Category: TheHackerNews

26
Sep
2025

Why BAS Is Proof of Defense, Not Assumptions

Sep 26, 2025The Hacker NewsSecurity Validation / Enterprise Security Car makers don’t trust blueprints. They smash prototypes into walls. Again…

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
26
Sep
2025

New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

Sep 26, 2025Ravie LakshmananMalware / Browser Security Cybersecurity researchers have discovered an updated version of a known Apple macOS malware…

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
26
Sep
2025

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

Sep 26, 2025Ravie LakshmananVulnerability / Threat Intelligence Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active…

Cisco ASA Firewall Zero-Day
26
Sep
2025

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

The U.K. National Cyber Security Centre (NCSC) has revealed that threat actors have exploited the recently disclosed security flaws impacting…

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
25
Sep
2025

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

Sep 25, 2025Ravie LakshmananMalvertising / Threat Intelligence The threat actor known as Vane Viper has been outed as a purveyor…

Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
25
Sep
2025

Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

Sep 25, 2025Ravie LakshmananZero-Day / Vulnerability Cisco is urging customers to patch two security flaws impacting the VPN web server…

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
25
Sep
2025

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

Sep 25, 2025Ravie LakshmananVulnerability / AI Security Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for…

North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers
25
Sep
2025

North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

The North Korea-linked threat actors associated with the Contagious Interview campaign have been attributed to a previously undocumented backdoor called…

CTEM's Core: Prioritization and Validation
25
Sep
2025

CTEM’s Core: Prioritization and Validation

Despite a coordinated investment of time, effort, planning, and resources, even the most up-to-date cybersecurity systems continue to fail. Every…

Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds
25
Sep
2025

Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

The latest Gcore Radar report analyzing attack data from Q1–Q2 2025, reveals a 41% year-on-year increase in total attack volume….

Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed
25
Sep
2025

Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

Sep 25, 2025Ravie LakshmananSoftware Security / Malware Cybersecurity researchers have discovered two malicious Rust crates impersonating a legitimate library called…

SNMP Vulnerability
25
Sep
2025

Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software

Sep 25, 2025Ravie LakshmananVulnerability / Network Security Cisco has warned of a high-severity security flaw in IOS Software and IOS…