows early boot DMA attack on ASRock, ASUS, GIGABYTE, MSI motherboards

December 19, 2025Ravi LakshmananFirmware security/vulnerabilities Certain motherboard models from vendors such as ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by security vulnerabilities that make them susceptible to early-start direct memory access (DMA) attacks across architectures that implement Unified Extensible Firmware Interface (UEFI) or Input/Output Memory Management Unit (IOMMU). UEFI and IOMMU are designed to […]
China-aligned threat group uses Windows Group Policy to deploy espionage malware

December 18, 2025Ravi LakshmananMalware/Cloud Security A previously undocumented Chinese-aligned threat cluster called “LongNosed Goblin” is believed to have resulted from a series of cyberattacks targeting government agencies in Southeast Asia and Japan. Slovak cybersecurity company ESET said in a report released today that the ultimate goal of these attacks is cyber espionage. The threat activity […]
HPE OneView flaw assessed CVSS 10.0 allows unauthenticated remote code execution

December 18, 2025Ravi LakshmananVulnerabilities / Enterprise Security Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in its OneView software that could allow remote code execution if successfully exploited. This critical vulnerability has been assigned CVE identifier CVE-2025-37164 and has a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that […]
WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

Dec 18, 2025Ravie LakshmananCybersecurity / Hacking News This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s […]
Dynamic AI-SaaS security case study as co-pilot scales

Over the past year, artificial intelligence co-pilots and agents have quietly infiltrated the SaaS applications that enterprises use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow have built-in AI assistant or agent-like features. Virtually all major SaaS vendors are rushing to incorporate AI into their products. The result is an explosion of […]
Kimsuky spreads DocSwap Android malware via QR phishing disguised as a distribution app

December 18, 2025Ravi LakshmananMalware/Mobile Security The North Korean threat actor known as Kimsuky is said to be behind a new campaign distributing a new variant of Android malware called DocSwap via QR codes hosted on phishing sites imitating Seoul-based logistics company CJ Logistics (formerly CJ Korea Express). “The attackers used QR codes and notification pop-ups […]
CISA reports critical flaw in ASUS Live Update following evidence of active exploitation

December 18, 2025Ravi LakshmananVulnerabilities/Software Security The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw affecting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), is described as “embedding a malicious code vulnerability” introduced by a supply […]
Cisco warns of active attack exploiting unpatched zero-day in AsyncOS email security appliances

December 18, 2025Ravi LakshmananVulnerability/Network Security Cisco has warned users of a maximum severity zero-day vulnerability in Cisco AsyncOS Software. This vulnerability, codenamed UAT-9686, is being actively exploited by a Chinese-aligned Advanced Persistent Threat (APT) attacker in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The network equipment giant said it […]
SonicWall fixes actively exploited CVE-2025-40602 on SMA 100 appliances

December 17, 2025Ravi LakshmananVulnerability/Network Security SonicWall has published fixes to address security flaws in its Secure Mobile Access (SMA) 100 Series appliances. This flaw is reportedly being exploited in the wild. The vulnerability, tracked as CVE-2025-40602 (CVSS score: 6.6), involves a case of local privilege escalation that occurs as a result of insufficient authentication in […]
Kimwolf botnet hijacks 1.8 million Android TVs and launches massive DDoS attack

QiAnXin “Kimwolf is a botnet compiled using NDK [Native Development Kit]”In addition to typical DDoS attack capabilities, it integrates proxy forwarding, reverse shell, and file management capabilities,” the company said in a report released today. The hyperscale botnet is estimated to have issued 1.7 billion DDoS attack commands in a three-day period from November 19 […]