Category: Uncategorized
-

Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon [email protected] (The Hacker News)
The North Korea-affiliated threat actor known as Konni (aka Earth Imp, Opal Sleet, Osmium, TA406, and Vedalia) has been attributed to a new set of attacks targeting both Android and Windows devices for data theft and remote control. “Attackers impersonated psychological counselors and North Korean human rights activists, distributing malware disguised as stress-relief programs,” the…
-

⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and More [email protected] (The Hacker News)
Cyber threats didn’t slow down last week—and attackers are getting smarter. We’re seeing malware hidden in virtual machines, side-channel leaks exposing AI chats, and spyware quietly targeting Android devices in the wild. But that’s just the surface. From sleeper logic bombs to a fresh alliance between major threat groups, this week’s roundup highlights a clear…
-

New Browser Security Report Reveals Emerging Threats for Enterprises [email protected] (The Hacker News)
According to the new Browser Security Report 2025, security leaders are discovering that most identity, SaaS, and AI-related risks converge in a single place, the user’s browser. Yet traditional controls like DLP, EDR, and SSE still operate one layer too low. What’s emerging isn’t just a blindspot. It’s a parallel threat surface: unmanaged extensions acting…
-
CNAPP vs. CSPM: Comparing cloud security tools
CNAPP or CSPM? Understand the key differences between these cloud security tools to make an informed choice that aligns with your organization’s maturity level.Read More
-

Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware [email protected] (The Hacker News)
Cybersecurity researchers have called attention to a massive phishing campaign targeting the hospitality industry that lures hotel managers to ClickFix-style pages and harvest their credentials by deploying malware like PureRAT. “The attacker’s modus operandi involved using a compromised email account to send malicious messages to multiple hotel establishments,” Sekoia said. “This campaignRead More
-

GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs [email protected] (The Hacker News)
Cybersecurity researchers have disclosed a new set of three extensions associated with the GlassWorm campaign, indicating continued attempts on part of threat actors to target the Visual Studio Code (VS Code) ecosystem. The extensions in question, which are still available for download, are listed below – ai-driven-dev.ai-driven-dev (3,402 downloads) adhamu.history-in-sublime-merge (4,057Read More
-

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic [email protected] (The Hacker News)
Microsoft has disclosed details of a novel side-channel attack targeting remote language models that could enable a passive adversary with capabilities to observe network traffic to glean details about model conversation topics despite encryption protections under certain circumstances. This leakage of data exchanged between humans and streaming-mode language models could pose serious risks toRead More
-

Samsung Zero-Click Flaw Exploited to Deploy LANDFALL Android Spyware via WhatsApp [email protected] (The Hacker News)
A now-patched security flaw in Samsung Galaxy Android devices was exploited as a zero-day to deliver a “commercial-grade” Android spyware dubbed LANDFALL in targeted attacks in the Middle East. The activity involved the exploitation of CVE-2025-21042 (CVSS score: 8.8), an out-of-bounds write flaw in the “libimagecodec.quram.so” component that could allow remote attackers to execute arbitraryRead…
-

From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools [email protected] (The Hacker News)
A China-linked threat actor has been attributed to a cyber attack targeting an U.S. non-profit organization with an aim to establish long-term persistence, as part of broader activity aimed at U.S. entities that are linked to or involved in policy issues. The organization, according to a report from Broadcom’s Symantec and Carbon Black teams, is…
-
News brief: Collaboration apps face security scrutiny — again
Check out the latest security news from the Informa TechTarget team.Read More
