loader image
Quasar RAT Spread by Bat Files in Stealth Malware Push

Cybersecurity analysts have uncovered a new campaign in which threat actors are using Windows batch files to deploy the Quasar RAT, a known remote access Trojan. The attack begins with a deceptive batch file that appears benign but covertly initiates the download and execution of malicious payloads, marking a notable shift in malware delivery tactics. […]

Washington Post Email Hack Tied to Foreign Spy Effort

A cyberattack has compromised the email system of The Washington Post, exposing the accounts of several journalists. The incident, referred to by cybersecurity analysts as the Washington Post Email Hack, is believed to have been carried out by a foreign government, though the source has not been publicly confirmed. The breach targeted internal communications, raising […]

M&S, Co-op Cyberattacks May Cost Up to £440 Million

The recent cyberattacks on Marks & Spencer and Co-op may cost the UK retail sector up to £440 million, according to the Cyber Monitoring Centre. The agency classified the M&S Co-op cyberattacks as a Category 2 systemic event, citing their financial severity and disruption to business operations and supply chains. Hackers from the DragonForce group […]

GitHub Fixes Flaw Letting Hackers Execute Code Remotely

GitHub has addressed a high-severity vulnerability in its Enterprise Server software that could have enabled remote attackers to execute arbitrary code. The flaw posed a significant risk to organizations relying on the platform for code collaboration and deployment. GitHub fixes flaw naturally by releasing a security patch to mitigate the issue and protect its enterprise […]

Fake Recruiters Use NetBird to Target CFOs Globally

A new spear-phishing campaign is targeting Chief Financial Officers and financial executives across six global regions, cybersecurity researchers have warned. The operation, which spans Europe, Africa, Canada, the Middle East, and South Asia, leverages fake recruiter emails to lure victims into downloading a legitimate remote access tool called NetBird. The attackers appear to be executing […]

KiranaPro Cloud Wiped in Attack, CEO Promises Action

KiranaPro, an Indian e-commerce platform that digitizes operations for local convenience stores, suffered a significant cyberattack that led to the deletion of its cloud-based resources. The company’s CEO described the incident as a “deliberate attack” and pledged to identify and expose the perpetrator behind the disruption. The platform, which enables small retailers to manage inventory […]

Malware Hits npm, PyPI in Global Supply Chain Attack

A new supply chain malware campaign is targeting the npm and PyPI open-source ecosystems, compromising over a dozen packages linked to GlueStack, according to cybersecurity researchers. The attack, disclosed by Aikido Security, involves a malicious modification to the ‘lib/commonjs/index.js’ file within these packages. The alteration enables attackers to execute shell commands, capture screenshots, and upload […]

Ukrainian Police Nab Hacker in Crypto Mining Bust

Ukrainian authorities have arrested a hacker accused of hijacking a hosting provider’s servers to illegally mine cryptocurrency, police said. The suspect, a resident of Poltava in central Ukraine, had allegedly been engaging in cyberattacks since at least 2018. According to law enforcement, the individual exploited access to server infrastructure to install unauthorized mining software, diverting […]

Microsoft Launches EU-Wide Cybersecurity Offensive

Microsoft launched a new European Security Programme designed to enhance cybersecurity resilience across the European Union and neighboring regions, as digital threats continue to grow, according to a report by *Computer Weekly*. The initiative will cover all 27 EU member states, candidate countries seeking EU accession, the United Kingdom, and several bordering nations. The program […]

Firefox Fixes Flaws That Risk Crashes, Code Execution

Mozilla patched two high-impact vulnerabilities in Firefox 139.0.4 that could lead to browser crashes or remote code execution. The flaws—CVE-2025-49709 and CVE-2025-49710—affect key components of the browser’s graphics rendering system and JavaScript engine. The first, CVE-2025-49709, involves memory corruption triggered by specific canvas operations. Improper handling of canvas surfaces could compromise memory integrity, enabling denial-of-service […]

Amazon CSO Warns AI Era Exposes Human Weakness

Amazon CSO Warns AI Era naturally shifts the cybersecurity landscape toward human vulnerabilities, not just software flaws. In a recent conversation on the Click Here podcast, Steve Schmidt revealed how Amazon’s digital honeypot, dubbed MadPot, played a key role in uncovering the activities of Volt Typhoon, a state-backed cyber threat group. The tool lured attackers […]

Citrix Zero-Day Flaw Hit as Hackers Exploit NetScaler

Citrix has disclosed a critical vulnerability affecting its NetScaler ADC and NetScaler Gateway products, warning users that the flaw is actively being exploited in the wild. The Citrix Zero Day Flaw, which surfaced just nine days after the company identified two separate defects in the same systems, poses a significant security risk to enterprise users […]