CISA reports Chinese hackers are using BRICKSTORM for long-term access to US systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor called BRICKSTORM that state-sponsored attackers from the People’s Republic of China (PRC) are using to maintain compromised systems for extended periods of time. “BRICKSTORM is an advanced backdoor for VMware vSphere and Windows environments,” the agency said. “BRICKSTORM enables cyber […]
JPCERT confirms active command injection attack against Array AG Gateway

December 5, 2025Ravi LakshmananVulnerability/Network Security A command injection vulnerability in Array Networks AG series secure access gateways has been exploited since August 2025, according to an alert issued by JPCERT/CC this week. This vulnerability, which does not have a CVE identifier, was resolved by the company on May 11, 2025. The vulnerability is rooted in […]
Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

A threat actor known as Silver Fox was discovered to be orchestrating false flag operations that mimic Russian threat groups in attacks targeting Chinese organizations. Search Engine Optimization (SEO) poisoning campaigns use Microsoft Teams lures to trick unsuspecting users into downloading malicious setup files, which lead to the deployment of ValleyRAT (Winos 4.0), a known […]
Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories

Dec 04, 2025Ravie LakshmananCybersecurity / Hacking News Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locked in a nonstop race to outsmart each other. Here’s a quick rundown of the latest cyber stories that show how fast the […]
5 threats that reshaped web security this year [2025]

As 2025 draws to a close, security professionals are faced with the sobering realization that traditional strategies for web security are dangerously outdated. AI-powered attacks, evolving injection techniques, and supply chain breaches affecting hundreds of thousands of websites have required a fundamental rethink of defense strategies. Here are five threats that reshaped web security this […]
GoldFactory hits Southeast Asia with modified banking app, infecting over 11,000 people

Cybercriminals associated with a financially motivated group known as GoldFactory have been observed launching new attacks targeting mobile users in Indonesia, Thailand, and Vietnam by impersonating government services. The activity, which has been observed since October 2024, involves the distribution of modified banking applications that act as a conduit for Android malware, Group-IB said in […]
Recorded 29.7 Tbps DDoS attack linked to AISURU botnet, infected up to 4 million hosts

December 4, 2025Ravi LakshmananDDoS attack/network security Cloudflare announced Wednesday that it detected and mitigated the largest distributed denial of service (DDoS) attack in history, reaching 29.7 terabits per second (Tbps). The web infrastructure and security company said the activity originated from a rental DDoS botnet known as AISURU, which has been linked to numerous high-volume […]
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

December 3, 2025Ravi LakshmananVulnerability / Cloud Security A maximum severity security flaw has been disclosed in React Server Components (RSC) that could allow remote code execution if successfully exploited. This vulnerability is tracked as CVE-2025-55182 and has a CVSS score of 10.0. The React team said in an alert issued today that this allows for […]
Microsoft silently patches Windows LNK flaw after years of active exploitation

December 3, 2025Ravi LakshmananVulnerabilities / Endpoint Security According to ACROS Security’s 0patch, Microsoft silently embedded a security flaw that has been exploited by multiple attackers since 2017 as part of the company’s November 2025 Patch Tuesday update. The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which is described as a Windows Shortcuts (LNK) file […]
WordPress King add-on flaw under active attack allows hackers to create administrator accounts

December 3, 2025Ravi LakshmananVulnerabilities / Website Security A critical security flaw affecting a WordPress plugin known as King Addons for Elementor is being exploited in the wild. This vulnerability, CVE-2025-8489 (CVSS score: 9.8), is a privilege escalation case that allows an unauthenticated attacker to grant themselves administrative privileges by simply specifying the administrator user role […]