“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
ShadowSilk Data Exfiltration Attack
FortiGuard Labs’ network telemetry has observed active exploitation of known vulnerabilities in Drupal Core and the WP-Automatic WordPress plugin for initial access. Following compromise, attackers deploy multiple web shells and utilities to enable lateral movement, privilege escalation, and the installation of remote access trojans (RATs).Read More
-

Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories [email protected] (The Hacker News)
A security weakness has been disclosed in the artificial intelligence (AI)-powered code editor Cursor that could trigger code execution when a maliciously crafted repository is opened using the program. The issue stems from the fact that an out-of-the-box security setting is disabled by default, opening the door for attackers to run arbitrary code on users’…
-

Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity [email protected] (The Hacker News)
Google on Tuesday announced that its new Google Pixel 10 phones support the Coalition for Content Provenance and Authenticity (C2PA) standard out of the box to verify the origin and history of digital content. To that end, support for C2PA’s Content Credentials has been added to Pixel Camera and Google Photos apps for Android. The…
-

Senator Wyden Urges FTC to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence [email protected] (The Hacker News)
U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to probe Microsoft and hold it responsible for what he called “gross cybersecurity negligence” that enabled ransomware attacks on U.S. critical infrastructure, including against healthcare networks. “Without timely action, Microsoft’s culture of negligent cybersecurity, combined with its de facto monopolization of theRead More
-
Positive vs. negative security: Choosing an AppSec model
Understand the benefits and challenges of positive and negative security models to determine how to best protect web apps in your organization.Read More
-

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers [email protected] (The Hacker News)
Threat actors affiliated with the Akira ransomware group have continued to target SonicWall devices for initial access. Cybersecurity firm Rapid7 said it observed a spike in intrusions involving SonicWall appliances over the past month, particularly following reports about renewed Akira ransomware activity since late July 2025. SonicWall subsequently revealed the SSL VPN activity aimed at…
-

Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts [email protected] (The Hacker News)
Cybersecurity researchers have disclosed two new campaigns that are serving fake browser extensions using malicious ads and fake websites to steal sensitive data. The malvertising campaign, per Bitdefender, is designed to push fake “Meta Verified” browser extensions named SocialMetrics Pro that claim to unlock the blue check badge for Facebook and Instagram profiles. At least…
-

Cracking the Boardroom Code: Helping CISOs Speak the Language of Business [email protected] (The Hacker News)
CISOs know their field. They understand the threat landscape. They understand how to build a strong and cost-effective security stack. They understand how to staff out their organization. They understand the intricacies of compliance. They understand what it takes to reduce risk. Yet one question comes up again and again in our conversations with these…
-

AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deliver a fleshless loader that drops a remote access trojan (RAT) called AsyncRAT to steal sensitive data from compromised hosts. “The attacker used ScreenConnect to gain remote access, then executed a layered VBScript…
-
Kunbus RevPi Webstatus Authentication Bypass
What is the Vulnerability? FortiGuard Labs has detected active attack attempts targeting the Kunbus Revolution Pi Webstatus authentication bypass vulnerability (CVE-2025-41646), a flaw that allows remote attackers to log in without a password by exploiting improper credential handling. A public proof-of-concept is already available, increasing the likelihood of widespread exploitation. The vulnerability can be triggered…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
