Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns
24
Jun
2025

Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns

The Department of Homeland Security has issued a critical advisory warning of escalating cyber threats from pro-Iranian hacktivist groups targeting…

NCSC Warns of SHOE RACK Malware Targeting Fortinet Firewalls via DOH & SSH Protocols
24
Jun
2025

NCSC Warns of SHOE RACK Malware Targeting Fortinet Firewalls via DOH & SSH Protocols

The National Cyber Security Centre (NCSC) has issued a critical alert regarding a newly identified malware, dubbed SHOE RACK, which…

Trojanized SonicWall NetExtender app exfiltrates VPN credentials
24
Jun
2025

Trojanized SonicWall NetExtender app exfiltrates VPN credentials

Unknown attackers have trojanized SonicWall’s SSL-VPN NetExtender application, the company has warned on Monday, and have been tricking users into…

The CTEM Conversation We All Need
24
Jun
2025

The CTEM Conversation We All Need

Jun 24, 2025Ravie LakshmananThreat Exposure Management I had the honor of hosting the first episode of the Xposure Podcast live…

Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data
24
Jun
2025

Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data

A sophisticated phishing campaign emerged in May 2025, targeting U.S. citizens through a coordinated impersonation of state Department of Motor…

Critical Convoy Flaw Allows Remote Code Execution on Servers
24
Jun
2025

Critical Convoy Flaw Allows Remote Code Execution on Servers

Credential Abuse Unmasked Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our…

One year since being freed, Julian Assange still a victim of state secrecy
24
Jun
2025

One year since being freed, Julian Assange still a victim of state secrecy

It is one year since WikiLeaks founder Julian Assange became a free man again. When he addressed the Council of…

Ransomware Africa 2024, Ransomware, Africa, Interpol,
24
Jun
2025

Africa Faces A Digital Sextortion Crisis As Numbers Surge

A continent-wide takedown of 63,000 Instagram accounts in Nigeria in mid-2024 has spotlighted one of Africa’s fastest growing cyber threats:…

Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers
24
Jun
2025

Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers

A sophisticated malware campaign has emerged targeting WordPress and WooCommerce websites with highly obfuscated credit card skimmers and credential theft…

OPPO Clone Phone Vulnerability Leaks Sensitive Data via Weak WiFi Hotspot
24
Jun
2025

OPPO Clone Phone Vulnerability Leaks Sensitive Data via Weak WiFi Hotspot

A newly disclosed security vulnerability in OPPO’s widely used Clone Phone app has raised significant concerns over user privacy, as…

Docker APIs to Mine Cryptocurrency
24
Jun
2025

Hackers Exploit Misconfigured Docker APIs to Mine Cryptocurrency via Tor Network

Jun 24, 2025Ravie LakshmananCloud Security / Cryptojacking Misconfigured Docker instances are the target of a campaign that employs the Tor…

Aviatrix Cloud Controller Authentication Vulnerability Let Attackers Execute Remote Code
24
Jun
2025

Aviatrix Cloud Controller Authentication Vulnerability Let Attackers Execute Remote Code

Two critical vulnerabilities in Aviatrix Controller, a Software-Defined Networking (SDN) utility that enables cloud connectivity across different vendors and regions. …