Category: TheHackerNews

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
09
May
2025

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials

May 09, 2025Ravie LakshmananSupply Chain Attack / Malware Cybersecurity researchers have flagged three malicious npm packages that are designed to…

Building AI Agents Securely
09
May
2025

Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business

May 09, 2025The Hacker NewsArtificial Intelligence / Software Security AI agents are changing the way businesses work. They can answer…

Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
09
May
2025

Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

May 09, 2025Ravie LakshmananMalware / Email Security Cybersecurity researchers are warning of a new campaign that’s targeting Portuguese-speaking users in…

Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
09
May
2025

Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android

May 09, 2025Ravie LakshmananArtificial Intelligence / Online Fraud Google on Thursday announced it’s rolling out new artificial intelligence (AI)-powered countermeasures…

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
09
May
2025

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

May 09, 2025Ravie LakshmananVulnerability / Industrial Security A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently…

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
08
May
2025

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases

Cybersecurity researchers have exposed what they say is an “industrial-scale, global cryptocurrency phishing operation” engineered to steal digital assets from…

SonicWall
08
May
2025

SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

May 08, 2025Ravie LakshmananNetwork Security / Vulnerability SonicWall has released patches to address three security flaws affecting SMA 100 Secure…

NETXLOADER Malware
08
May
2025

Qilin Leads April 2025 Ransomware Spike with 45 Breaches Using NETXLOADER Malware

May 08, 2025Ravie LakshmananThreat Intelligence / Ransomware Threat actors with ties to the Qilin ransomware family have leveraged malware known…

ROAMINGMOUSE and Upgraded ANEL Malware
08
May
2025

MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware

May 08, 2025Ravie LakshmananMalware / Cyber Espionage The nation-state threat actor known as MirrorFace has been observed deploying malware dubbed…

Security Tools Alone Don't Protect You — Control Effectiveness Does
08
May
2025

Security Tools Alone Don’t Protect You — Control Effectiveness Does

61% of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This…

LOSTKEYS Malware
08
May
2025

Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware

The Russia-linked threat actor known as COLDRIVER has been observed distributing a new malware called LOSTKEYS as part of an…

Cisco Patches CVE-2025-20188
08
May
2025

Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT

May 08, 2025Ravie LakshmananVulnerability / Network Security Cisco has released software fixes to address a maximum-severity security flaw in its…