Category: Uncategorized
-

Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS Attack [email protected] (The Hacker News)
Cloudflare on Tuesday said it automatically mitigated a record-setting volumetric distributed denial-of-service (DDoS) attack that peaked at 11.5 terabits per second (Tbps). “Over the past few weeks, we’ve autonomously blocked hundreds of hyper-volumetric DDoS attacks, with the largest reaching peaks of 5.1 Bpps and 11.5 Tbps,” the web infrastructure and security company said in a…
-

CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active Exploitation [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity security flaw impacting TP-Link TL-WA855RE Wi-Fi Ranger Extender products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2020-24363 (CVSS score: 8.8), concerns a case of missing authentication that could be abused to obtainRead More
-

Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations [email protected] (The Hacker News)
Salesloft on Tuesday announced that it’s taking Drift temporarily offline “in the very near future,” as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication tokens. “This will provide the fastest path forward to comprehensively review the application and buildRead…
-

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE [email protected] (The Hacker News)
The North Korea-linked threat actor known as the Lazarus Group has been attributed to a social engineering campaign that distributes three different pieces of cross-platform malware called PondRAT, ThemeForestRAT, and RemotePE. The attack, observed by NCC Group’s Fox-IT in 2024, targeted an organization in the decentralized finance (DeFi) sector, ultimately leading to the compromise of…
-

Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control [email protected] (The Hacker News)
Cybersecurity researchers have disclosed a stealthy new backdoor called MystRodX that comes with a variety of features to capture sensitive data from compromised systems. “MystRodX is a typical backdoor implemented in C++, supporting features like file management, port forwarding, reverse shell, and socket management,” QiAnXin XLab said in a report published last week. “Compared to…
-

Shadow AI Discovery: A Critical Part of Enterprise AI Governance [email protected] (The Hacker News)
The Harsh Truths of AI Adoption MITs State of AI in Business report revealed that while 40% of organizations have purchased enterprise LLM subscriptions, over 90% of employees are actively using AI tools in their daily work. Similarly, research from Harmonic Security found that 45.4% of sensitive AI interactions are coming from personal email accounts,…
-
An introduction to AWS IAM and security best practices
With AI threats rising and machine identities outnumbering humans 82-to-1, discover how AWS IAM’s authentication and authorization framework safeguards your cloud resources.Read More
-

Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices [email protected] (The Hacker News)
Cybersecurity researchers have flagged a Ukrainian IP network for engaging in massive brute-force and password spraying campaigns targeting SSL VPN and RDP devices between June and July 2025. The activity originated from a Ukraine-based autonomous system FDN3 (AS211736), per French cybersecurity company Intrinsec. “We believe with a high level of confidence that FDN3 is part…
-

Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT Malware [email protected] (The Hacker News)
The threat actor known as Silver Fox has been attributed to abuse of a previously unknown vulnerable driver associated with WatchDog Anti-malware as part of a Bring Your Own Vulnerable Driver (BYOVD) attack aimed at disarming security solutions installed on compromised hosts. The vulnerable driver in question is “amsdk.sys” (version 1.0.600), a 64-bit, validly signed…
-

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets [email protected] (The Hacker News)
Cybersecurity researchers have discovered a malicious npm package that comes with stealthy features to inject malicious code into desktop apps for cryptocurrency wallets like Atomic and Exodus on Windows systems. The package, named nodejs-smtp, impersonates the legitimate email library nodemailer with an identical tagline, page styling, and README descriptions, attracting a total of 347Read More
