Fake OSINT and GPT utility GitHub repositories spread PyStoreRAT malware payload

Cybersecurity researchers are calling attention to a new campaign that leverages Python repositories hosted on GitHub to distribute a previously undocumented JavaScript-based remote access Trojan (RAT) called PyStoreRAT. “These repositories, often themed around development utilities or OSINT tools, contain just a few lines of code responsible for silently downloading a remote HTA file and running […]
New advanced phishing kit uses AI and MFA bypass tactics to steal credentials at scale

Cybersecurity researchers have documented four new phishing kits named BlackForce, GhostFrame, InboxPrime AI, and Spiderman that can facilitate large-scale credential theft. First detected in August 2025, BlackForce is designed to steal credentials and perform Man-in-the-Browser (MitB) attacks to capture one-time passwords (OTPs) and bypass multi-factor authentication (MFA). The kit is being sold on Telegram forums […]
Policies, isolation, and data controls that actually work

Browsers are the primary interface to GenAI for most enterprises, from web-based LLM and CoPilot to GenAI-powered extensions and agent browsers like ChatGPT Atlas. Employees leverage GenAI’s capabilities to draft emails, summarize documents, work with code, and analyze data by copying/pasting sensitive information directly into prompts or uploading files. Traditional security controls were not designed […]
New React RSC vulnerability allows DoS and source code disclosure

December 12, 2025Ravi LakshmananSoftware security/vulnerabilities The React team has released fixes for two new types of defects in React Server Components (RSC). Successful exploitation may lead to a denial of service (DoS) or source code disclosure. According to the team, this issue was discovered by the security community while attempting to exploit a patch released […]
React2Shell exploit escalates into massive global attack, forcing emergency mitigation

December 12, 2025Ravi LakshmananVulnerability/Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to patch recent vulnerabilities in React2Shell by December 12, 2025, amid reports of widespread exploitation. This critical vulnerability is tracked as CVE-2025-55182 (CVSS score: 10.0) and affects the React Server Components (RSC) Flight protocol. The root cause of […]
CISA reports actively exploited GeoServer XXE flaw in updated KEV catalog

December 12, 2025Ravi LakshmananVulnerabilities / Server Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw affecting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of real-world exploitation. The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML external entity (XXE) flaw that […]
Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories

Dec 11, 2025Ravie Lakshmanan This week’s cyber stories show how fast the online world can turn risky. Hackers are sneaking malware into movie downloads, browser add-ons, and even software updates people trust. Tech giants and governments are racing to plug new holes while arguing over privacy and control. And researchers keep uncovering just how much […]
NANOREMOTE malware uses Google Drive API for hidden controls on Windows systems

December 11, 2025Ravi LakshmananCyber Spy / Windows Security Cybersecurity researchers have revealed details of a new full-featured Windows backdoor called NANOREMOTE that uses the Google Drive API for command and control (C2) purposes. According to a report by Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (also known as Squidoor) […]
The impact of robotic process automation (RPA) on identity and access management

December 11, 2025hacker newsAutomation/Compliance As companies refine their strategies for handling non-human identifiers (NHI), robotic process automation (RPA) has become a powerful tool for streamlining operations and increasing security. However, RPA bots have different levels of access to sensitive information, so businesses should be prepared to mitigate different challenges. Bots are beginning to outnumber human […]
WIRTE uses AshenLoader sideloading to install AshTag spy backdoor

December 11, 2025Ravi LakshmananCyberwarfare/Threat Intelligence The Advanced Persistent Threat (APT), known as WIRTE, is believed to be the result of attacks targeting government and diplomatic organizations across the Middle East since 2020 using a previously undocumented malware suite called AshTag. Palo Alto Networks is tracking an activity cluster named Ashen Lepus. Artifacts uploaded to the […]