Android malware FvncBot, SeedSnatcher, and ClayRat gain stronger data theft capabilities

Cybersecurity researchers have revealed details of two new Android malware families called FvncBot and SeedSnatcher, as another upgraded version of ClayRat was discovered in the wild. The findings were obtained from Intel 471, CYFIRMA, and Zimperium, respectively. FvncBot targets Polish mobile banking users under the guise of a security app developed by mBank. What’s notable […]
Sneeit WordPress RCE in the wild as ICTBroadcast bug fuels Frost botnet attack

A critical security flaw in the Sneeit Framework plugin for WordPress is being exploited in the wild, according to data from Wordfence. The remote code execution vulnerability in question is CVE-2025-6389 (CVSS score: 9.8), which affects all versions of the plugin prior to 8.3. Patched in version 8.4 released on August 5, 2025. This plugin […]
Muddy Water deploys UDPGangster backdoor in campaigns targeting Turkey, Israel, and Azerbaijan

December 8, 2025Ravi LakshmananNetwork security/vulnerabilities An Iranian hacker group known as MuddyWater was observed leveraging a new backdoor called UDPGangster that uses User Datagram Protocol (UDP) for command and control (C2) purposes. According to a Fortinet FortiGuard Labs report, the cyber espionage campaign targeted users in Türkiye, Israel, and Azerbaijan. “This malware allows remote control […]
Researchers discover more than 30 flaws in AI coding tools that enable data theft and RCE attacks

December 6, 2025Ravi LakshmananAI security/vulnerabilities More than 30 security vulnerabilities have been uncovered in various artificial intelligence (AI)-powered integrated development environments (IDEs) that combine prompt injection primitives with legitimate functionality to enable data exfiltration and remote code execution. These security flaws were collectively named IDEsaster by security researcher Ari Marzouk (MaccariTA). These affect popular IDEs […]
React2Shell critical flaw added to CISA KEV after active exploitation

December 6, 2025Ravi LakshmananVulnerability/patch management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday officially added a critical security flaw affecting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild. This vulnerability, CVE-2025-55182 (CVSS score: 10.0), is related to remote code execution by […]
Zero-click agent browser attack could delete entire Google Drive using crafted email

December 5, 2025Ravi LakshmananEmail Security/Threat Investigation New agent browser attack targeting Perplexity’s Comet browser. A seemingly innocuous email can be turned into a destructive action that erases the entire contents of a user’s Google Drive, research from Striker STAR Labs reveals. Zero-click Google Drive wiper technology is all about automating everyday tasks by connecting your […]
Critical XXE bug CVE-2025-66516 (CVSS 10.0) in Apache Tika, urgent patch required

December 5, 2025Ravi LakshmananApplication security/vulnerabilities A critical security flaw has been disclosed in Apache Tika that could lead to an XML External Entity (XXE) injection attack. This vulnerability is tracked as CVE-2025-66516 and is rated 10.0 on the CVSS scoring scale, indicating maximum severity. According to the vulnerability advisory, “A critical XXE in the Apache […]
Chinese hackers have begun exploiting newly disclosed React2Shell vulnerabilities

December 5, 2025Ravi LakshmananVulnerabilities/Software Security Two Chinese-linked hacker groups were observed weaponizing a newly revealed security flaw in React Server Components (RSC) within hours of it becoming public knowledge. The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), also known as React2Shell, which allows unauthenticated remote code execution. This issue is addressed in React versions […]
Intellexa leak reveals zero-day and ad-based vectors for Predator spyware distribution

A human rights lawyer in Pakistan’s Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a member of the country’s civil society has been targeted by Intellexa’s Predator spyware, Amnesty International said in a report. The nonprofit said the link was a “predator attack attempt based on the […]
Anti-sales guide for MSPs

Most MSPs and MSSPs know how to provide effective security. The challenge is to help prospects understand why it’s important from a business perspective. Sales conversations often stall because prospects are overwhelmed, skeptical, or fed up with fear-based messages. That’s why we created “Getting to Yes”: An anti-sales guide for MSPs. This guide helps service […]