“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

The State of AI in the SOC 2025 – Insights from Recent Study [email protected] (The Hacker News)
Security leaders are embracing AI for triage, detection engineering, and threat hunting as alert volumes and burnout hit breaking points. A comprehensive survey of 282 security leaders at companies across industries reveals a stark reality facing modern Security Operations Centers: alert volumes have reached unsustainable levels, forcing teams to leave critical threats uninvestigated. You canRead…
-

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security [email protected] (The Hacker News)
Microsoft is calling attention to a new phishing campaign primarily aimed at U.S.-based organizations that has likely utilized code generated using large language models (LLMs) to obfuscate payloads and evade security defenses. “Appearing to be aided by a large language model (LLM), the activity obfuscated its behavior within an SVG file, leveraging business terminology and…
-

First Malicious MCP Server Found Stealing Emails in Rogue Postmark-MCP Package [email protected] (The Hacker News)
Cybersecurity researchers have discovered what has been described as the first-ever instance of a Model Context Protocol (MCP) server spotted in the wild, raising software supply chain risks. According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called “postmark-mcp” that copied an official Postmark Labs library of…
-

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks [email protected] (The Hacker News)
Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU). “The new variant’s features overlap with both the RainyDay and Turian backdoors, including abuse of the same legitimate applications for DLL side-loading,…
-

Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam [email protected] (The Hacker News)
A new campaign has been observed impersonating Ukrainian government agencies in phishing attacks to deliver CountLoader, which is then used to drop Amatera Stealer and PureMiner. “The phishing emails contain malicious Scalable Vector Graphics (SVG) files designed to trick recipients into opening harmful attachments,” Fortinet FortiGuard Labs researcher Yurren Wan said in a report shared…
-
What to know about 5G security threats in the enterprise
Learn about key 5G security threats facing enterprises, plus practical defense strategies for CISOs.Read More
-
News brief: AI cybersecurity worries mount
Check out the latest security news from the Informa TechTarget team.Read More
-

New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks [email protected] (The Hacker News)
The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks designed to deliver two new “lightweight” malware families tracked as BAITSWITCH and SIMPLEFIX. Zscaler ThreatLabz, which detected the new multi-stage ClickFix campaign earlier this month, described BAITSWITCH as a downloader that ultimately drops SIMPLEFIX, aRead…
-

Crash Tests for Security: Why BAS Is Proof of Defense, Not Assumptions [email protected] (The Hacker News)
Car makers don’t trust blueprints. They smash prototypes into walls. Again and again. In controlled conditions. Because design specs don’t prove survival. Crash tests do. They separate theory from reality. Cybersecurity is no different. Dashboards overflow with “critical” exposure alerts. Compliance reports tick every box. But none of that proves what matters most to a…
-

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure [email protected] (The Hacker News)
Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early as September 10, 2025, a whole week before it was publicly disclosed. “This is not ‘just’ a CVSS 10.0 flaw in a solution long favored…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
