# InfosecToday.com > Information Security and AI ## Posts - [KillSec ransomware targeting healthcare IT systems](https://infosectoday.com/cybersecurity/killsec-ransomware-targeting-healthcare-it-systems/): The KillSec ransomware strain has quickly emerged as a significant threat to healthcare IT infrastructures across Latin America and beyond. First identified in early September 2025, KillSec operators have exploited compromised software supply chain relationships to deploy their malicious payloads at scale. Initial signs of compromise were detected when several Brazilian healthcare providers reported unusual network traffic originating from cloud storage buckets. Uniquely, this group combines basic exfiltration methods, such as open AWS S3 buckets, with advanced encryption routines, maximising impact while minimising the complexity of initial intrusions. Resecurity analysts observed that KillSec’s entry points often involve unpatched web applications […] - [HiddenGh0st, Winos, and kkRAT using SEO strategies and GitHub pages](https://infosectoday.com/cybersecurity-threats/hiddengh0st-winos-and-kkrat-are-utilizing-seo-strategies-and-github-pages-in-their-chinese-malware-assaults/): Chinese-speaking users have become the primary target of a malicious search engine optimisation (SEO) poisoning campaign. This campaign employs fake software sites to distribute malware, posing significant risks to unsuspecting individuals. According to Fortinet FortiGuard Labs researcher Pei Han Liao, the attackers have manipulated search rankings by utilising SEO plugins. They have also registered lookalike domains that closely resemble legitimate software sites, making it difficult for users to discern the difference. This deceptive strategy aims to lure users into downloading harmful software under the guise of legitimate applications. The attackers have crafted their content using convincing language and small character […] - [Runtime visibility indispensable in cloud-native security](https://infosectoday.com/cloud-native-security-challenges/runtime-visibility-indispensable-in-cloud-native-security/): The security landscape for cloud-native applications is undergoing a significant transformation as Containers, Kubernetes, and Serverless technologies become the standard for modern enterprises. This shift accelerates delivery but also expands the attack surface in ways that traditional security models struggle to address. As adoption increases, so does complexity, with security teams tasked to monitor sprawling hybrid environments and sift through thousands of alerts. The challenge is not only to detect risks earlier but also to prioritise and respond to what truly matters in real time. Cloud-Native Application Protection Platforms (CNAPPs) emerge as a solution, consolidating visibility, compliance, detection, and response […] - [Cursor AI Code Editor getting hammered through compromised repositories](https://infosectoday.com/security-vulnerabilities/cursor-ai-code-editor-getting-hammered-through-compromised-repositories/): A security vulnerability has been identified in the AI-powered code editor Cursor, which could allow code execution when a maliciously crafted repository is opened. This issue arises from the default disabling of an important security feature known as Workspace Trust. According to Oasis Security, Cursor’s configuration permits VS Code-style tasks to auto-execute upon opening a project folder, which can lead to silent code execution if a malicious .vscode/tasks.json file is present. This flaw poses significant risks, as attackers can embed hidden “autorun” instructions in projects hosted on platforms like GitHub, enabling the execution of harmful code when users inadvertently browse […] - [Chinese APT group infiltrated Philippine military with EggStreme fileless malware](https://infosectoday.com/cybersecurity-threats/chinese-apt-group-infiltrated-philippine-military-with-eggstreme-fileless-malware/): An advanced persistent threat (APT) group from China has been linked to the compromise of a military company based in the Philippines, employing a previously undocumented fileless malware framework known as EggStreme. This sophisticated multi-stage toolset facilitates persistent and low-profile espionage by injecting malicious code directly into memory and utilising DLL sideloading to execute payloads. According to Bitdefender researcher Bogdan Zavadovschi, the core component, EggStremeAgent, functions as a comprehensive backdoor that allows for extensive system reconnaissance, lateral movement, and data theft through an injected keylogger. The targeting of the Philippines aligns with a recurring pattern observed in Chinese state-sponsored hacking […] - [Akira ransomware attackers actively exploiting SonicWall SSL VPN](https://infosectoday.com/ransomware-threats/akira-ransomware-attackers-actively-exploiting-sonicwall-ssl-vpn/): Threat actors associated with the Akira ransomware group have intensified their focus on SonicWall devices for initial access. Cybersecurity firm Rapid7 reported a notable increase in intrusions involving SonicWall appliances, particularly following a resurgence of Akira ransomware activity since late July 2025. SonicWall disclosed that the SSL VPN activity targeting its firewalls exploited a year-old security vulnerability (CVE-2024-40766, CVSS score: 9.3), where local user passwords were not reset during migration. The company observed a rise in brute-force attempts on user credentials and recommended that customers enable Botnet Filtering to block known threat actors and implement Account Lockout policies to mitigate […] - [Counterfeit Madgicx Plus and SocialMetrics extensions hijacking Meta business accounts](https://infosectoday.com/malvertising-campaigns/counterfeit-madgicx-plus-and-socialmetrics-extensions-hijacking-meta-business-accounts/): Cybersecurity researchers have revealed two new campaigns that distribute fake browser extensions through malicious advertisements and counterfeit websites to steal sensitive data. The first campaign, identified by Bitdefender, promotes a fraudulent “Meta Verified” browser extension called SocialMetrics Pro, which falsely claims to unlock the blue check badge for Facebook and Instagram profiles. At least 37 malicious ads have been detected promoting this extension. These ads are accompanied by a video tutorial that instructs viewers on how to download and install the extension, which purports to unlock special features on Facebook. However, the extension, hosted on a legitimate cloud service called […] - [AsyncRAT Takes Advantage of ConnectWise ScreenConnect to Capture Credentials and Cryptocurrency](https://infosectoday.com/remote-access-trojans/asyncrat-takes-advantage-of-connectwise-screenconnect-to-capture-credentials-and-cryptocurrency/): Cybersecurity researchers have revealed a new campaign that exploits ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deploy a fileless loader that delivers a Remote Access Trojan (RAT) known as AsyncRAT. According to a report from LevelBlue shared with The Hacker News, attackers utilise ScreenConnect to gain remote access and execute a layered Visual Basic Script and PowerShell loader that retrieves obfuscated components from external URLs. These components include encoded .NET assemblies that ultimately unpack into AsyncRAT, maintaining persistence through a deceptive scheduled task labelled as ‘Skype Updater’. The infection chain involves threat actors leveraging a ScreenConnect […] - [CHILLYHELL macOS Backdoor and ZynorRAT remote access trojan threat to all operating systems](https://infosectoday.com/malware-families/chillyhell-macos-backdoor-and-zynorrat-remote-access-trojan-rat-pose-risks-to-macos-windows-and-linux-operating-systems/): Cybersecurity researchers have identified two new malware families, including a modular Apple macOS backdoor named CHILLYHELL and a Go-based Remote Access Trojan (RAT) called ZynorRAT, which can target both Windows and Linux systems. An analysis from Jamf Threat Labs indicates that CHILLYHELL is written in C++ and designed for Intel architectures. This malware is attributed to an uncategorised threat cluster known as UNC4487, which is believed to have been active since at least October 2022. Threat intelligence shared by Google Mandiant suggests that UNC4487 is a suspected espionage actor that has compromised the websites of Ukrainian government entities to redirect […] - [APT41 hackers targeting US trade officials as talks with China approach](https://infosectoday.com/cyber-espionage/apt41-hackers-targeting-us-trade-officials-as-talks-with-china-approach/): The House Select Committee on China has issued a formal advisory regarding an ongoing series of targeted cyber espionage campaigns linked to the People’s Republic of China (PRC). These campaigns aim to compromise organisations and individuals involved in U.S.–China trade policy and diplomacy, including U.S. government agencies, business organisations, law firms, think tanks, and at least one foreign government. The committee reported that suspected Chinese threat actors impersonated Republican Party Congressman John Robert Moolenaar in phishing emails sent to trusted counterparts. Their objective was to deceive recipients into opening files and links that would provide unauthorized access to sensitive information […] - [New phishing tool Salty2FA bypasses two-factor authentication](https://infosectoday.com/targeted-industries/new-phishing-tool-salty2fa-bypasses-two-factor-authentication/): Phishing-as-a-Service (PhaaS) platforms continue to evolve, providing attackers with faster and cheaper methods to infiltrate corporate accounts. Researchers at ANY.RUN have identified a new threat: Salty2FA, a phishing kit engineered to circumvent various two-factor authentication (2FA) methods and evade traditional security measures. This kit has already been detected in campaigns across the United States and Europe, posing significant risks to enterprises in sectors ranging from finance to energy. Salty2FA’s multi-stage execution chain, evasive infrastructure, and capability to intercept credentials and 2FA codes render it one of the most perilous PhaaS frameworks observed this year. Salty2FA raises the stakes for enterprises […] - [Cryptojacking attack using TOR infiltrates misconfigured Docker APIs](https://infosectoday.com/cryptojacking/cryptojacking-attack-using-tor-infiltrates-misconfigured-docker-apis/): Cybersecurity researchers have identified a new variant of a previously disclosed campaign that exploits the TOR network for cryptojacking attacks aimed at exposed Docker APIs. Akamai, which uncovered this recent activity last month, indicated that the campaign is designed to prevent other actors from accessing the Docker API over the internet. These findings build upon an earlier report from Trend Micro in late June 2025, which revealed a malicious campaign targeting exposed Docker instances to stealthily deploy an XMRig cryptocurrency miner via a TOR domain for anonymity. Security researcher Yonatan Gilvarg noted that this new strain appears to utilise similar […] - [GPUGate malware using Google Ads and counterfeit GitHub commits](https://infosectoday.com/cybersecurity-threats/gpugate-malware-using-google-ads-and-counterfeit-github-commits/): Cybersecurity researchers have uncovered a sophisticated malware campaign that utilises paid advertisements on search engines like Google to deliver malware to unsuspecting users searching for popular tools such as GitHub Desktop. This campaign introduces a novel twist to traditional malvertising by embedding a GitHub commit into a page URL, which contains altered links that redirect to attacker-controlled infrastructure. Even when a link appears to lead to a reputable platform like GitHub, the underlying URL can be manipulated to direct users to counterfeit sites. The campaign has specifically targeted IT and software development companies in Western Europe since at least December […] - [Chinese agents reportedly posed as US congressman to transmit malware](https://infosectoday.com/cyber-espionage/chinese-agents-reportedly-posed-as-us-congressman-to-transmit-malware/): China’s APT41 has been implicated in a sophisticated cyber espionage operation, where they impersonated U.S. Representative John Moolenaar to distribute malicious emails. These emails were aimed at trade groups in an effort to gather sensitive information ahead of critical U.S.-China trade negotiations. The operation highlights the increasing threat posed by state-sponsored hackers, particularly as geopolitical tensions rise. By masquerading as a legitimate U.S. lawmaker, APT41 sought to exploit the trust associated with official communications, thereby enhancing the likelihood of successful malware delivery. The report underscores the need for heightened vigilance among organisations involved in trade discussions with China. Cybersecurity experts […] - [GitHub workflow breaches impact multiple repositories](https://infosectoday.com/cybersecurity-threats/github-workflow-breaches-impact-multiple-repositories/): A supply chain attack known as GhostAction has emerged, allowing threat actors to infiltrate systems and steal sensitive information. This sophisticated attack has particularly targeted GitHub workflows, affecting hundreds of repositories and compromising thousands of secrets. By exploiting vulnerabilities within these workflows, attackers have been able to gain unauthorised access to critical data, raising significant concerns about the security of software development processes. The implications of such breaches are profound, as they not only jeopardise individual projects but also threaten the integrity of the broader software ecosystem. The GhostAction attack highlights the urgent need for enhanced security measures within development […] - [Lazarus Group boosts malware tools with PondRAT, ThemeForestRAT, & RemotePE](https://infosectoday.com/cybersecurity-threats/lazarus-group-boosts-malware-tools-with-pondrat-themeforestrat-remotepe/): The North Korea-linked threat actor known as the Lazarus Group has been linked to a social engineering campaign that distributes three distinct pieces of cross-platform malware: PondRAT, ThemeForestRAT, and RemotePE. This attack, observed by NCC Group’s Fox-IT in 2024, targeted an organisation in the Decentralised Finance (DeFi) sector, ultimately leading to the compromise of an employee’s system. The attack chain commenced with the threat actor impersonating an existing employee of a trading company on Telegram, utilising fake websites that masqueraded as Calendly and Picktime to schedule a meeting with the victim. Although the exact initial access vector remains unknown, the […] - [Remote hiring fraud increasing quickly](https://infosectoday.com/hiring-fraud/remote-hiring-fraud-increasing-quickly/): What if the star engineer that an organisation just hired is actually an attacker in disguise? This scenario is not about phishing; it involves infiltration through the onboarding process. Meet “Jordan from Colorado,” who possesses a strong resume, convincing references, a clean background check, and a digital footprint that checks out. On their first day, Jordan logs into email and attends the weekly standup, receiving a warm welcome from the team. Within hours, they gain access to repositories, project folders, and even some copy/pasted development keys for their pipeline. A week later, tickets close faster, and everyone is impressed. Jordan […] - [MystRodX backdoor uses DNS and ICMP triggers for covert manipulation](https://infosectoday.com/malware/mystrodx-backdoor-uses-dns-and-icmp-triggers-for-covert-manipulation/): Cybersecurity researchers have recently unveiled a sophisticated backdoor known as MystRodX, which is designed to capture sensitive data from compromised systems. Implemented in C++, MystRodX boasts features such as file management, port forwarding, reverse shell, and socket management. According to QiAnXin XLab, this backdoor distinguishes itself from typical variants through its exceptional stealth and flexibility. Also referred to as ChronosRAT, MystRodX was first identified by Palo Alto Networks Unit 42 in connection with a threat activity cluster named CL-STA-0969, which is believed to have links to a China-nexus cyber espionage group known as Liminal Panda. The stealth capabilities of MystRodX […] - [Can AI agents identify threats that your Security Operations Center overlooks?](https://infosectoday.com/ai-driven-network-monitoring/can-ai-agents-identify-threats-that-your-security-operations-center-overlooks/): A new research project called NetMoniAI demonstrates how AI agents could transform network monitoring and security. Developed by a team at Texas Tech University, the framework integrates distributed monitoring at the edge with AI-driven analysis at the centre. Although still in the research stage, it provides Chief Information Security Officers (CISOs) with insights into the potential of agentic AI systems in enterprise environments. The project is open source, allowing the community to test and build upon its findings. The system features a central controller architecture with a layered design for detection and correlation. Lightweight agents operate on individual machines, monitoring […] - [Iranian cybercriminals compromise over 100 diplomatic email accounts](https://infosectoday.com/cyber-espionage/iranian-cybercriminals-compromise-over-100-diplomatic-email-accounts/): An Iran-nexus group has been linked to a “coordinated” and “multi-wave” spear-phishing campaign targeting embassies and consulates across Europe and other regions globally. This activity has been attributed to Iranian-aligned operators associated with a group known as Homeland Justice, as reported by Israeli cybersecurity company Dream. The campaign involved sending emails that disguised legitimate diplomatic communications, indicating a broader regional espionage effort aimed at governmental entities during heightened geopolitical tensions. The spear-phishing emails, themed around the geopolitical strife between Iran and Israel, contained malicious Microsoft Word documents that prompted recipients to “Enable Content” to execute an embedded Visual Basic for […] - [BruteForceAI: New AI-powered Github tool](https://infosectoday.com/penetration-testing/bruteforceai-new-ai-powered-github-tool/): BruteForceAI is an innovative penetration testing tool that leverages Large Language Models (LLMs) to enhance the execution of brute-force attacks. Unlike traditional methods that require extensive manual setup, BruteForceAI automatically analyses HTML content to detect login form selectors, streamlining the attack preparation process. This tool is designed to simulate realistic human behaviour while conducting multi-threaded attacks, significantly improving the effectiveness and accuracy of security testing. The AI begins by identifying login fields on the target page, and once the selectors are mapped, it initiates a targeted attack. It supports both brute-force and password spray modes, incorporating small delays, random timing, […] - [Connected vehicles are intelligent, user-friendly, and vulnerable to cyberattack](https://infosectoday.com/cybersecurity-concerns/connected-vehicles-are-intelligent-user-friendly-and-vulnerable-to-cyber-threats/): Consumers are increasingly concerned about vulnerabilities in their vehicles, which significantly impacts their purchasing behaviour and brand loyalty, according to RunSafe Security. Modern vehicles operate on over 100 million lines of code, surpassing that of most fighter jets, yet they often lack adequate cybersecurity measures. While innovations such as over-the-air (OTA) updates and smartphone integration offer convenience, they also present new opportunities for cybercriminals. A notable 65% of drivers believe that remote hacking of their vehicle is possible. Despite this awareness, only 19% feel very confident that their car is protected from hackers. When comparing their vehicles to other connected […] - [Fake npm packages stealing Ethereum wallet keys](https://infosectoday.com/cryptocurrency-theft/fake-npm-packages-stealing-ethereum-wallet-keys/): A new set of four malicious packages has been discovered in the NPM package registry, designed to steal cryptocurrency wallet credentials from Ethereum developers. These packages masquerade as legitimate cryptographic utilities and Flashbots MEV infrastructure while secretly exfiltrating private keys and mnemonic seeds to a Telegram bot controlled by the threat actor. Socket researcher Kush Pandya highlighted that the packages were uploaded by a user named “Flashbotts,” with the earliest library appearing in September 2023 and the most recent upload on August 19, 2025. The identified packages include @Flashbotts/Ethers-Provider-Bundle, Flashbot-SDK-Eth, SDK-Ethers, and Gram-Utilz, all of which remain available for download. […] - [North Korean fake job interview schemes](https://infosectoday.com/infrastructure-vulnerability/north-korean-fake-job-interview-schemes/): North Korean hackers have been observed actively monitoring cyber threat intelligence to identify and reconstruct exposed infrastructure. This strategic approach enables them to exploit vulnerabilities and target unsuspecting individuals. Recently, these hackers launched a series of fake job interview attacks, successfully reaching hundreds of potential victims. By masquerading as legitimate employers, they aimed to extract sensitive information and gain unauthorised access to personal and corporate data. The implications of these attacks are significant, highlighting the need for heightened awareness and robust cybersecurity measures. As cyber threats continue to evolve, organisations must remain vigilant and proactive in safeguarding their digital assets. […] - [TAG-150 creates CastleRAT using Python and C, broadening the capabilities of CastleLoader malware.](https://infosectoday.com/phishing-attacks/tag-150-creates-castlerat-using-python-and-c-broadening-the-capabilities-of-castleloader-malware/): The threat actor known as TAG-150 is behind the malware-as-a-service (MaaS) framework and loader called CastleLoader, as well as a remote access trojan (RAT) named CastleRAT. CastleRAT is available in both Python and C variants, with its core functionalities including the collection of system information, downloading and executing additional payloads, and executing commands via CMD and PowerShell. TAG-150 has been active since at least March 2025, and CastleLoader is viewed as an initial access vector for various secondary payloads, such as remote access trojans and information stealers. CastleLoader was first documented by Swiss cybersecurity company PRODAFT in July 2025, and […] - [Parallel-Poisoned Web Attack presents poisoned web pages to AI web bots](https://infosectoday.com/ai-security-threats/parallel-poisoned-web-attack-presents-poisoned-web-pages-to-ai-web-bots/): AI agents can be manipulated into executing malicious actions by websites that remain concealed from regular users, as discovered by JFrog AI architect Shaked Zychlinski. This innovative method enables attackers to inject prompts or instructions into these autonomous AI-powered assistants, effectively hijacking their behaviour for nefarious purposes. Indirect prompt-injection poisoning attacks, where harmful instructions are embedded within the same page visible to human visitors, are often undetectable by users but can still be identified by security systems. The newly identified “parallel-poisoned web” attack takes this a step further by serving a distinct version of the page solely to AI agents. […] - [SAP S/4HANA vulnerability CVE-2025-42957 actively exploited](https://infosectoday.com/vulnerability-management/sap-s-4hana-vulnerability-cve-2025-42957-actively-exploited/): A critical security vulnerability affecting SAP S/4HANA, an Enterprise Resource Planning (ERP) software, has been actively exploited in the wild. The command injection vulnerability, identified as CVE-2025-42957 with a CVSS score of 9.9, was addressed by SAP in its recent monthly updates. According to the NIST National Vulnerability Database (NVD), this flaw allows an attacker with user privileges to exploit a vulnerability in the function module exposed via Remote Function Call (RFC). This vulnerability enables the injection of arbitrary ABAP code into the system, bypassing essential authorisation checks. Successful exploitation could lead to a complete system compromise, undermining the confidentiality, […] - [AI-driven supply chain attack using model namespace reuse](https://infosectoday.com/ai-supply-chain-vulnerabilities/ai-driven-supply-chain-attack-using-model-namespace-reuse/): A critical AI supply chain vulnerability known as Model Namespace Reuse has emerged, posing significant risks to major tech companies like Google and Microsoft. This issue enables attackers to deploy malicious AI models, which can lead to unauthorised code execution within affected systems. By exploiting this vulnerability, cybercriminals can manipulate the AI supply chain, potentially compromising sensitive data and undermining the integrity of AI applications. The implications of such attacks are profound, as they can disrupt operations and erode trust in AI technologies. The recent demonstration of this AI supply chain attack method highlights the urgent need for enhanced security […] - [Importance of the CVE matrix for cybersecurity](https://infosectoday.com/vulnerability-management/__trashed-261/): The industry operates under the influence of Common Vulnerabilities and Exposures (CVE). Each security update released by various vendors addresses specific software flaws that could be exploited. These publicly acknowledged flaws are assigned a CVE designator along with associated parameters such as type, severity, and CVSS score. These parameters are crucial for assessing the risk to network and computing assets, ultimately guiding the prioritisation of security updates or patches. The CVE has become a central organising principle, with its resolution serving as a benchmark for measuring effectiveness. Vulnerability scanners have long been employed to identify potential software vulnerabilities in operational […] - [Hidden SVG files launch base64-encoded phishing sites](https://infosectoday.com/phishing-attacks/virustotal-discovers-44-undetected-svg-files-employed-for-launching-base64-encoded-phishing-websites/): Cybersecurity researchers have identified a new malware campaign that utilises Scalable Vector Graphics (SVG) files in phishing attacks, impersonating the Colombian judicial system. According to VirusTotal, these SVG files are distributed via email and are designed to execute an embedded JavaScript payload. This payload decodes and injects a Base64-encoded HTML phishing page that masquerades as a portal for Fiscalía General de la Nación, the Office of the Attorney General of Colombia. The phishing page simulates an official government document download process with a fake progress bar while stealthily triggering the download of a ZIP archive in the background. The specific […] - [File security risks increasing due to insider threats, malware, and AI](https://infosectoday.com/file-security-risks/file-security-risks-increasing-due-to-insider-threats-malware-and-ai/): Breaches related to file access are increasingly common, leading to significant financial repercussions for many organisations. Over the past two years, numerous companies have experienced multiple file-related incidents, resulting in losses that can reach millions. The consequences of these breaches often include the theft of customer data, diminished productivity, and the exposure of intellectual property. A recent study by Ponemon Institute highlights that data leakage from insiders poses a substantial threat, driven by both negligence and malicious intent. This risk is exacerbated when access controls are inadequate or when file activity remains obscured. Additional concerns include the presence of malicious […] - [GhostRedirector compromises Windows servers utilizing Rungan backdoor and Gamshen IIS module](https://infosectoday.com/malware/ghostredirector-compromises-windows-servers-utilizing-rungan-backdoor-and-gamshen-iis-module/): Cybersecurity researchers have uncovered a previously undocumented threat cluster known as GhostRedirector, which has compromised at least 65 Windows servers, primarily located in Brazil, Thailand, and Vietnam. According to Slovak cybersecurity company ESET, the attacks have resulted in the deployment of a passive C++ backdoor named Rungan and a native Internet Information Services (IIS) module referred to as Gamshen. The threat actor is believed to have been active since at least August 2024. Rungan possesses the capability to execute commands on a compromised server, while Gamshen is designed to provide SEO fraud as-a-service, manipulating search engine results to enhance the […] - [Russian cyberespionage group APT28 targets NATO member firms with Outlook "NotDoor" backdoor](https://infosectoday.com/cybersecurity-threats/russian-cyberespionage-group-apt28-target-nato-member-firms-with-outlook-notdoor-backdoor/): The Russian state-sponsored hacking group known as APT28 has been linked to a new Microsoft Outlook backdoor called NotDoor, which has been used in attacks against various companies across NATO member countries. NotDoor functions as a Visual Basic for Applications (VBA) macro designed to monitor incoming emails for specific trigger words. When such an email is detected, it allows attackers to exfiltrate data, upload files, and execute commands on the victim’s computer. The malware derives its name from the inclusion of the word “Nothing” in its source code, highlighting the exploitation of Outlook as a covert channel for communication, data […] - [Cybercriminals distributing malware via 'Grokking'](https://infosectoday.com/cybersecurity-threats/cybercriminals-are-taking-advantage-of-xs-grok-ai-to-circumvent-advertisement-safeguards-and-distribute-malware-to-millions/): Cybersecurity researchers have identified a new technique, codenamed Grokking, that cybercriminals are using to circumvent malvertising protections on social media platform X. Nati Tal, head of Guardio Labs, highlighted this method in a series of posts on X. The technique exploits the platform’s restrictions on Promoted Ads, which only permit text, images, or videos. Malvertisers are running video card-promoted posts featuring adult content as bait, concealing malicious links in the “From:” metadata field beneath the video player, which appears to evade the platform’s scanning processes. Subsequently, fraudsters tag Grok in replies, prompting the AI assistant to display the hidden link, […] - [USA and allies advocating Software Bill of Materials (SBOMs)](https://infosectoday.com/risk-management/the-united-states-and-its-allies-are-advocating-for-software-bill-of-materials-sboms-to-enhance-cybersecurity-measures/): The adoption of Software Bill of Materials (SBOM) is set to significantly enhance software supply chain security, thereby reducing risks and costs associated with vulnerabilities. As the United States and its allies advocate for the implementation of SBOMs, the initiative aims to provide a clearer view of the components within software products. This transparency is crucial for identifying potential security threats and ensuring that organisations can respond effectively to vulnerabilities. By fostering a more secure software environment, SBOMs are expected to streamline compliance processes and reduce the financial burden of security breaches. Furthermore, the push for SBOMs reflects a growing […] - [DDoS attacks act as tools for political leverage and chaos](https://infosectoday.com/ddos-attack-trends/ddos-attacks-act-as-tools-for-political-leverage-and-chaos/): In the first half of 2025, there were 8,062,971 DDoS attacks globally, with the EMEA region experiencing the highest volume at 3.2 million attacks, according to Netscout. Peak attack speeds reached an alarming 3.12 Tbps and 1.5 Gpps. These attacks have evolved from mere disruption tools into precise instruments of geopolitical influence, capable of targeting critical infrastructure during sensitive moments. Major political events have been significant catalysts for these spikes in attacks. For instance, during the World Economic Forum, Switzerland recorded over 1,400 attacks, which is double the normal rate for similar periods in December. Italy also faced sustained targeting […] - [The US Cybersecurity Agency has highlighted a vulnerability in Wi-Fi range extenders that is currently being exploited.](https://infosectoday.com/cybersecurity-vulnerabilities/the-us-cybersecurity-agency-has-highlighted-a-vulnerability-in-wi-fi-range-extenders-that-is-currently-being-exploited/): The Cybersecurity and Infrastructure Security Agency (CISA) has identified a significant vulnerability in the TP-Link TL-WA855RE Wi-Fi range extender, which allows attackers to reset and hijack the devices. This flaw poses a serious risk to users, as it can lead to unauthorised access to their networks. CISA has urged individuals still using these discontinued extenders to retire them immediately to mitigate potential security threats. The agency’s warning highlights the importance of maintaining updated and secure networking equipment to protect against active attacks targeting these vulnerable devices. As cyber threats continue to evolve, the CISA’s alert serves as a crucial reminder […] - [Malicious actors using HexStrike AI to create Citrix exploits](https://infosectoday.com/cybersecurity-threats/malicious-actors-using-hexstrike-ai-to-create-citrix-exploits/): Threat actors are attempting to exploit a newly released artificial intelligence (AI) offensive security tool called HexStrike AI, which is designed to automate reconnaissance and vulnerability discovery. HexStrike AI is marketed as an AI-driven security platform aimed at enhancing authorised red teaming operations, bug bounty hunting, and capture the flag (CTF) challenges. The open-source platform integrates with over 150 security tools, facilitating network reconnaissance, web application security testing, reverse engineering, and cloud security. It also features numerous specialised AI agents tailored for vulnerability intelligence, exploit development, attack chain discovery, and error handling. However, a report from Check Point indicates that […] - [Cloudflare successfully thwarts unprecedented DDoS attack](https://infosectoday.com/ddos-attacks/cloudflare-successfully-thwarts-unprecedented-ddos-attack/): A recent wave of Distributed Denial of Service (DDoS) attacks persisted for several weeks, characterised by a massive User Datagram Protocol (UDP) flood. This unprecedented assault originated from multiple Internet of Things (IoT) devices and cloud service providers, showcasing the vulnerabilities inherent in these technologies. The scale of the attack was staggering, reaching a record-breaking 11.5 terabits per second (Tbps), which posed significant challenges for cybersecurity measures. Cloudflare, a leading web infrastructure and security company, successfully mitigated this overwhelming threat, demonstrating its robust capabilities in defending against such large-scale attacks. The sustained nature of this DDoS attack highlights the increasing […] - [How a background in gaming can benefit a career in cybersecurity](https://infosectoday.com/gaming-skills/how-a-background-in-gaming-can-benefit-a-career-in-cybersecurity/): Many people may not realise that playing video games can contribute to a career in cybersecurity. The skills acquired through gaming, although seemingly unrelated at first, can be highly beneficial in this field. With over 3 billion gamers globally, there exists a significant talent pool that companies could tap into for cybersecurity roles. Organisations struggling to fill critical positions might find value in exploring this demographic. The military sector was among the first to acknowledge the relevance of gamers’ skills in modern warfare. Matthew Radolec, Vice President of Incident Response at Varonis, describes gamers as “the most untapped talent pool […] - [WhatsApp Zero-day vulnerabilities utilised for iOS attacks](https://infosectoday.com/vulnerabilities/zero-day-vulnerabilities-in-whatsapp-have-been-used-to-launch-attacks-aimed-at-apple-users/): A critical vulnerability identified as CVE-2025-55177 has been exploited in conjunction with a zero-day flaw affecting iOS and macOS systems. This exploitation is believed to be part of a series of suspected spyware attacks targeting Apple users. The security breach highlights the increasing sophistication of cyber threats, particularly those aimed at popular platforms like WhatsApp. Users of these devices are urged to remain vigilant and ensure their software is up to date to mitigate potential risks associated with this vulnerability. The recent discovery of the WhatsApp zero-day exploit underscores the urgent need for enhanced security measures among Apple users. As […] - [Silver Fox using WatchDog driver to distribute ValleyRAT malware](https://infosectoday.com/cybersecurity-threats/silver-fox-using-watchdog-driver-to-distribute-valleyrat-malware/): The threat actor known as Silver Fox has exploited a previously unknown vulnerable driver associated with WatchDog Anti-Malware in a Bring Your Own Vulnerable Driver (BYOVD) attack. This attack aims to disable security solutions on compromised hosts. The vulnerable driver, “amsdk.sys” (version 1.0.600), is a 64-bit, validly signed Windows kernel device driver built on the Zemana Anti-Malware SDK. According to Check Point’s analysis, this driver was Microsoft-signed, not listed in the Microsoft Vulnerable Driver Blocklist, and went undetected by community projects like LOLDrivers. The attack employs a dual-driver strategy, using a known vulnerable Zemana driver (“zam.exe”) for Windows 7 machines […] - [Nodemailer imitator nodejs-smtp clips Atomic and Exodus wallets](https://infosectoday.com/malicious-software/nodemailer-imitator-nodejs-smtp-clips-atomic-and-exodus-wallets/): Cybersecurity researchers have uncovered a malicious npm package named Nodejs-Smtp, which stealthily injects harmful code into desktop applications for cryptocurrency wallets such as Atomic and Exodus on Windows systems. This package, uploaded in April 2025 by a user named “nikotimon,” impersonates the legitimate email library Nodemailer, featuring identical taglines, page styling, and README descriptions. Despite attracting 347 downloads, it is no longer available. Upon import, the package utilises Electron tooling to unpack Atomic Wallet’s app.asar, replace a vendor bundle with a malicious payload, and repackage the application while erasing traces by deleting its working directory. The primary aim is to […] - [Ukrainian group FDN3 initiates large-scale brute-force attacks against SSL VPN and RDP systems.](https://infosectoday.com/cybersecurity-threats/ukrainian-group-fdn3-initiates-large-scale-brute-force-attacks-against-ssl-vpn-and-rdp-systems/): Cybersecurity researchers have identified a Ukrainian IP network, FDN3 (AS211736), as being involved in extensive brute-force and password spraying campaigns targeting SSL VPN and RDP devices during June and July 2025. According to a report from French cybersecurity firm Intrinsec, FDN3 is believed to be part of a larger abusive infrastructure that includes two other Ukrainian networks, VAIZ-AS (AS61432) and ERISHENNYA-ASN (AS210950), along with a Seychelles-based network named TK-NET (AS210848). All these networks were allocated in August 2021 and frequently exchange IPv4 prefixes to evade blocklisting, thereby continuing their malicious activities. AS61432 currently announces a single prefix, 185.156.72[.]0/24, while AS210950 […] - [Android Droppers distributing banking trojans, SMS stealers and spyware](https://infosectoday.com/android-malware/android-droppers-are-now-used-to-distribute-not-only-banking-trojans-but-also-sms-stealers-and-spyware/): Cybersecurity researchers are highlighting a significant shift in the Android malware landscape, where dropper apps, traditionally used to deliver banking trojans, are now also distributing simpler forms of malware such as SMS stealers and basic spyware. These campaigns are being propagated through dropper apps that masquerade as government or banking applications in India and other regions of Asia, according to a recent report by ThreatFabric. The Dutch mobile security firm attributes this change to new security measures that Google has implemented in select markets, including Singapore, Thailand, Brazil, and India, aimed at blocking the sideloading of potentially harmful apps that […] - [Considering Browsers as a Vulnerability Target: Reevaluating Security for Scattered Spider](https://infosectoday.com/cybersecurity-threats/considering-browsers-as-a-vulnerability-target-reevaluating-security-for-scattered-spider/): As enterprises increasingly transition their operations to web-based platforms, security teams encounter a rising array of cyber challenges. Over 80% of security incidents now stem from web applications accessed through browsers like Chrome, Edge, and Firefox. One particularly agile adversary, Scattered Spider, has focused its efforts on compromising sensitive data within these browsers. Known also as UNC3944, Octo Tempest, or Muddled Libra, Scattered Spider has evolved over the past two years by precisely targeting human identity and browser environments. This strategic shift sets them apart from other infamous cybercriminal groups such as Lazarus Group, Fancy Bear, and REvil. If sensitive […] - [ScarCruft's "Operation HanKook Phantom" targeting South Korean academics with RokRAT malware](https://infosectoday.com/phishing-campaigns/scarcrufts-operation-hankook-phantom-targeting-south-korean-academics-with-rokrat-malware/): Cybersecurity researchers have identified a new phishing campaign orchestrated by the North Korea-linked hacking group known as ScarCruft (also referred to as APT37), aimed at delivering a malware called RokRAT. This operation, dubbed Operation HanKook Phantom by Seqrite Labs, appears to target individuals affiliated with the National Intelligence Research Association, including academics, former government officials, and researchers. Security researcher Dixit Panchal noted that the attackers likely seek to steal sensitive information, establish persistence, or conduct espionage. The attack begins with a spear-phishing email that lures recipients with a fake “National Intelligence Research Society Newsletter—Issue 52,” which is a publication from […] - [Velociraptor forensic tool used for command and control tunneling](https://infosectoday.com/remote-access-tools/velociraptor-forensic-tool-used-for-command-and-control-tunneling/): Cybersecurity researchers have highlighted a recent cyber attack involving the deployment of Velociraptor, an open-source endpoint monitoring and digital forensic tool, by unknown threat actors. This incident exemplifies the ongoing misuse of legitimate software for malicious purposes. According to the Sophos Counter Threat Unit Research Team, the attackers utilised Velociraptor to download and execute Visual Studio Code, likely intending to create a tunnel to an attacker-controlled Command-and-Control (C2) server. The use of Velociraptor indicates a tactical evolution in cyber attacks, where incident response tools are leveraged to gain a foothold, reducing the necessity for deploying custom malware. Further investigation revealed […] - [Abandoned Sogou Zhuyin update server compromised and repurposed for Taiwan espionage operation](https://infosectoday.com/cyber-espionage/abandoned-sogou-zhuyin-update-server-compromised-and-repurposed-for-taiwan-espionage-operation/): An abandoned update server linked to the Input Method Editor (IME) software Sogou Zhuyin was exploited by threat actors in an espionage campaign that delivered various malware families, including C6DOOR and GTELAM. This campaign, identified in June 2025 and codenamed TAOTH by Trend Micro researchers Nick Dai and Pierre Lee, primarily targeted users in Eastern Asia. The victims included dissidents, journalists, researchers, and technology and business leaders from China, Taiwan, Hong Kong, Japan, South Korea, and overseas Taiwanese communities. Taiwan represented 49% of the targets, followed by Cambodia at 11% and the United States at 7%. In October 2024, attackers […] - [Amazon disrupts APT29 watering hole attack using Microsoft Device Code Authentication](https://infosectoday.com/cybersecurity-threats/amazon-disrupts-apt29-watering-hole-attack-using-microsoft-device-code-authentication/): On Friday, Amazon reported that it had identified and disrupted an opportunistic watering hole campaign orchestrated by the Russia-linked APT29 actors, aimed at intelligence gathering. The campaign involved compromised websites that redirected visitors to malicious infrastructure, designed to deceive users into authorising attacker-controlled devices through Microsoft’s device code authentication flow, as stated by Amazon’s Chief Information Security Officer, C.J. Moses. APT29, also known as BlueBravo, Cloaked Ursa, CozyLarch, Cozy Bear, Earth Koshchei, ICECAP, Midnight Blizzard, and The Dukes, is a state-sponsored hacking group associated with Russia’s Foreign Intelligence Service (SVR). Recently, this prolific threat actor has been linked to attacks […] - [FreePBX servers exploited by zero-day vulnerability](https://infosectoday.com/vulnerability-management/freepbx-servers-exploited-by-zero-day-vulnerability/): The Sangoma FreePBX Security Team has issued a critical advisory regarding an actively exploited zero-day vulnerability affecting FreePBX systems with an exposed Administrator Control Panel (ACP) on the public internet. FreePBX, an open-source private branch exchange (PBX) platform built on Asterisk, is widely utilised by businesses, call centres, and service providers for managing voice communications. The vulnerability, identified as CVE-2025-57819, has a CVSS score of 10.0, indicating its maximum severity. It allows unauthenticated access to the FreePBX Administrator due to insufficiently sanitised user-supplied data, leading to arbitrary database manipulation and potential remote code execution. The affected versions include FreePBX 15 […] - [Can your security system monitor your employee's generative AI prompts?](https://infosectoday.com/data-loss-prevention/can-your-security-system-monitor-your-employees-generative-ai-prompts/): Generative AI platforms such as ChatGPT, Gemini, Copilot, and Claude are becoming increasingly prevalent in organisations. While these solutions enhance efficiency across various tasks, they also introduce new challenges for data leak prevention in the context of generative AI. Sensitive information can be inadvertently shared through chat prompts, files uploaded for AI-driven summarisation, or browser plugins that circumvent established security controls. Traditional Data Loss Prevention (DLP) products often struggle to detect these events. Solutions like Fidelis Network® Detection and Response (NDR) offer a network-based approach to data loss prevention, enabling organisations to monitor, enforce policies, and audit the use of […] - [Storm-0501 utilizes Entra ID to extract and erase Azure data during hybrid cloud attacks](https://infosectoday.com/cybersecurity-threats/storm-0501-utilizes-entra-id-to-extract-and-erase-azure-data-during-hybrid-cloud-attacks/): The financially motivated threat actor known as Storm-0501 has been observed refining its tactics to conduct data exfiltration and extortion attacks targeting cloud environments. Unlike traditional on-premises ransomware, where the threat actor typically deploys malware to encrypt critical files across endpoints within the compromised network and then negotiates for a decryption key, cloud-based ransomware introduces a fundamental shift. The Microsoft Threat Intelligence team reported that Storm-0501 leverages cloud-native capabilities to rapidly exfiltrate large volumes of data, destroy data and backups within the victim environment, and demand ransom—all without relying on traditional malware deployment. First documented by Microsoft almost a year […] - [First AI-driven ransomware leveraging OpenAI model](https://infosectoday.com/cybersecurity-threats/first-ai-driven-ransomware-leveraging-openai-model/): ESET, a cybersecurity company, has disclosed the discovery of an artificial intelligence (AI)-powered ransomware variant codenamed PromptLock. Written in Golang, this newly identified strain utilises the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts in real-time. The open-weight language model was released by OpenAI earlier this month. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. ESET noted that these Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. The ransomware code also embeds instructions to craft a custom […] - [Anthropic AI used for cybercrime](https://infosectoday.com/ai-as-an-operational-tool/anthropic-ai-used-for-cybercrime/): A new report from Anthropic reveals that criminals are increasingly using AI to manage various aspects of their operations. The findings indicate that AI is now integrated throughout the entire attack cycle, encompassing reconnaissance, malware development, fraud, and extortion. This report is based on actual cases where Anthropic’s models were misused, providing a unique perspective on how attackers are evolving and incorporating AI into every phase of their activities. While the focus is primarily on Anthropic’s own model, the cases illustrate a wider trend applicable to advanced AI systems in general. One of the most notable insights is how criminals […] - [Counterfeit PDF editing software downloads TamperedChef malware](https://infosectoday.com/malware-distribution/counterfeit-pdf-editing-software-downloadstamperedchef-malware/): Cybersecurity researchers have uncovered a sophisticated cybercrime campaign that employs malvertising techniques to redirect victims to fraudulent websites, ultimately delivering a new information stealer known as TamperedChef. The primary aim of this campaign is to entice users into downloading and installing a trojanised PDF editor, specifically the AppSuite PDF Editor, which is embedded with the TamperedChef malware. According to Truesec researchers Mattias Wåhlén, Nicklas Keijser, and Oscar Lejerbäck Wolf, the malware is engineered to extract sensitive information, including user credentials and web cookies. The campaign utilises multiple counterfeit sites to promote the PDF editor installer, which, upon installation, prompts users […] - [Visual Studio Code vulnerability allows deleted extension takeover](https://infosectoday.com/cybersecurity-vulnerabilities/visual-studio-code-vulnerability-allows-deleted-extension-takeover/): Cybersecurity researchers have uncovered a significant loophole in the Visual Studio Code Marketplace that enables threat actors to reuse names of previously removed extensions. Software supply chain security firm ReversingLabs made this discovery after identifying a malicious extension named “ahbanC.shiba,” which operates similarly to two other flagged extensions, “ahban.shiba” and “ahban.cychelloworld.” All three extensions function as downloaders, retrieving a PowerShell payload that encrypts files in a folder called “testShiba” on the victim’s Windows desktop, demanding a Shiba Inu token as ransom. The researchers noted that the new extension’s name was nearly identical to one of the previously identified extensions, prompting […] - [s1ngularity Nx attack exposes GitHub credentials](https://infosectoday.com/vulnerability-exploitation/s1ngularity-nx-attack-exposes-github-credentials/): The maintainers of the Nx build system have issued a warning regarding a supply chain attack that enabled attackers to publish malicious versions of the widely used npm package and its auxiliary plugins. These compromised versions contained code designed to scan users’ file systems, collect sensitive credentials, and post this information to GitHub as repositories under the users’ accounts. Nx, an open-source and technology-agnostic build platform, is marketed as an “AI-first build platform” that integrates various tools from code editors to Continuous Integration (CI) systems. The npm package boasts over 3.5 million weekly downloads. The affected versions, which have since […] - [Git vulnerability CVE-2025-48384 allows remote code execution](https://infosectoday.com/vulnerability-exploitation/attackers-are-exploiting-a-git-vulnerability-that-can-lead-to-remote-code-execution-rce-identified-as-cve-2025-48384/): CVE-2025-48384 is a recently patched vulnerability in the widely used distributed revision control system Git, which is currently being exploited by attackers. The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed the exploitation of this flaw and added it to its Known Exploited Vulnerabilities catalog. This vulnerability arises from a mismatch in how Git reads and writes configuration values containing control characters. According to DataDog researchers, it can be exploited to create a malicious Git Hook script, leading to remote code execution (RCE) when executing commands like git commit and git merge. Attackers can craft a malicious .gitmodules file with […] - [Over 300,000 Plex Media Server installations remain susceptible to exploitation due to CVE-2025-34158](https://infosectoday.com/cybersecurity-vulnerabilities/over-300000-plex-media-server-installations-remain-susceptible-to-exploitation-due-to-cve-2025-34158/): Over 300,000 internet-facing Plex Media Server instances remain vulnerable to the critical CVE-2025-34158, despite a fix being issued earlier this month. Plex Media Server (PMS) allows users to transform their Windows, Linux, or macOS computers, as well as network-attached storage devices, into personal media servers. This software organises movies, music, photos, and other media, enabling streaming on various devices. CVE-2025-34158 is an improper input validation vulnerability affecting PMS versions 1.41.7.x to 1.42.0.x, with a CVSS score indicating it can be exploited remotely without user interaction or authentication. The flaw poses significant risks, including potential loss of confidentiality, integrity, and availability, […] - [ShadowSilk attacks Asia-Pacific government targets via Telegram bots](https://infosectoday.com/data-exfiltration/shadowsilk-attacks-asia-pacific-government-targets-via-telegram-bots/): A threat activity cluster known as ShadowSilk has been linked to a new wave of attacks targeting government entities in Central Asia and the Asia-Pacific (APAC) region. According to Group-IB, nearly three dozen victims have been identified, primarily focusing on data exfiltration. The hacking group exhibits toolset and infrastructural overlaps with other threat actors, including YoroTrooper, SturgeonPhisher, and Silent Lynx. Victims of ShadowSilk’s campaigns include government organisations in Uzbekistan, Kyrgyzstan, Myanmar, Tajikistan, Pakistan, and Turkmenistan, as well as entities in the energy, manufacturing, retail, and transportation sectors. Researchers Nikita Rostovcev and Sergei Turner noted that the operation is conducted by […] - [Energy industry needs to be vigilant about cyberattacks](https://infosectoday.com/cybersecurity-threats/energy-industry-needs-to-be-vigilant-about-cyberattacks/): The energy sector remains a significant target for cybercriminals, with power outages posing threats to economic stability and public safety. The rising demand for electricity, driven by technological advancements and digital growth, exacerbates the sector’s vulnerabilities. Artificial Intelligence is a major contributor to this demand, with Goldman Sachs predicting a 160% increase in data centre power consumption by 2030, which could strain already fragile grids. The recent blackout on the Iberian Peninsula highlighted the disruptive potential of power outages, affecting millions in Spain and Portugal, as well as transport, banking, and communication systems. Although this blackout was not caused by […] - [AI agents vulnerable to prompt injection via image scaling attacks](https://infosectoday.com/ai-vulnerabilities/ai-agents-vulnerableto-prompt-injection-via-image-scaling-attacks/): Researchers have uncovered a significant vulnerability in popular AI systems, demonstrating that these technologies can be manipulated into executing malicious instructions concealed within images. This technique, known as a prompt injection via image scaling attack, allows attackers to embed harmful commands in seemingly innocuous visuals. By exploiting the way AI interprets and processes images, malicious actors can bypass security measures and influence the behaviour of AI models. This discovery raises critical concerns about the security of AI applications, highlighting the need for enhanced protective measures against such sophisticated attacks. The implications of this research are profound, as it reveals the […] - [ShadowCaptcha distributing ransomware & cryptominers via compromised WordPress sites](https://infosectoday.com/cybercrime/shadowcaptcha-distributing-ransomware-cryptominers-via-compromised-wordpress-sites/): A new large-scale cybercrime campaign, codenamed ShadowCaptcha, has been identified, exploiting over 100 compromised WordPress sites. This campaign, first detected in August 2025 by the Israel National Digital Agency, directs unsuspecting visitors to fake CAPTCHA verification pages using the ClickFix social engineering tactic. Researchers Shimi Cohen, Adi Pick, Idan Beit Yosef, Hila David, and Yaniv Goldman noted that the campaign combines social engineering, living-off-the-land binaries (LOLBins), and multi-stage payload delivery to establish and maintain a foothold in targeted systems. The primary objectives of ShadowCaptcha include collecting sensitive information through credential harvesting, exfiltrating browser data, deploying cryptocurrency miners for illicit profits, […] - [HOOK Android Trojan incorporates ransomware overlays & 107 remote commands](https://infosectoday.com/malware-evolution/hook-android-trojan-incorporates-ransomware-overlays-107-remote-commands/): Cybersecurity researchers have identified a new variant of an Android banking trojan named HOOK, which incorporates ransomware-style overlay screens to display extortion messages. A key feature of this variant is its ability to deploy a full-screen ransomware overlay designed to pressure victims into making ransom payments. Zimperium zLabs researcher Vishnu Pratapagiri noted that this overlay presents a distressing ‘*WARNING*’ message, along with a wallet address and amount that are dynamically retrieved from the command-and-control server. The overlay is remotely activated when the command “ransome” is issued by the C2 server, and it can be dismissed by the attacker using the […] - [Docker vulnerability (CVE-2025-9074) allows container escape, assigned CVSS of 9.3](https://infosectoday.com/security-vulnerability/docker-vulnerability-cve-2025-9074-allows-container-escape-assigned-cvss-of-9-3/): Docker has released critical fixes for a significant security vulnerability affecting the Docker Desktop application for Windows and macOS. This flaw, identified as CVE-2025-9074, has a CVSS score of 9.3 out of 10.0 and has been addressed in version 4.44.3. The vulnerability allows a malicious container to access the Docker Engine and launch additional containers without needing the Docker socket to be mounted. This could lead to unauthorised access to user files on the host system, and Enhanced Container Isolation (ECI) does not mitigate this risk. Security researcher Felix Boulet noted that the issue arises from a lack of authentication […] - [Diplomats targeted by UNC6384 through captive portal hijacking](https://infosectoday.com/cybersecurity-threats/diplomats-targeted-by-unc6384-through-captive-portal-hijacking/): A China-nexus threat actor known as UNC6384 has been linked to a series of attacks aimed at diplomats in Southeast Asia and various global entities to further Beijing’s strategic interests. This multi-stage attack chain employs sophisticated social engineering techniques, including valid code signing certificates, an Adversary-in-the-Middle (AitM) attack, and indirect execution methods to avoid detection. Google Threat Intelligence Group (GTIG) researcher Patrick Whitsell noted that UNC6384 shares tactical and tooling similarities with the Chinese hacking group Mustang Panda, which is also referred to by several other names, including BASIN, Bronze President, and RedDelta. The campaign, identified by GTIG in March […] - [Phishing Attack Employs UpCrypter in Fraudulent Voicemail Emails to Distribute RAT Payloads.](https://infosectoday.com/malware-distribution/phishing-attack-employs-upcrypter-in-fraudulent-voicemail-emails-to-distribute-rat-payloads/): Cybersecurity researchers have identified a new phishing campaign that employs fake voicemails and purchase orders to distribute a malware loader known as UpCrypter. The campaign utilises “carefully crafted emails to deliver malicious URLs linked to convincing phishing pages,” according to Fortinet FortiGuard Labs researcher Cara Lin. These phishing pages are designed to entice recipients into downloading JavaScript files that serve as droppers for UpCrypter. Since the beginning of August 2025, the attacks have primarily targeted sectors such as manufacturing, technology, healthcare, construction, and retail/hospitality worldwide. The majority of infections have been reported in countries including Austria, Belarus, Canada, Egypt, India, […] - [Transparent Tribe spear-phishing Indian government using weaponised desktop shortcuts](https://infosectoday.com/cybersecurity-threats/transparent-tribe-spear-phishing-indian-government-using-weaponised-desktop-shortcuts/): The advanced persistent threat (APT) actor known as Transparent Tribe has been observed targeting both Windows and BOSS (Bharat Operating System Solutions) Linux systems with malicious Desktop shortcut files in attacks aimed at Indian Government entities. Initial access is achieved through spear-phishing emails, as reported by CYFIRMA. Linux BOSS environments are specifically targeted via weaponised .desktop shortcut files that, once opened, download and execute malicious payloads. Transparent Tribe, also referred to as APT36, is assessed to be of Pakistani origin. The group, along with its sub-cluster SideCopy, has a storied history of infiltrating Indian government institutions using various remote access […] - [MixShell malware spreading through US supply chains via contact forms](https://infosectoday.com/cybersecurity-threats/mixshell-malware-spreading-through-us-supply-chains-via-contact-forms/): Cybersecurity researchers have raised alarms about a sophisticated social engineering campaign targeting supply chain-critical manufacturing companies with a stealthy in-memory malware known as MixShell. Codenamed ZipLine by Check Point Research, this campaign diverges from traditional phishing tactics by initiating contact through a company’s public ‘Contact Us’ form. Attackers manipulate employees into engaging in seemingly professional conversations that can last for weeks, often culminating in the signing of fake Non-Disclosure Agreements (NDAs) before delivering a weaponised ZIP file containing the MixShell malware. The campaign has primarily focused on U.S.-based entities but has also extended its reach to organisations in Singapore, Japan, […] - [Reasons Behind SIEM Rule Failures and Solutions: Lessons Learned from 160 Million Attack Simulations](https://infosectoday.com/log-collection-failures/reasons-behind-siem-rule-failures-and-solutions-lessons-learned-from-160-million-attack-simulations/): Security Information and Event Management (SIEM) systems serve as essential tools for detecting suspicious activities within enterprise networks, enabling organisations to identify and respond to potential attacks in real time. However, the recent Picus Blue Report 2025, which analysed over 160 million real-world attack simulations, revealed a concerning statistic: organisations are only detecting 1 out of 7 simulated attacks. This highlights a significant gap in threat detection and response capabilities. Despite many organisations believing they are adequately equipped to detect adversary actions, a substantial number of threats are evading their defences, leaving networks vulnerable to compromise. This detection gap fosters […] - [Is an SSH brute-force Go module stealing your credentials?](https://infosectoday.com/cybersecurity-threats/a-harmful-go-module-disguises-itself-as-a-tool-for-ssh-brute-force-attacks-while-actually-stealing-credentials-through-a-telegram-bot/): Cybersecurity researchers have identified a malicious Go module, dubbed “golang-random-ip-ssh-bruteforce,” which masquerades as a brute-force tool for SSH but is designed to covertly exfiltrate credentials to its creator. According to Socket researcher Kirill Boychenko, upon the first successful login, the module transmits the target IP address, username, and password to a hard-coded Telegram bot controlled by the threat actor. Although the associated GitHub account, IllDieAnyway (G3TT), is no longer accessible, the module remains available on pkg.go[.]dev, having been published on June 24, 2022. The Go module scans random IPv4 addresses for exposed SSH services on TCP port 22 and attempts […] - [Robust MLSecOps vital for managing vulnerabilities](https://infosectoday.com/agentic-ai/robust-mlsecops-vital-for-managing-vulnerabilities/): Organisations that fail to adapt their security programs while implementing Artificial Intelligence (AI) risk exposure to a range of both traditional and emerging threats. MLSecOps addresses this critical gap in security by integrating AI and Machine Learning (ML) development with stringent security protocols. Establishing a robust MLSecOps foundation is vital for proactively mitigating vulnerabilities and simplifying the remediation of previously undiscovered flaws. AI and ML systems must remain trustworthy, resilient, and secure. According to a white paper from the Open Software Security Foundation, MLSecOps can assist security teams in embedding protections as their operations scale. However, as organisations enhance their […] - [AI Agents have hidden security flaws](https://infosectoday.com/ai-security-risks/the-impending-ai-security-dilemma-that-is-being-overlooked-by-many/): In a recent interview with Help Net Security, Jacob Ideskog, the Chief Technology Officer of Curity, highlighted the significant risks that AI agents pose to organisations. He expressed concern that the industry is “sleepwalking” into a security crisis as these agents become increasingly integrated into enterprise systems. Ideskog noted that AI agents and other non-human identities are proliferating at an alarming rate, with some organisations reporting that they outnumber human users by more than 80 to 1. Many of these agents are granted broad, persistent access to critical systems and data without the same level of security controls, governance, or […] - [Lightweight LLMs decrease incident response time using decision theoretic planning](https://infosectoday.com/incident-response-planning/lightweight-llms-decrease-incident-response-time-using-decision-theoretic-planning/): Researchers from the University of Melbourne and Imperial College London have developed a novel method for enhancing incident response planning using Large Language Models (LLMs), with a particular emphasis on minimising the risk of hallucinations. Their approach utilises a smaller, fine-tuned LLM in conjunction with retrieval-augmented generation and decision-theoretic planning. The method addresses the prevalent issue of incident response being predominantly manual, slow, and reliant on expert-configured playbooks, which can lead to prolonged recovery times for organisations. Kim Hammar, one of the authors, highlighted that the system is designed to integrate seamlessly into existing workflows without necessitating additional software or […] - [Apple releases fix for CVE-2025-43300 zero-day vulnerability](https://infosectoday.com/security-vulnerabilities/apple-releases-fix-for-cve-2025-43300-zero-day-vulnerability/): Apple has released critical security updates to address a zero-day vulnerability impacting iOS, iPadOS, and macOS, which has reportedly been exploited in the wild. The flaw, tracked as CVE-2025-43300, is an out-of-bounds write vulnerability within the ImageIO framework that could lead to memory corruption when processing malicious images. In an advisory, Apple acknowledged that this issue may have been used in sophisticated attacks targeting specific individuals. The company discovered the bug internally and has implemented improved bounds checking to mitigate the risk. The updates are available in iOS 18.6.2 and iPadOS 18.6.2 for devices including iPhone XS and later, various […] - [AI boosts ransomware impacts](https://infosectoday.com/ransomware-threats/ai-boosts-ransomware-impacts/): Ransomware continues to pose a significant threat to large and medium-sized businesses, with numerous ransomware gangs leveraging artificial intelligence for automation, according to Acronis. From January to June 2025, the number of publicly reported ransomware victims surged by 70% compared to the same period in 2023 and 2024. February emerged as the most severe month, recording 955 reported cases. Cl0p was responsible for 335 of these incidents, marking a staggering 300% month-over-month increase, primarily due to the mass exploitation of high-severity vulnerabilities in CLEO MFT platforms, including Harmony, VLTrader, and Lexicom, as well as CVE-2024-50623 (remote code execution) and CVE-2024-55956 […] - [Chinese hacker groups Murky, Genesis, and Glacial Panda targeting cloud computing and telecommunications](https://infosectoday.com/cyber-espionage/chinese-hacker-groups-murky-genesis-and-glacial-panda-targeting-cloud-computing-and-telecommunications/): Cybersecurity researchers have raised alarms about the malicious activities of a China-nexus cyber espionage group known as Murky Panda, which exploits trusted relationships in the cloud to infiltrate enterprise networks. According to a report by CrowdStrike, this adversary has demonstrated a significant capability to rapidly weaponise N-day and zero-day vulnerabilities, often gaining initial access to targets by exploiting internet-facing appliances. Murky Panda, also referred to as Silk Typhoon (formerly Hafnium), gained notoriety for its zero-day exploitation of Microsoft Exchange Server vulnerabilities in 2021. The group has targeted a range of sectors, including government, technology, academia, legal, and professional services across […] - [Linux RAR malware bypasses antivirus software](https://infosectoday.com/malware-delivery-techniques/linux-malware-hidden-in-harmful-rar-file-names-successfully-bypasses-antivirus-software/): Cybersecurity researchers have uncovered a sophisticated attack chain that utilises phishing emails to deliver an open-source backdoor known as VShell. This Linux-specific malware infection begins with a spam email containing a malicious RAR archive file. Trellix researcher Sagar Bade noted that the payload is not concealed within the file content or a macro; instead, it is encoded directly in the filename. By employing shell command injection and Base64-encoded Bash payloads, the attacker transforms a simple file listing operation into an automatic malware execution trigger. This technique exploits a dangerous pattern often seen in shell scripts, where inadequate sanitisation of file […] - [Automation is transforming how penetration testing services are provided.](https://infosectoday.com/vulnerability-management/automation-is-transforming-how-penetration-testing-services-are-provided/): Pentesting remains one of the most effective methods for identifying real-world security weaknesses before adversaries can exploit them. However, as the threat landscape has evolved, the delivery of pentest results has not kept pace. Most organisations still depend on traditional reporting methods, such as static PDFs, emailed documents, and spreadsheet-based tracking. These outdated workflows introduce delays, create inefficiencies, and undermine the value of the work. Security teams require faster insights, tighter handoffs, and clearer paths to remediation. Automated delivery platforms like PlexTrac provide real-time pentest finding delivery through robust, rules-based workflows, eliminating the need to wait for final reports. The […] - [Increasing municipal infrastructure hacking risk](https://infosectoday.com/cybersecurity-threats/increasing-municipal-infrastructure-hacking-risk/): A small-town water system, a county hospital, and a local school district may not appear to be front-line targets in global conflict, yet they are increasingly vulnerable to cyber attacks. These organisations face daily threats, ranging from ransomware to foreign adversaries probing for weaknesses. The implications of these attacks can extend to national security, disrupting essential services such as healthcare and transportation. This warning is highlighted in a recent report from the Multi-State Information Sharing and Analysis Center (MS-ISAC), which examines the current threat landscape, recent successes, and the critical needs identified by State, Local, Tribal, and Territorial (SLTT) organisations. […] - [OSINT helps financial institutions combat money laundering](https://infosectoday.com/osint-tools-for-financial-investigations/osint-helps-financial-institutions-combat-money-laundering/): Open Source Intelligence (OSINT) tools play a crucial role in helping financial firms combat money laundering by revealing complex networks and ownership structures. Money launderers frequently utilise layered networks of offshore entities and shell companies to obscure the true Ultimate Beneficial Owner (UBO) of a company. The manual process of identifying UBOs can be laborious and inefficient, often leading to missed insights. By leveraging public data sources such as corporate registries and property ownership records, OSINT tools can create detailed maps of intricate corporate and criminal networks. This capability allows investigators to work more efficiently, uncovering connections between individuals and […] - [Commvault pre-auth exploit chain allows remote code execution](https://infosectoday.com/remote-code-execution/chains-of-pre-auth-exploits-discovered-in-commvault-may-allow-attackers-to-execute-remote-code/): Commvault has released critical updates to address four security vulnerabilities that could be exploited for remote code execution on affected instances. The vulnerabilities, identified in Commvault versions prior to 11.36.60, include CVE-2025-57788 (CVSS score: 6.9), which allows unauthenticated attackers to execute API calls without user credentials; CVE-2025-57789 (CVSS score: 5.3), which enables remote attackers to exploit default credentials during the setup phase to gain admin control; CVE-2025-57790 (CVSS score: 8.7), a path traversal vulnerability that permits unauthorized file system access; and CVE-2025-57791 (CVSS score: 6.9), which allows remote attackers to manipulate command-line arguments due to insufficient input validation. Researchers Sonny […] - [ClickFix & fake CAPTCHAs facilitate CORNFLAKE.V3 deployment](https://infosectoday.com/cybersecurity-threats/clickfix-fake-captchas-facilitate-cornflake-v3-deployment/): Threat actors have been observed employing a deceptive social engineering tactic known as ClickFix to deploy a versatile backdoor codenamed CORNFLAKE.V3. Google-owned Mandiant has described this activity, tracked as UNC5518, as part of an access-as-a-service scheme that utilises fake CAPTCHA pages to lure users into providing initial access to their systems. This access is subsequently monetised by other threat groups. The initial infection vector, referred to as ClickFix, involves enticing users on compromised websites to copy a malicious PowerShell script and execute it via the Windows Run dialog box. The access provided by UNC5518 is believed to be leveraged by […] - [QuirkyLoader distributes Agent Tesla, AsyncRAT, Snake Keylogger and other malware](https://infosectoday.com/cybersecurity-threats/quirkyloader-distributes-agent-tesla-asyncrat-snake-keylogger-and-other-malware/): Cybersecurity researchers have revealed a new malware loader named QuirkyLoader, which has been actively delivering various next-stage payloads, including information stealers and remote access trojans, through email spam campaigns since November 2024. Notable malware families distributed via QuirkyLoader include Agent Tesla, AsyncRAT, Formbook, Masslogger, Remcos RAT, Rhadamanthys Stealer, and Snake Keylogger. IBM X-Force reported that these attacks utilise spam emails sent from both legitimate email service providers and self-hosted servers. The emails contain a malicious archive that includes a DLL, an encrypted payload, and a legitimate executable. Security researcher Raymond Joseph Alfonso explained that the threat actor employs DLL side-loading, […] - [DOJ charges 22-year-old accused RapperBot botmaster](https://infosectoday.com/cybercrime/doj-charges-22-year-old-accused-rapperbot-botmaster/): A 22-year-old man from Oregon, Ethan Foltz, has been charged with allegedly developing and managing a distributed denial-of-service (DDoS)-for-hire botnet known as RapperBot. The U.S. Department of Justice (DoJ) reported that this botnet has been responsible for large-scale DDoS attacks targeting victims in over 80 countries since at least 2021. Foltz faces one count of aiding and abetting computer intrusions, with a potential maximum penalty of 10 years in prison if convicted. Law enforcement authorities executed a search warrant at Foltz’s residence on August 6, 2025, seizing control of the botnet infrastructure. RapperBot, also referred to as ‘Eleven Eleven Botnet’ […] - [Apache ActiveMQ exploit allows DripDropper installation on Linux cloud systems](https://infosectoday.com/cybersecurity-vulnerabilities/apache-activemq-exploit-allows-dripdropper-installation-on-linux-cloud-systems/): Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware known as DripDropper. In a surprising twist, these unknown attackers have been observed patching the exploited vulnerability after securing initial access, thereby preventing further exploitation by other adversaries and evading detection, according to a report by Red Canary shared with The Hacker News. The attacks leverage a maximum-severity security flaw in Apache ActiveMQ (CVE-2023-46604, CVSS score: 10.0), a remote code execution vulnerability that allows for the execution of arbitrary shell commands. This flaw was addressed in late […] - [AWS Trusted Advisor vulnerability hides public S3 buckets](https://infosectoday.com/s3-access-control-mechanisms/aws-trusted-advisor-vulnerability-hides-public-s3-buckets/): AWS’s Trusted Advisor tool is designed to alert customers about the public exposure of their S3 storage buckets. However, recent findings by Fog Security researchers indicate that this tool can be manipulated to report buckets as not exposed, even when they are. Amazon S3 offers various access protection mechanisms, including IAM users, roles, and policies, bucket policies, and access control lists (ACLs). While AWS encourages the use of bucket policies over ACLs, it also provides a “Block Public Access” feature to prevent unintended public access. By default, new S3 buckets block all public access, but users may disable this feature […] - [FBI alleges Russian APT group exploiting old Cisco vulnerability (CVE-2018-0171)](https://infosectoday.com/vulnerability-exploitation/fbi-alleges-russian-apt-group-exploiting-old-cisco-vulnerability-cve-2018-0171/): Russian state-sponsored hackers, identified as Static Tundra, have been actively exploiting a seven-year-old vulnerability in Cisco devices, specifically CVE-2018-0171. This critical flaw allows attackers to gain unauthorised access to affected systems, posing significant risks to organisations that have not patched their devices. The FBI has issued warnings regarding this ongoing campaign, highlighting the persistent nature of Static Tundra’s operations. By targeting outdated vulnerabilities, these hackers demonstrate a strategic approach to infiltrating networks and compromising sensitive data. The exploitation of CVE-2018-0171 underscores the importance of timely software updates and robust cybersecurity measures. Static Tundra’s activities serve as a reminder for organisations […] - [Git version 2.51: Getting ready for the future by incorporating SHA-256.](https://infosectoday.com/cryptographic-security/git-version-2-51-getting-ready-for-the-future-by-incorporating-sha-256/): Git 2.51 has been released, continuing the ongoing effort to modernise the version control system. This update introduces several technical enhancements, with a significant focus on bolstering cryptographic security through the support of SHA-256. Since its inception in 2005, Git has relied on SHA-1, which has become increasingly vulnerable to collision attacks, rendering it unsuitable for long-term use. The transition to SHA-256 is complex, as Git repositories are built around object IDs that depend on the hash function. While repositories still default to SHA-1, the 2.51 release enhances internal support for SHA-256, particularly in the transport layer and object verification […] - [VPN applications for Android, widely utilized by millions of users, are secretly maintaining connections and are vulnerable to security issues.](https://infosectoday.com/vpn-provider-families/vpn-applications-for-android-widely-utilized-by-millions-of-users-are-secretly-maintaining-connections-and-are-vulnerable-to-security-issues/): A recent study by researchers from Arizona State University and Citizen Lab has revealed that three families of Android VPN apps, collectively boasting over 700 million downloads on Google Play, are secretly interconnected. Virtual Private Networks (VPNs) are often promoted as tools for enhancing user privacy and securing internet traffic. However, the consumer VPN landscape is notably opaque, making it challenging for users to make informed decisions regarding their online security. Researchers Benjamin Mixon-Baca, Jeffrey Knockel, and Jedidiah R. Crandall conducted an extensive analysis of various Android VPN apps, uncovering hidden affiliations among providers who deliberately obscure their ownership. They […] - [United Kingdom government withdraws Apple backdoor request](https://infosectoday.com/encryption-policy/united-kingdom-government-withdraws-apple-backdoor-request/): The U.K. government has reportedly abandoned its plans to compel Apple to weaken encryption protections and implement a backdoor that would allow access to the encrypted data of U.S. citizens. U.S. Director of National Intelligence Tulsi Gabbard stated on X that the U.S. government had collaborated with its U.K. partners over recent months to safeguard Americans’ civil liberties. As a result, the U.K. has agreed to withdraw its mandate for Apple to provide a backdoor, which would have infringed upon these civil liberties. This decision follows Apple’s disabling of its Advanced Data Protection feature for iCloud in the U.K. earlier […] - [URL-based and QR code phishing increasing](https://infosectoday.com/url-based-threats/url-based-and-qr-code-phishing-increasing/): Cybercriminals are increasingly employing advanced social engineering techniques and AI-generated content to create malicious URLs that are difficult for users to identify, according to Proofpoint. URL-based threats have become the dominant form of cyber threats, manifesting through emails, text messages, and collaboration apps. Attackers are not only impersonating trusted brands but are also abusing legitimate services, tricking users with fake error prompts, and embedding threats in QR codes and SMS messages to bypass traditional security measures. The preference for URLs over attachments has grown significantly in recent years. Researchers observed that, during a six-month period in 2024–2025, URL threats were […] - [CISOs must consider potential risks before hastily adopting AI technologies.](https://infosectoday.com/cybersecurity-posture/cisos-must-consider-potential-risks-before-hastily-adopting-ai-technologies/): Organisations are increasingly investing in cloud, AI, and emerging technologies, yet their infrastructure and security strategies often lag behind. A recent Unisys survey of 1,000 senior executives reveals a misalignment between business and IT leaders regarding the necessary preparations for the next wave of technology. From a security perspective, the findings raise concerns about the speed at which organisations advance without addressing core risks. Eighty-five per cent of respondents indicated that their cybersecurity posture is reactive, focusing more on incident response than prevention. This reactive approach leaves organisations vulnerable to attacks that can result in significant downtime. Notably, 41 per […] - [AI browsers scammed by PromptFix attacks run malicious hidden prompts](https://infosectoday.com/cybersecurity-threats/ai-browsers-scammed-by-promptfix-attacks-run-malicious-hidden-prompts/): Cybersecurity researchers have unveiled a new prompt injection technique known as PromptFix. This method deceives a generative artificial intelligence (GenAI) model by embedding malicious instructions within a fake CAPTCHA check on a web page. Guardio Labs describes this technique as an “AI-era take on the ClickFix scam.” The attack demonstrates how AI-driven browsers, such as Perplexity’s Comet, which are designed to automate mundane tasks like online shopping or email management, can be manipulated into engaging with phishing landing pages or fraudulent storefronts without the user’s awareness. Guardio explains that the approach differs from traditional methods, as it does not attempt […] - [Healthcare cybersecurity risks increasing - especially password management](https://infosectoday.com/password-security-risks/healthcare-cybersecurity-risks-increasing-especially-password-management/): In 2025, healthcare organisations are confronting a significant rise in password security risks. Recent data from the HIMSS Cybersecurity Survey indicates that 74% of these organisations experienced at least one major security incident in the past year. More than half of the respondents, specifically 52%, anticipate an increase in their IT budgets for 2025. Notably, 55% of health systems plan to allocate funds specifically for cybersecurity initiatives, which include enhancing tools, updating policies, and expanding IT teams. The underlying issues remain consistent: poor security practices, reused passwords, outdated tools, insufficient staff training, and employee fatigue. Medical staff now spend an […] - [Pharmaceutical company Inotiv hit by ransomware attack](https://infosectoday.com/business-impact/pharmaceutical-company-inotiv-hit-by-ransomware-attack/): Inotiv, a pharmaceutical company, has officially notified the Securities and Exchange Commission (SEC) about a significant disruption to its business operations following a ransomware attack. Hackers successfully compromised and encrypted Inotiv’s internal systems, leading to operational challenges that have impacted the company’s ability to function effectively. The breach has raised concerns regarding data security and the potential implications for stakeholders. Inotiv is currently working to assess the full extent of the damage and implement measures to restore its systems and safeguard against future attacks. The ransomware incident has highlighted the increasing threat of cyberattacks within the pharmaceutical sector, prompting Inotiv […] - [Regional Australian councils expose confidential information due to Workhorse vulnerability](https://infosectoday.com/data-security/regional-australian-councils-expose-confidential-information-due-to-workhorse-vulnerability/): The Cyber Emergency Response Team Coordination Center (CERT/CC) has revealed critical information exposure vulnerabilities in a Workhorse Software application, which is widely utilised by numerous cities and towns across Australia. Despite the release of patches intended to address these security flaws, sensitive data remains at risk due to inadequate remediation efforts. The vulnerabilities could potentially allow unauthorised access to personal information, raising significant concerns for local governments and their constituents. As the software is employed by hundreds of municipalities, the implications of these flaws extend far beyond individual users, potentially affecting entire communities. In light of these findings, it is […] - [SAP Netweaver exploits CVE-2025-31324 and CVE-2025-42999 publicly released](https://infosectoday.com/cybersecurity-threats/sap-netweaver-vulnerabilities-cve-2025-31324-and-cve-2025-42999-publicly-released/): A working exploit that concatenates two critical SAP Netweaver vulnerabilities, CVE-2025-31324 and CVE-2025-42999, has been made public by VX Underground, as warned by Onapsis security researchers. This exploit was allegedly released on a Telegram channel associated with a collective of three established cybercrime groups: Scattered Spider, ShinyHunters, and LAPSUS$. Earlier this year, CVE-2025-31324, a missing authentication bug, was exploited by an initial access broker group to upload webshells, paving the way for subsequent ransomware attacks. Following this, opportunistic threat actors leveraged the established webshells on vulnerable systems. In mid-May, SAP released fixes for CVE-2025-42999, which altered the file processing mechanism […] - [North Korean hackers target diplomats via GitHub spearphishing attack](https://infosectoday.com/cyber-espionage/north-korean-hackers-target-diplomats-via-github-spearphishing-attack/): North Korean threat actors have been linked to a coordinated cyber espionage campaign targeting diplomatic missions in South Korea between March and July 2025. This campaign involved at least 19 spear-phishing emails that impersonated trusted diplomatic contacts, aiming to lure embassy staff and foreign ministry personnel with convincing meeting invites, official letters, and event invitations. The attackers utilised GitHub, a platform typically associated with legitimate development, as a covert command-and-control channel. Trellix researchers Pham Duy Phuc and Alex Lanstein noted that the infection chains relied on trusted cloud storage solutions like Dropbox and Daum Cloud to deliver a variant of […] ## Pages - [Infrastructure Attacks](https://infosectoday.com/articles/infrastructure-attacks/) - [Supply Chain Attacks](https://infosectoday.com/articles/supply-chain-attacks/): Supply chain attacks have become one of the most dangerous cybersecurity threats of the past decade. Unlike traditional breaches, attackers no longer need to break down the front door. Instead, they compromise a trusted supplier, service provider, or software vendor and ride that trust directly into the heart of their targets. From SolarWinds to NotPetya to CCleaner, the message is clear: an organization is only as secure as the weakest link in its supply chain. This article explains what supply chain attacks are, how they work, why they’re so devastating, and—most importantly—what you can do to defend against them. What […] - [Phishing](https://infosectoday.com/articles/social-engineering/phishing/) - [Social Engineering](https://infosectoday.com/articles/social-engineering/) - [DOS & DDOS Attacks](https://infosectoday.com/articles/dos-ddos-attacks/) - [How Traditional Deep Packet Analysis Works](https://infosectoday.com/articles/deep-packet-inspection/how-traditional-deep-packet-analysis-works/): Traditional DPI is a deterministic pipeline built around protocol decoding and content signatures. Think accurate, explainable, tunable—with strict attention to performance and evasions. Steps in traditional deep packet analysis 1) Packet Ingest & Normalization 2) Flow Tracking & Reassembly 3) Protocol Identification & Decoding 4) Content Transforms (Canonicalization) 5) Content Inspection (Signature Engines) Example (Suricata, request-side heuristic): For response-side PE delivery, pivot to to_client and file.magic/fileext buffers instead of URI/UA. 6) Policy, Actions, and Response 7) Performance Engineering 8) Evasion & Robustness Controls 9) Telemetry & Forensics 10) Limitations (Why AI Helps Later) 11) Operational Add-Ons (Often Overlooked) Quick Deployment […] - [Deep Packet Analysis: How AI Models Process Packet Metadata](https://infosectoday.com/articles/deep-packet-inspection/deep-packet-analysis-how-ai-models-process-packet-metadata/): Traditional DPI engines look inside packet payloads. But with 80%+ of internet traffic encrypted, payload inspection isn’t always possible. Instead, AI models can analyze metadata — the statistical and structural characteristics of traffic flows — to infer malicious intent without decryption. Here’s how it works: 1. Feature Extraction From each network flow, the DPI system extracts metadata features, such as: 2. Data Normalization Raw values are normalized into machine-readable vectors: 3. Model Training Different AI/ML approaches can be applied: 4. Real-Time Inference When deployed inline, the trained model processes flows as they pass through: 5. Feedback Loop Practical Example: A […] - [Deep Packet Inspection](https://infosectoday.com/articles/deep-packet-inspection/): Modern enterprises face a constant barrage of network-based threats — from commodity malware to sophisticated nation-state intrusions. Traditional firewalls and intrusion detection systems, once the backbone of perimeter defense, often lack the granularity to deal with modern, encrypted, and evasive traffic. Enter Deep Packet Inspection (DPI) — a powerful technology that inspects not just packet headers, but the payloads themselves, to identify, classify, and sometimes block network traffic. What is Deep Packet Inspection? At its core, DPI is a method of examining network traffic beyond the OSI layer 3 and 4 headers (IP and TCP/UDP). Unlike basic packet filtering that […] - [Darknets / Dark Web](https://infosectoday.com/articles/darknets/): Introduction When the term darknet comes up, most people imagine shadowy corners of the internet where cybercriminals thrive. While this perception is not entirely inaccurate, it only tells part of the story. Darknets play a complex role in today’s digital ecosystem. For cybersecurity practitioners, researchers, and policymakers, understanding darknets is essential—both for defense against criminal activity and for appreciating their role in digital privacy, free speech, and political resistance. What is a Darknet? A darknet is an overlay network built on top of the regular internet but designed to provide anonymity and privacy to its users. Unlike the “surface web,” […] - [Contact](https://infosectoday.com/contact/) - [D3f3ndo](https://infosectoday.com/defendo/): D3f3ndo is a helpful chatbot who just loves answering your questions about cybersecurity. - [Mobile Device Security](https://infosectoday.com/articles/mobile-device-physical-security/): When most people think about cybersecurity, their minds jump straight to firewalls, intrusion detection, encryption, and patch management. But there’s another dimension of security that often gets overlooked: physical security—particularly when it comes to mobile devices. Addressing physical device security includes considering the set of policies, controls, and best practices that prevent theft, tampering, or unauthorised access to mobile devices such as smartphones, tablets, and laptops. Unlike purely digital defenses, physical safeguards ensure that attackers can’t simply bypass your network security by stealing the hardware itself. Why Physical Security Matters for Mobile Devices Mobile devices are powerful, portable, and pervasive. […] - [Cyberwarfare](https://infosectoday.com/articles/cyberwarfare/): What Is Cyberwarfare? From stealthy espionage to critical‑infrastructure disruption, cyberwarfare has reshaped how nations compete, defend, and project power. Cyberwarfare is the use of digital operations by nation‑states (or their proxies) to achieve political, military, or strategic objectives against other states. Unlike financially motivated cybercrime, these operations are designed to shape the geopolitical environment—from covert data theft to overt disruption of critical services. In cyberspace, borders are porous, timing is instantaneous, and plausible deniability is a strategic weapon. Strategic Objectives Anatomy of a Cyberwarfare Campaign Nation‑state operations rarely hinge on a single exploit. They unfold as multi‑phase campaigns aligned to […] - [AI Privacy Policy](https://infosectoday.com/legals/ai-privacy-policy/) - [Privacy Policy](https://infosectoday.com/legals/privacy-policy-2/) - [Terms & Conditions](https://infosectoday.com/legals/terms-conditions/) - [Legals](https://infosectoday.com/legals/) - [Articles](https://infosectoday.com/articles/) - [Course 1](https://infosectoday.com/courses/course-1/) - [Courses](https://infosectoday.com/courses/) - [Course Completed](https://infosectoday.com/course-completed/): Congratulations on completing this course! 🥳 - [My Courses](https://infosectoday.com/my-courses/) - [Cybersecurity Glossary](https://infosectoday.com/cybersecurity-glossary/) [comment]: # (Generated by Hostinger Tools Plugin)