North Korea-linked attackers exploit React2Shell to deploy new EtherRAT malware

North Korean-linked attackers may have become the latest to exploit a recently revealed critical security React2Shell flaw in React Server Components (RSC) to deliver a previously undocumented remote access Trojan called EtherRAT. “EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and downloads its own Node.js runtime from nodejs.org,” […]
Four threat clusters use CastleLoader as GrayBravo expands its malware services infrastructure

December 9, 2025Ravi LakshmananCybersecurity/Malware Four different clusters of threat activity have been observed utilizing a malware loader known as CastleLoader, reinforcing previous assessments that this tool is being made available to other threat actors under a malware-as-a-service (MaaS) model. The threat actor behind CastleLoader has been assigned the name GrayBravo by Recorded Future’s Insikt Group, […]
Storm-0249 Using ClickFix, Fileless PowerShell, and DLL Sideloading to Escalate Ransomware Attacks

December 9, 2025Ravi LakshmananRansomware/Endpoint Security The threat actor known as Storm-0249 may be moving from its role as an initial access broker to a combination of more sophisticated tactics such as domain spoofing, DLL sideloading, and fileless PowerShell execution to facilitate ransomware attacks. “These techniques allow them to evade defenses, penetrate networks, maintain persistence, and […]
How to streamline zero trust using the shared signals framework

Zero Trust can help organizations reduce their attack surface and respond quickly to threats, but many companies still struggle to implement Zero Trust because security tools don’t reliably share signals. According to Accenture, 88% of organizations admit that they faced significant challenges when implementing such an approach. If the products cannot communicate, real-time access decisions […]
Google adds layered defenses to Chrome to block indirect prompt injection threats

Google on Monday announced a series of new security features for Chrome as it adds agent-based artificial intelligence (AI) capabilities to its web browser. To this end, the tech giant said it has implemented defense-in-depth to make it difficult for malicious parties to exploit indirect prompt injections that occur as a result of exposure to […]
Gold Blade deploys QWCrypt ransomware; 80% of STAC6565 attacks target Canada

A Canadian organization has emerged as the center of a targeted cyber campaign organized by the threat activity cluster known as STAC6565. Cybersecurity company Sophos announced that it investigated approximately 40 intrusions linked to this actor between February 2024 and August 2025. This campaign is assessed with high confidence to be an overlap with the […]
Researchers discover malicious VS Code, Go, npm, and Rust packages that steal developer data

December 9, 2025Ravi LakshmananMalware/Threat Analysis Cybersecurity researchers have discovered two new extensions in the Microsoft Visual Studio Code (VS Code) Marketplace that are designed to infect developers’ machines with stealer malware. The VS Code extension pretends to be a coding assistant powered by a premium dark theme and artificial intelligence (AI), but it actually hides […]
Experts confirm that JS#SMUGGLER uses compromised sites to deploy NetSupport RAT

Cybersecurity researchers are calling attention to a new campaign called JS#SMUGGLER. This campaign has been observed utilizing compromised websites as a distribution vector for a remote access Trojan named NetSupport RAT. The attack chain analyzed by Securonix includes three main moving parts: an obfuscated JavaScript loader injected into a website, an HTML application (HTA) that […]
USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More

Dec 08, 2025Ravie LakshmananHacking News / Cybersecurity It’s been a week of chaos in code and calm in headlines. A bug that broke the internet’s favorite framework, hackers chasing AI tools, fake apps stealing cash, and record-breaking cyberattacks — all within days. If you blink, you’ll miss how fast the threat map is changing. New […]
How can retailers stay cyber-secure during the most vulnerable time of the year?

December 8, 2025hacker news The holiday season compresses risk into a short, high-stakes window. Systems run hot, teams run lean, and attackers time automated campaigns for maximum profit. Multiple industry threat reports have found that bot fraud, credential stuffing, and account takeover attempts intensify around peak shopping events, particularly in the weeks around Black Friday […]