Beware of Fake Error Pages Deploying Platform-Specific Malware on Linux and Windows Systems
25
Jul
2025

Beware of Fake Error Pages Deploying Platform-Specific Malware on Linux and Windows Systems

Wiz Research has uncovered an active cryptomining campaign, dubbed Soco404, that exploits misconfigurations in PostgreSQL databases and other cloud services…

U.S. Sanctions Firm Behind N. Korean IT Scheme; Arizona Woman Jailed for Running Laptop Farm
25
Jul
2025

U.S. Sanctions Firm Behind N. Korean IT Scheme; Arizona Woman Jailed for Running Laptop Farm

Jul 25, 2025Ravie LakshmananCybercrime / Insider Threat The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned…

US offers $15 million reward for info on North Korean nationals involved in global criminal network
25
Jul
2025

US offers $15 million reward for info on North Korean nationals involved in global criminal network

The State Department announced Thursday it will pay up to $15 million for information leading to the arrest of seven…

Critical VMware Tools VGAuth Vulnerabilities Enable Full System Access for Attackers
25
Jul
2025

Critical VMware Tools VGAuth Vulnerabilities Enable Full System Access for Attackers

Two critical vulnerabilities in the VMware Guest Authentication Service (VGAuth) component of VMware Tools allow local attackers to escalate privileges…

Hackers Use Weaponized .HTA Files to Infect Victims with Red Ransomware
25
Jul
2025

Hackers Use Weaponized .HTA Files to Infect Victims with Red Ransomware

CloudSEK’s TRIAD team uncovered an active development site deploying Clickfix-themed malware linked to the Epsilon Red ransomware. This variant deviates…

Remote Code Execution in Microsoft SharePoint (CVE-2025-53770) — API Security
25
Jul
2025

Remote Code Execution in Microsoft SharePoint (CVE-2025-53770) — API Security

On July 19, 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-53770, also referred to as ToolShell) was publicly disclosed,…

Microsoft Copilot Rooted to Gain Unauthorized Root Access to its Backend System
25
Jul
2025

Microsoft Copilot Rooted to Gain Unauthorized Root Access to its Backend System

A critical security vulnerability has been discovered in Microsoft Copilot Enterprise, allowing unauthorized users to gain root access to its…

Fake Indian Banking Apps on Android Steal Login Credentials from Users
25
Jul
2025

Fake Indian Banking Apps on Android Steal Login Credentials from Users

A malicious Android application has been uncovered, impersonating legitimate Indian banking apps to orchestrate credential theft, surveillance, and unauthorized financial…

Cyber Espionage
25
Jul
2025

Cyber Espionage Campaign Hits Russian Aerospace Sector Using EAGLET Backdoor

Jul 25, 2025Ravie LakshmananCyber Espionage / Malware Russian aerospace and defense industries have become the target of a cyber espionage…

The UK’s ransomware payment ban is a strategic win
25
Jul
2025

The UK’s ransomware payment ban is a strategic win

Back in January 2025 the UK government took an important step towards dismantling the ransomware economy by proposing a ban…

Multiple Vulnerabilities in Tridium Niagara Framework
25
Jul
2025

Multiple Vulnerabilities in Tridium Niagara Framework

Researchers identified 13 critical vulnerabilities in Tridium’s widely-deployed Niagara Framework that could allow attackers to compromise building automation systems and…

Fire Ant Hackers Target VMware ESXi and vCenter Flaws to Infiltrate Organizations
25
Jul
2025

Fire Ant Hackers Target VMware ESXi and vCenter Flaws to Infiltrate Organizations

Cybersecurity firm Sygnia has been tracking and mitigating a sophisticated espionage operation dubbed Fire Ant, which zeroes in on virtualization…