SecAlerts cuts through the noise with a smarter, faster way to track vulnerabilities

Vulnerability management is a core element of any cybersecurity strategy. But businesses often use thousands of pieces of software without realizing it (when was the last time you checked?), and tracking all the vulnerability alerts, notifications, and updates can strain resources and lead to vulnerabilities being missed. Considering that nearly 10% of vulnerabilities were exploited […]
Google patches 107 Android flaws, including two framework bugs that were exploited in the wild

December 2, 2025Ravi LakshmananMobile security/vulnerabilities Google on Monday released its monthly security update for its Android operating system, which included two vulnerabilities that have been reportedly exploited in the wild. The patch addresses a total of 107 security flaws across a variety of components, including frameworks, systems, and kernels, as well as components from Arm, […]
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

December 1, 2025Ravi LakshmananSurveillance/National Security India’s Ministry of Telecommunications has reportedly asked major mobile device manufacturers to preload the government-backed cybersecurity app Sanchar Saathi on all new mobile phones within 90 days. Reuters reports that the app cannot be removed or disabled from users’ devices. Sanchar Saathi is available on the web and via mobile […]
ShadyPanda turns popular browser extension with 4.3 million installs into spyware

The threat actor known as ShadyPanda has been involved in a seven-year browser extension campaign that has resulted in over 4.3 million installs. According to a report by Koui Security, five of these extensions started as legitimate programs and introduced malicious changes in mid-2024, garnering 300,000 installations. These extensions have since been removed. “These extensions […]
Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More

Dec 01, 2025Ravie LakshmananHacking News / Cybersecurity Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and turn them against us. One bad download can leak your keys. One weak vendor can expose many customers […]
Why the new AI browser wars are a nightmare for security teams

The AI browser wars are coming to a desktop near you and you should start worrying about security challenges. For the past 20 years, whether you’re using Chrome, Edge, or Firefox, the basic paradigm has remained the same. That is, it is a passive window through which human users view and interact with the Internet. […]
New Albiriox MaaS malware targets over 400 apps for on-device fraud and screen control

A new Android malware named Albiriox is being touted as based on a malware-as-a-service (MaaS) model that offers a “full range” of features that facilitate on-device fraud (ODF), screen manipulation, and real-time interaction with infected devices. The malware is embedded with a hardcoded list of over 400 applications spanning banking, financial technology, payment processors, cryptocurrency […]
Endpoint Permission Management – Keeper Security

temporary account Temporary system-generated privileged accounts are created and managed to perform specific elevated tasks and then automatically deleted to have zero permanent privileges and minimize security risks. Least privilege management Restrict users and systems to only the minimum access rights necessary to perform authorized tasks. Standards-based architecture Leverages industry protocols and specifications to allow […]
Tomiris moves to public service implants for stealthier C2 attacks on government targets

December 1, 2025Ravi LakshmananMalware/Threat Intelligence The attacker, known as Tomiris, is believed to have targeted the Russian Ministry of Foreign Affairs, intergovernmental organizations, and government agencies with the goal of establishing remote access and deploying additional tools. “These attacks highlight a notable change in Tomiris’ tactics, namely the increasing use of implants that leverage public […]
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

November 30, 2025Ravi LakshmananHacktivism / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog to include security flaws affecting OpenPLC ScadaBR, citing evidence of active exploitation. The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) flaw that affects Windows and Linux versions of […]