Category: TheHackerNews

EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations
29
Sep
2025

EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations

Threat actors have been observed using seemingly legitimate artificial intelligence (AI) tools and software to sneakily slip malware for future…

The State of AI in the SOC 2025
29
Sep
2025

The State of AI in the SOC 2025

Security leaders are embracing AI for triage, detection engineering, and threat hunting as alert volumes and burnout hit breaking points….

First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package
29
Sep
2025

First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package

Sep 29, 2025Ravie LakshmananMCP Server / Vulnerability Cybersecurity researchers have discovered what has been described as the first-ever instance of…

Microsoft Flags AI-Driven Phishing
29
Sep
2025

LLM-Crafted SVG Files Outsmart Email Security

Microsoft is calling attention to a new phishing campaign primarily aimed at U.S.-based organizations that has likely utilized code generated…

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks
27
Sep
2025

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

Sep 27, 2025Ravie LakshmananMalware / Network Security Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as…

SVG and PureRAT Phishing
26
Sep
2025

Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam

Sep 26, 2025Ravie LakshmananMalware / Cryptocurrency A new campaign has been observed impersonating Ukrainian government agencies in phishing attacks to…

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks
26
Sep
2025

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks

The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks…

Why BAS Is Proof of Defense, Not Assumptions
26
Sep
2025

Why BAS Is Proof of Defense, Not Assumptions

Sep 26, 2025The Hacker NewsSecurity Validation / Enterprise Security Car makers don’t trust blueprints. They smash prototypes into walls. Again…

26
Sep
2025

Why BAS Is Proof of Defense, Not Assumptions

Sep 26, 2025The Hacker NewsSecurity Validation / Enterprise Security Car makers don’t trust blueprints. They smash prototypes into walls. Again…

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
26
Sep
2025

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

Sep 26, 2025Ravie LakshmananMalware / Browser Security Cybersecurity researchers have discovered an updated version of a known Apple macOS malware…

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
26
Sep
2025

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

Sep 26, 2025Ravie LakshmananVulnerability / Threat Intelligence Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active…

Cisco ASA Firewall Zero-Day
26
Sep
2025

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

The U.K. National Cyber Security Centre (NCSC) has revealed that threat actors have exploited the recently disclosed security flaws impacting…