Matt Kapko
09
Oct
2025

SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal

A brute-force attack exposed firewall configuration files of every SonicWall customer who used the company’s cloud backup service, the besieged…

Hackers now use Velociraptor DFIR tool in ransomware attacks
09
Oct
2025

Hackers now use Velociraptor DFIR tool in ransomware attacks

Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit…

New Quishing Attack With Weaponized QR Code Targeting Microsoft Users
09
Oct
2025

New Quishing Attack With Weaponized QR Code Targeting Microsoft Users

Microsoft users are facing a novel quishing campaign that leverages weaponized QR codes embedded in malicious emails. Emerging in early…

Oracle tells clients of second recent hack
09
Oct
2025

Google says ‘likely over 100’ affected by Oracle-linked hacking campaign

Google said there were likely to be more than 100 companies affected by an ambitious hacking campaign that targeted Oracle’s…

ClayRat campaign uses Telegram and phishing sites to distribute Android spyware
09
Oct
2025

ClayRat campaign uses Telegram and phishing sites to distribute Android spyware

ClayRat campaign uses Telegram and phishing sites to distribute Android spyware Pierluigi Paganini October 09, 2025 ClayRat Android spyware targets…

Hackers steal Microsoft logins using legitimate ADFS redirects
09
Oct
2025

Hackers target universities in “payroll pirate” attacks

A cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in…

Threat Actors Mimic as HR Departments to Steal Your Gmail Login Credentials
09
Oct
2025

Threat Actors Mimic as HR Departments to Steal Your Gmail Login Credentials

A sophisticated phishing campaign has emerged targeting job seekers through legitimate Zoom document-sharing features, demonstrating how cybercriminals exploit trusted platforms…

scary VPN tunnel
09
Oct
2025

Fake VPN and streaming app drops malware that drains your bank account

Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over…

Hackers Upgraded ClickFix Attack With Cache Smuggling to Secretly Download Malicious Files
09
Oct
2025

Hackers Upgraded ClickFix Attack With Cache Smuggling to Secretly Download Malicious Files

Cybersecurity researchers have uncovered a sophisticated evolution of the ClickFix attack methodology, where threat actors are leveraging cache smuggling techniques…

Microsoft SQL Server
09
Oct
2025

Microsoft Defender mistakenly flags SQL Server as end-of-life

​Microsoft is working to resolve a known issue that causes its Defender for Endpoint enterprise endpoint security platform to incorrectly…

New Polymorphic Python Malware Repeatedly Mutate its Appearance at Every Execution Time
09
Oct
2025

New Polymorphic Python Malware Repeatedly Mutate its Appearance at Every Execution Time

A recently discovered Python-based remote access trojan (RAT) exhibits unprecedented polymorphic behavior, altering its code signature each time it runs….

Cybercriminals Impersonate HR Departments to Harvest Your Gmail Login Details
09
Oct
2025

Cybercriminals Impersonate HR Departments to Harvest Your Gmail Login Details

A seemingly legitimate Zoom document share from “HR” redirected victims through a fake bot-protection gate into a Gmail login phish….