loader image
Quasar RAT Spread by Bat Files in Stealth Malware Push

Cybersecurity analysts have uncovered a new campaign in which threat actors are using Windows batch files to deploy the Quasar RAT, a known remote access Trojan. The attack begins with a deceptive batch file that appears benign but covertly initiates the download and execution of malicious payloads, marking a notable shift in malware delivery tactics. […]

Windows SMB Flaw Lets Hackers Hijack System Privileges

A critical Windows SMB vulnerability tracked as CVE-2025-33073 has been exploited in the wild using a technique known as Reflective Kerberos Relay Attack. Microsoft addressed the flaw during its June 2025 Patch Tuesday updates, assigning it a CVSS score of 9.8 due to the high risk of privilege escalation and low exploitation complexity. The Reflective […]

Stryker Android Hacking App Offers Free Access to 2050

The Stryker Android hacking app, a penetration testing tool for mobile security professionals, has made its premium features available for free until the year 2050, according to a post on the r/netsec subreddit. Designed for ethical hackers and cybersecurity researchers, the app enables users to conduct advanced security assessments on Android devices, offering a suite […]

NHS Temping Unit Hid Major Active Directory Breach

A significant cybersecurity incident involving the NHS temping unit Active Directory breach was never publicly disclosed, raising concerns about transparency in handling sensitive data. The breach compromised the internal systems of NHS Professionals, the organization responsible for supplying temporary staff across the UK’s National Health Service. According to individuals familiar with the matter, incident responders […]

CISA Leads Global Push to Shield Network Edge Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with cybersecurity authorities from nine allied nations, has released a series of detailed guidelines to shield network edge devices from advanced cyber threats. These edge devices—such as firewalls, VPN gateways, and routers—are increasingly being exploited by threat actors, including state-sponsored groups. The guidance includes four technical […]

Anubis RaaS Adds Wiper Tool to Permanently Erase Data

A newly emerged ransomware-as-a-service offering known as Anubis RaaS adds wiper functionality, making attacks more destructive by permanently deleting victim data. Active since December 2024, the ransomware encrypts files and—if its “wipe mode” is enabled—erases contents irreversibly, leaving behind empty 0 KB files. The malware campaign has targeted organizations across sectors such as healthcare and […]

Paragon Spyware Found on iPhones of EU Journalists

Researchers have confirmed that spyware developed by Paragon was found on an Apple device, marking a significant development in a growing surveillance controversy in Italy. The discovery, revealed Wednesday, adds to mounting concerns over the use of advanced surveillance tools targeting journalists across Europe. The spyware’s presence was detected during an investigation into potential abuses […]

Graphite Spyware Hits iPhones of European Journalists

Security investigators have confirmed that attackers deployed Graphite Spyware Hits iPhones in a series of zero-click exploits targeting Apple iOS devices. The spyware platform, developed by Paragon, infiltrated the smartphones of at least two journalists based in Europe, according to a forensic analysis. Graphite Spyware Hits iPhones without requiring user interaction, making it highly effective […]

Archetyp Dark Web Market Busted, Admin Held in Spain

European authorities have seized the Archetyp Dark Web Market and apprehended its alleged administrator in Spain, disrupting one of the latest illicit marketplaces operating on the dark net. Officials coordinated the takedown as part of a targeted crackdown on cybercrime networks that facilitate the sale of illegal goods and services online. The operation resulted in […]

WordPress Hijacked to Spread VexTrio Scam Globally

Cybercriminals are exploiting legitimate WordPress websites in a growing scheme tied to the VexTrio Viper Traffic Distribution Service (TDS). The operation, which security researchers describe as highly organized, uses WordPress hijacked to spread malicious software and scams across a global network. VexTrio appears to operate alongside other TDS platforms, including Help TDS and Disposable TDS. […]

Episource Hack Exposes Data of 5.4 Million Patients

Hackers breached healthcare services firm Episource, compromising personal and health data of approximately 5.4 million individuals. The Episource Hack Exposes Data tied to customers of healthcare organizations that rely on the company for critical services. The attackers accessed sensitive information, including personal identifiers and medical details, raising concerns about patient privacy and data security across […]

Asana MCP AI Bug Exposed Customer Data to Rivals

Asana has alerted users to a flaw in its new Model Context Protocol (MCP), which may have exposed customer data across different organizations. The issue, linked to the Asana MCP AI Bug, surfaced in the early stages of the feature’s deployment. The company warned that the bug could have allowed data from one user’s instance […]