“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

China-Linked MirrorFace Deploys ANEL and AsyncRAT in New Cyber Espionage Operation [email protected] (The Hacker News)
Threat hunters have shed more light on a previously disclosed malware campaign undertaken by the China-aligned MirrorFace threat actor that targeted a diplomatic organization in the European Union with a backdoor known as ANEL. The attack, detected by ESET in late August 2024, singled out a Central European diplomatic institute with lures related to Word…
-

BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse [email protected] (The Hacker News)
At least four different threat actors have been identified as involved in an updated version of a massive ad fraud and residential proxy scheme called BADBOX, painting a picture of an interconnected cybercrime ecosystem. This includes SalesTracker Group, MoYu Group, Lemon Group, and LongTV, according to new findings from the HUMAN Satori Threat Intelligence and…
-
How to calculate the cost of a data breach
Post ContentRead More
-

Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto Wallets [email protected] (The Hacker News)
Microsoft is calling attention to a novel remote access trojan (RAT) named StilachiRAT that it said employs advanced techniques to sidestep detection and persist within target environments with an ultimate aim to steal sensitive data. The malware contains capabilities to “steal information from the target system, such as credentials stored in the browser, digital wallet…
-
GitHub Actions supply chain attack spotlights CI/CD risks
Post ContentRead More
-

Apache Tomcat Vulnerability Actively Exploited Just 30 Hours After Public Disclosure [email protected] (The Hacker News)
A recently disclosed security flaw impacting Apache Tomcat has come under active exploitation in the wild following the release of a public proof-of-concept (PoC) a mere 30 hours after public disclosure. The vulnerability, tracked as CVE-2025-24813, affects the below versions – Apache Tomcat 11.0.0-M1 to 11.0.2 Apache Tomcat 10.1.0-M1 to 10.1.34 Apache Tomcat 9.0.0-M1 to…
-
5 fundamental strategies for REST API authentication
Post ContentRead More
-
How to avoid and prevent social engineering attacks
Post ContentRead More
-

Unpatched Edimax Camera Flaw Exploited for Mirai Botnet Attacks Since Last Year [email protected] (The Hacker News)
An unpatched security flaw impacting the Edimax IC-7100 network camera is being exploited by threat actors to deliver Mirat botnet malware variants since at least May 2024. The vulnerability in question is CVE-2025-1316 (CVSS v4 score: 9.3), a critical operating system command injection flaw that an attacker could exploit to achieve remote code execution on…
-

Cybercriminals Exploit CSS to Evade Spam Filters and Track Email Users’ Actions [email protected] (The Hacker News)
Malicious actors are exploiting Cascading Style Sheets (CSS), which are used to style and format the layout of web pages, to bypass spam filters and track users’ actions. That’s according to new findings from Cisco Talos, which said such malicious activities can compromise a victim’s security and privacy. “The features available in CSS allow attackers…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
