CISA warns of high-value signals and active spyware activity hijacking WhatsApp users

November 25, 2025Ravi LakshmananSpyware/Mobile Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday issued a warning about criminals actively using commercial spyware and remote access Trojans (RATs) to target users of mobile messaging applications. “These cyberattackers leverage sophisticated targeting and social engineering techniques to deliver spyware, gain unauthorized access to victims’ messaging apps, […]

New Fluent Bit flaw exposes cloud to RCE and stealth infrastructure intrusions

November 24, 2025Ravi LakshmananVulnerabilities / Container Security Cybersecurity researchers have discovered five vulnerabilities in Fluent Bit, an open-source lightweight telemetry agent. These can cascade to compromise and take over cloud infrastructure. Oligo Security said in a report shared with The Hacker News that the security flaw “allows an attacker to bypass authentication, perform path traversal, […]

Second Sha1-Hulud wave affects over 25,000 repositories via npm preinstall credential theft

November 24, 2025Ravi LakshmananCloud security/vulnerabilities Multiple security vendors are warning of a second wave of attacks targeting the npm registry in a manner reminiscent of the Shai-Hulud attack. Aikido, HelixGuard, Koi Security, Socket, and Wiz report that this new supply chain campaign, called Sha1-Hulud, compromised hundreds of npm packages. The trojanized npm package was uploaded […]

Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More

Nov 24, 2025Ravie LakshmananCybersecurity / Hacking News This week saw a lot of new cyber trouble. Hackers hit Fortinet and Chrome with new 0-day bugs. They also broke into supply chains and SaaS tools. Many hid inside trusted apps, browser alerts, and software updates. Big firms like Microsoft, Salesforce, and Google had to react fast […]

China’s DeepSeek-R1 AI generates unsafe code when mentioning Tibet or Uighurs in prompt

New research from CrowdStrike reveals that DeepSeek’s artificial intelligence (AI) inference model DeepSeek-R1 creates more security vulnerabilities in response to prompts containing topics deemed politically sensitive by China. “We found that when DeepSeek-R1 receives a prompt containing a topic that the Chinese Communist Party (CCP) considers politically sensitive, it increases the likelihood of generating code […]

ShadowPad malware actively exploits WSUS vulnerabilities to gain system-wide access

November 24, 2025Ravi LakshmananMalware/vulnerabilities A recently patched security flaw in Microsoft Windows Server Update Services (WSUS) was exploited by threat actors to distribute malware known as ShadowPad. “The attackers targeted Windows servers with WSUS enabled and exploited CVE-2025-59287 for initial access,” the AhnLab Security Intelligence Center (ASEC) said in a report released last week. “They […]

China-linked APT31 launches stealth cyber attack on Russian IT using cloud services

November 22, 2025Rabi LakshmananCyber ​​espionage / cloud security The China-linked Advanced Persistent Threat (APT) group, known as APT31, is blamed for a long period of undetected cyberattacks targeting Russia’s information technology (IT) sector from 2024 to 2025. “In 2024-2025, the Russian IT sector, especially companies working as contractors and integrators of government solutions, faced a […]

Matrix Push C2 uses browser notifications for fileless, cross-platform phishing attacks

Malicious attackers are leveraging browser notifications as a vector for phishing attacks to distribute malicious links using a new command-and-control (C2) platform called Matrix Push C2. “This browser-native fileless framework leverages push notifications, fake alerts, and link redirects to targeted victims across operating systems,” Blackfog researcher Brenda Robb said in a report Thursday. In these […]

CISA warns that critical zero-day vulnerability in Oracle Identity Manager is being actively exploited

November 22, 2025Rabi LakshmananZero-day/Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-61757 (CVSS score: 9.8), which could result in missing authentication for a critical function, […]

Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation

November 21, 2025Rabi LakshmananVulnerability/Threat Mitigation Grafana has released a security update to address a maximum severity security flaw that could allow privilege escalation and user impersonation under certain configurations. This vulnerability is tracked as CVE-2025-41115 and has a CVSS score of 10.0. It resides within the System for Cross-Domain Identity Management (SCIM) component, which enables […]