Category: Uncategorized
-
Microsoft Windows Server Update Service Remote Code Execution Vulnerability
What is the Vulnerability? CVE-2025-59287 is a critical unauthenticated remote code execution (RCE) vulnerability affecting Windows Server Update Services (WSUS). The flaw stems from unsafe deserialization of untrusted data, allowing attackers to execute arbitrary code on vulnerable servers without authentication. A public proof-of-concept exploit has been released, and CISA has added the vulnerability to its…
-
To maximize their influence, CISOs need diverse skills
In many organizations today, when the CISO talks, the CEO and board listen. CISOs who successfully rise to the occasion have broad skillsets.Read More
-

Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive [email protected] (The Hacker News)
Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry that harbors a remote access trojan called SleepyDuck. According to Secure Annex’s John Tuckner, the extension in question, juan-bianco.solidity-vlang (version 0.0.7), was first published on October 31, 2025, as a completely benign library that was subsequently updated to version 0.0.8 on November…
-
Browser detection and response fills gaps in security programs
BDR is the latest tool to address detection and response as more and more communication occurs over Edge, Chrome and their counterparts. But does your organization really need it?Read More
-

Cybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks [email protected] (The Hacker News)
Bad actors are increasingly training their sights on trucking and logistics companies with an aim to infect them with remote monitoring and management (RMM) software for financial gain and ultimately steal cargo freight. The threat cluster, believed to be active since at least June 2025 according to Proofpoint, is said to be collaborating with organized…
-

⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & More [email protected] (The Hacker News)
Cyberattacks are getting smarter and harder to stop. This week, hackers used sneaky tools, tricked trusted systems, and quickly took advantage of new security problems—some just hours after being found. No system was fully safe. From spying and fake job scams to strong ransomware and tricky phishing, the attacks came from all sides. Even encrypted…
-

The Evolution of SOC Operations: How Continuous Exposure Management Transforms Security Operations [email protected] (The Hacker News)
Security Operations Centers (SOC) today are overwhelmed. Analysts handle thousands of alerts every day, spending much time chasing false positives and adjusting detection rules reactively. SOCs often lack the environmental context and relevant threat intelligence needed to quickly verify which alerts are truly malicious. As a result, analysts spend excessive time manually triaging alerts, theRead…
-

Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data [email protected] (The Hacker News)
Cybersecurity researchers have shed light on two different Android trojans called BankBot-YNRK and DeliveryRAT that are capable of harvesting sensitive data from compromised devices. According to CYFIRMA, which analyzed three different samples of BankBot-YNRK, the malware incorporates features to sidestep analysis efforts by first checking its running within a virtualized or emulated environmentRead More
-

New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea [email protected] (The Hacker News)
The North Korea-linked threat actor known as Kimsuky has distributed a previously undocumented backdoor codenamed HttpTroy as part of a likely spear-phishing attack targeting a single victim in South Korea. Gen Digital, which disclosed details of the activity, did not reveal any details on when the incident occurred, but noted that the phishing email contained…
-

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability [email protected] (The Hacker News)
The Australian Signals Directorate (ASD) has issued a bulletin about ongoing cyber attacks targeting unpatched Cisco IOS XE devices in the country with a previously undocumented implant known as BADCANDY. The activity, per the intelligence agency, involves the exploitation of CVE-2023-20198 (CVSS score: 10.0), a critical vulnerability that allows a remote, unauthenticated attacker to create…
