Will SOC save you?

Detection is considered a standard investment and first line of defense, so today’s enterprises are expected to have at least six to eight detection tools. However, security leaders have a hard time justifying dedicating resources to their superiors further downstream in the alert lifecycle. As a result, most organizations’ security investments are asymmetric and robust […]
Learn how to identify risks and safely patch using community-maintained tools

November 26, 2025hacker newsSoftware security/patch management If you’re using community tools like Chocolatey and Winget to keep your system up to date, you’re not alone. These platforms are fast, flexible, and easy to use, making them a favorite of IT teams. But there’s a catch… The very tools that make your job easier can also […]
Chrome extension found to be injecting hidden Solana transfer fees into Radium Swap

November 26, 2025Ravi LakshmananBrowser security / Cryptocurrency Cybersecurity researchers have discovered a new malicious extension in the Chrome Web Store that can insert stealthy Solana transfers into swap transactions and transfer funds to an attacker-controlled crypto wallet. The extension, named Crypto Copilot, was first published on May 7, 2024 by a user named ‘sjclark76’. The […]
RomCom uses SocGholish fake update attack to deliver Mythic Agent malware

November 26, 2025Ravi LakshmananMalware/Cyber Espionage The attackers behind the malware family known as RomCom targeted a US-based civil engineering company via a JavaScript loader called SocGholish and delivered the Mythic Agent. “This is the first time a RomCom payload has been observed being distributed by SocGholish,” Arctic Wolf Labs researcher Jacob Faires said in a […]
Researchers point to increase in AI phishing and holiday scams, FBI reports $262 million in ATO fraud

The US Federal Bureau of Investigation (FBI) has warned that cybercriminals are impersonating financial institutions with the aim of stealing money and confidential information to facilitate account takeover (ATO) fraud schemes. The agency said the campaign targets individuals, businesses and organizations of various sizes and sectors, adding that the fraudulent scheme has caused more than […]
Years of JSONFormatter and CodeBeautify leaks expose thousands of passwords and API keys

November 25, 2025Ravi LakshmananData Leak / Cloud Security A new study has found that organizations in a variety of sensitive sectors, including government, telecommunications, and critical infrastructure, are pasting passwords and credentials into online tools used to format and validate code, such as JSONformatter and CodeBeautify. Cybersecurity firm watchTowr Labs announced that it has captured […]
JackFix uses fake Windows Update pop-ups on adult sites to distribute multiple thieves

Cybersecurity researchers are warning of a new campaign that combines ClickFix lures with fake adult websites to trick users into running malicious commands under the guise of an “important” Windows security update. “The campaign utilizes fake adult websites (xHamster, a PornHub clone) as a phishing mechanism and is likely distributed via malvertising,” Acronis said in […]
ToddyCat’s new hacking tool steals Outlook emails and Microsoft 365 access tokens

November 25, 2025Ravi LakshmananMalware/vulnerabilities The attacker known as ToddyCat has been observed employing new methods to access corporate email data belonging to targeted companies, including using a custom tool called TCSectorCopy. “This attack allows the user’s browser to be used to obtain OAuth 2.0 authentication protocol tokens, which can be used to access corporate email […]
Three SOC challenges you need to solve by 2026

2026 will mark a pivotal shift in cybersecurity. Threat actors are moving from experimenting with AI to becoming a primary weapon, using it to scale attacks, automate reconnaissance, and create highly realistic social engineering campaigns. storm on the horizon Global instability and rapid technology advancements are forcing security teams to adapt not just their defensive […]
Hackers hijack Blender 3D assets and deploy StealC V2 data-stealing malware

November 25, 2025Ravi LakshmananMalware/Browser Security Cybersecurity researchers have revealed details of a new campaign that leverages Blender Foundation files to distribute an information theft tool known as StealC V2. “This ongoing operation, which has been active for at least six months, involves embedding malicious .blend files into platforms such as CGTrader,” Morphisec researcher Shmuel Uzan […]