Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Scam

The threat actor known as Water Saci is actively evolving its tactics, switching to sophisticated, highly layered infection chains that use HTML application (HTA) files and PDFs to propagate a worm that deploys a banking Trojan via WhatsApp in attacks targeting users in Brazil. The latest wave is characterized by attackers moving from PowerShell to […]
Discover the AI tools that will fuel the next cybercrime wave — watch the webinar

December 3, 2025hacker newsCybercrime/Artificial Intelligence Remember when phishing emails were easy to spot? Bad grammar, weird formatting, and a request from a “prince” in a faraway land? Those days are over. Today, a 16-year-old with zero coding skills and $200 in pocket money can launch a campaign that rivals state-sponsored hackers. They don’t have to […]
Turn disruptive technologies into strategic advantages

Most people know the story of Paul Bunyan. Challenges from a giant lumberjack, his trusty axe, and a machine that promises to outdo him. Paul strained and swung harder the way he had before, but still lost a quarter of an inch. His mistake was not losing the contest. His mistake was believing that he […]
Picklescan bug could allow malicious PyTorch models to bypass scanning and execute code

December 3, 2025Ravi LakshmananMachine learning/vulnerabilities Three serious security flaws have been revealed in an open source utility called Picklescan. This flaw could allow a malicious attacker to load an untrusted PyTorch model and execute arbitrary code, effectively bypassing the tool’s protections. Picklescan, developed and maintained by Matthieu Maitre (@mmaitre314), is a security scanner designed to […]
Malicious Rust Crate delivers OS-specific malware to Web3 developer systems

December 3, 2025Ravi LakshmananMalware / Web3 Security Cybersecurity researchers have discovered a malicious Rust package with malicious functionality that can target Windows, macOS, and Linux systems and covertly run on developers’ machines under the guise of an Ethereum Virtual Machine (EVM) unit helper tool. The Rust crate named “evm-units” was uploaded to crates.io in mid-April […]
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

December 2, 2025Ravi LakshmananRegulatory Compliance/Online Safety India’s Department of Telecommunications (DoT) has directed app-based telecom service providers to ensure that their platforms cannot be used without an active SIM card linked to a user’s mobile number. To this end, messaging apps like WhatsApp, Telegram, Snapchat, Arattai, Sharechat, Josh, JioChat, Signal, i.e. Telecommunications Identified User Entities […]
Researchers Live Camera Live Camera of Lazarus APT’s Remote Worker Plan

December 2, 2025hacker newsIdentity Theft/Threat Intelligence A joint investigation led by Mauro Erdrich, founder of BCA LTD, and conducted in collaboration with NorthScan, a threat intelligence company, and ANY.RUN, an interactive malware analysis and threat intelligence solution, revealed a network of remote IT employees tied to one of North Korea’s most persistent intrusion schemes, the […]
GlassWorm returns with 24 malicious extensions masquerading as popular developer tools

December 2, 2025Ravi LakshmananMalware/Blockchain The supply chain campaign known as GlassWorm has gained momentum again, with 24 extensions masquerading as popular developer tools and frameworks, including Flutter, React, Tailwind, Vim, and Vue, infiltrating both Microsoft Visual Studio Marketplace and Open VSX. GlassWorm was first documented in October 2025, detailing its use of the Solana blockchain […]
Malicious npm package uses hidden prompts and scripts to evade AI security tools

December 2, 2025Ravi LakshmananAI Security/Software Supply Chain Cybersecurity researchers have revealed details of an npm package that attempts to influence artificial intelligence (AI)-powered security scanners. The package in question is eslint-plugin-unicorn-ts-2, which pretends to be a TypeScript extension for the popular ESLint plugin. This package was uploaded to the registry in February 2024 by a […]
Iran-linked hackers use new MuddyViper backdoor to attack Israeli sectors in targeted attacks

Israeli organizations across academia, engineering, local government, manufacturing, technology, transportation, and utilities sectors have emerged as targets of a new wave of attacks by Iranian nation-state actors who distributed a previously undocumented backdoor called MuddyViper. ESET believes this activity is the work of a hacking group known as MuddyWater (also known as Mango Sandstorm or […]