TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files
22
Oct
2025

TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files

TARmageddon flaw in Async-Tar Rust library allows to smuggle extra archives when the library is processing nested TAR files Pierluigi…

Card
22
Oct
2025

PhantomCaptcha ClickFix attack targets Ukraine war relief orgs

A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for…

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts
22
Oct
2025

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts

Since its emergence in August 2022, Lumma Infostealer has rapidly become a cornerstone of malware-as-a-service platforms, enabling even unskilled threat…

Take It from a Former Pen Tester: Zero-Days Aren’t the Problem. One-Days Are.
22
Oct
2025

Take It from a Former Pen Tester: Zero-Days Aren’t the Problem. One-Days Are.

Let’s set the record straight: the greatest risk to most companies isn’t breaking news. It’s known weaknesses that are left…

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters
22
Oct
2025

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters

Cybercriminals continue to evolve their email phishing arsenals, reviving legacy tactics while layering on advanced evasions to slip past automated…

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys
22
Oct
2025

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

Oct 22, 2025Ravie LakshmananCryptocurrency / Software Integrity Cybersecurity researchers have uncovered a new supply chain attack targeting the NuGet package…

Atos boss ‘utterly determined’ not to allow GenAI to pull up career drawbridge
22
Oct
2025

Atos boss ‘utterly determined’ not to allow GenAI to pull up career drawbridge

Michael Herron, the UK head at French IT service provider Atos, has told Computer Weekly that ensuring future talent can…

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI | Blog
22
Oct
2025

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI | Blog

Amelia Coen | 22 October 2025 at 13:15 UTC In her latest video, CyberMaddy dives into the world of AI-driven…

Singapore cyber summit stresses need for unified front amid rising threats
22
Oct
2025

Singapore cyber summit stresses need for unified front amid rising threats

Experts and officials at a major cybersecurity summit in Singapore have called for deeper collaboration between governments and tech giants,…

Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition
22
Oct
2025

Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition

GitLab has urgently released patch versions 18.5.1, 18.4.3, and 18.3.5 for its Community Edition (CE) and Enterprise Edition (EE) to…

Injecting Malicious Code into RMClient to Evade EDR
22
Oct
2025

Injecting Malicious Code into RMClient to Evade EDR

CyberProof researchers detected a significant surge in Remcos (Remote Control & Surveillance Software) campaigns throughout September and October 2025, exploiting…

Rubrik Agent Cloud speeds enterprise AI with built-in security and guardrails
22
Oct
2025

Rubrik Agent Cloud speeds enterprise AI with built-in security and guardrails

Rubrik announced the launch of the Rubrik Agent Cloud to accelerate enterprise AI agent adoption while managing risk of AI…