loader image
North Korea Hacks Devs via Fake npm Job Interviews

A new wave of North Korea hacks devs through a deceptive campaign that uses fake job interviews and malicious npm packages. Security researchers have identified 35 compromised packages uploaded to the npm repository, which deliver infostealers and backdoors to developers’ systems. These tools collect sensitive information and open unauthorized access points. Labeled the “Contagious Interview” […]

Microsoft 365 Tool Abused to Bypass Phishing Filters

Cybercriminals have found a new exploitation path by misusing the Microsoft 365 tool abused feature known as Direct Send. This feature, intended to help internal systems send emails through Microsoft’s infrastructure, is now being leveraged to distribute phishing messages that slip past conventional email security filters. Security researchers have observed that attackers use Direct Send […]

Cisco Fixes 35 Flaws, 17 Rated Critical or High

Cisco has released security updates addressing 35 vulnerabilities across multiple products, with a significant focus on its widely used IOS and IOS XE software platforms. Of these, 26 flaws were found in IOS and IOS XE, including 17 that have been classified as critical or high severity. The company has urged users to apply the […]

Europol Shuts DDoS Sites, Arrests Four in Poland

Europol has announced the takedown of several websites offering distributed denial-of-service (DDoS)-for-hire services, along with the arrest of four individuals in Poland as part of its ongoing crackdown on cybercrime. The operation targeted illicit platforms that enable users to launch DDoS attacks without technical expertise, disrupting online services by overwhelming them with traffic. The arrests […]

Qilin Drives April Ransom Surge With NETXLOADER Tool

Qilin-linked threat actors were responsible for a significant spike in ransomware activity in April 2025, accounting for 45 breaches, according to cybersecurity researchers. The group employed a combination of the known malware SmokeLoader and a newly identified .NET-based loader dubbed NETXLOADER in a campaign first observed in November 2024. Researchers say NETXLOADER functions as a […]

Google Uses On-Device AI to Spot Scams in Chrome

Google is rolling out new artificial intelligence-based protections designed to detect online scams across its Chrome browser, Search engine, and Android operating system, the company announced Thursday. The initiative leverages Gemini Nano, Google’s on-device large language model, to enhance Safe Browsing features in Chrome version 137 on desktop platforms. By processing data locally, Gemini Nano […]

Blob URL Phishing Bypasses Email Filters, Hides in Browser

A newly identified phishing technique is exploiting blob URLs to bypass Secure Email Gateways (SEGs) and evade traditional security analysis tools, according to researchers at Cofense. The method leverages blob URIs—browser-generated, temporary data URLs—to create credential harvesting pages that reside solely in the victim’s browser memory. The attack begins with emails linking to allowlisted services […]

Moldova Nabs Suspect in €4.5M Dutch Cyberattack

Moldovan authorities have arrested a 45-year-old foreign national suspected of carrying out a €4.5 million ransomware attack on a Dutch research agency, officials said Monday. The suspect is believed to have orchestrated a series of cyber intrusions targeting companies in the Netherlands in 2021, according to a statement from law enforcement. The individual is wanted […]

SAP Fixes Second Zero-Day Used in Server Attacks

SAP has issued security patches to fix a second zero-day vulnerability that was actively exploited in recent cyberattacks targeting its NetWeaver application servers. The flaw, which had not been previously disclosed, allowed attackers to compromise systems before a fix was made available, highlighting the urgency of the update. This marks the second such vulnerability in […]

Malicious NPM Code Hides via Unicode, Google Calendar

A malicious package published to the Node Package Manager (NPM) repository has been found using Unicode-based steganography to conceal its true functionality, evading detection by traditional security tools. The package hides harmful code by embedding invisible Unicode characters within its script, a technique that obscures malicious instructions from both human reviewers and automated scanners. In […]

Hackers Win $1 Million Cracking AI, OS at Pwn2Own Berlin

Hackers earned over $1 million in cash prizes during the Pwn2Own Berlin 2025 competition, where cybersecurity researchers showcased high-impact vulnerabilities across a range of modern digital systems. Participants successfully demonstrated exploits targeting virtual machines, artificial intelligence platforms, web browsers, servers, containers, and operating systems. The event, designed to uncover critical security flaws before they can […]

Russia SpyPress Malware Hacks Webmail to Track Ukraine

A newly identified malware strain linked to Russian threat actors is exploiting webmail platforms to conduct surveillance operations targeting Ukraine, according to cybersecurity researchers. Dubbed “SpyPress,” the malware enables attackers to intercept communications, exfiltrate sensitive data, and monitor victims’ online activity through compromised email accounts. The campaign underscores the continued use of sophisticated cyber-espionage tactics […]