loader image
Malicious NPM Code Hides via Unicode, Google Calendar

A malicious package published to the Node Package Manager (NPM) repository has been found using Unicode-based steganography to conceal its true functionality, evading detection by traditional security tools. The package hides harmful code by embedding invisible Unicode characters within its script, a technique that obscures malicious instructions from both human reviewers and automated scanners. In […]

Hackers Win $1 Million Cracking AI, OS at Pwn2Own Berlin

Hackers earned over $1 million in cash prizes during the Pwn2Own Berlin 2025 competition, where cybersecurity researchers showcased high-impact vulnerabilities across a range of modern digital systems. Participants successfully demonstrated exploits targeting virtual machines, artificial intelligence platforms, web browsers, servers, containers, and operating systems. The event, designed to uncover critical security flaws before they can […]

Russia SpyPress Malware Hacks Webmail to Track Ukraine

A newly identified malware strain linked to Russian threat actors is exploiting webmail platforms to conduct surveillance operations targeting Ukraine, according to cybersecurity researchers. Dubbed “SpyPress,” the malware enables attackers to intercept communications, exfiltrate sensitive data, and monitor victims’ online activity through compromised email accounts. The campaign underscores the continued use of sophisticated cyber-espionage tactics […]

Nova Scotia Power Hit by Ransomware, Data Exposed

Nova Scotia Power has confirmed that a recent cybersecurity incident was the result of a ransomware attack, acknowledging the breach after weeks of investigation. The utility company, which provides electricity across the Canadian province, stated that while its systems were compromised, it has not paid any ransom to the attackers. As part of the fallout […]

Russian State Services Crippled in Cyberattack Wave

Several major Russian government services experienced widespread disruptions, with indications pointing to a cyberattack as the potential cause. Internet monitoring platforms detected outages affecting the country’s tax service and Saby, a platform used for managing secure digital keys and official documents. The disruptions, which began earlier this week, appear to be ongoing, according to technical […]

Ivanti RCE Attacks Spread to Cloud as Hacks Surge

Ivanti is facing continued scrutiny as remote code execution (RCE) attacks targeting its software remain active, with recent exploitation efforts extending into cloud environments. The vulnerabilities appear to stem from insecure code within Ivanti’s security suite, raising concerns over the reliability of tools designed to protect enterprise systems. The ongoing nature of the attacks suggests […]

Vietnam Hackers Bait AI Tool Fans With Stealth Malware

A threat group based in Vietnam is deploying deceptive online campaigns that exploit the growing interest in artificial intelligence video-generation tools, according to cybersecurity firm Mandiant. The group has launched thousands of ads, fake websites and social media posts that falsely promise access to popular prompt-to-video AI services. Instead of delivering the advertised tools, the […]

Phishing Kits Go Retail as Cybercrime Turns Subscription

Cybercriminals are increasingly adopting a subscription-based model known as Phishing-as-a-Service (PhaaS), lowering the barrier to entry for launching sophisticated phishing attacks. Mirroring legitimate SaaS platforms, PhaaS kits—often sold on the dark web—offer pre-built templates, spoofed email tools, credential-harvesting sites, and real-time dashboards for tracking campaign success. These services enable even novice attackers to mimic trusted […]

Google Patches 34 Critical Flaws in Android Update

Google has released its June 2025 Android security update, addressing 34 high-severity vulnerabilities across the platform. According to the company, the most critical flaw impacts the Android system and could allow attackers to locally escalate privileges on affected devices. The update targets multiple components, aiming to mitigate risks that could compromise user data and device […]

Android Malware Loaders Defeat Google’s New Defenses

Cybercriminals are successfully bypassing Android 13’s security improvements by leveraging malware loaders to exploit accessibility services, according to new threat intelligence from Intel471. Google introduced the restrictions to block sideloaded apps from gaining accessibility access—often abused by banking trojans—but attackers have adapted using session-based package installers to evade these controls. One such loader, TiramisuDropper, has […]

FBI Seizes 145 Domains Tied to BidenCash Fraud Hub

U.S. federal authorities have seized 145 internet domains linked to BidenCash, a cybercrime platform accused of trafficking stolen financial data, according to the Justice Department. The illicit marketplace, active since at least March 2022, reportedly served over 117,000 customers and facilitated the sale of more than 15 million compromised credit card numbers. The domain seizure […]

Anubis RaaS Adds Wiper Tool to Permanently Erase Data

A newly emerged ransomware-as-a-service offering known as Anubis RaaS adds wiper functionality, making attacks more destructive by permanently deleting victim data. Active since December 2024, the ransomware encrypts files and—if its “wipe mode” is enabled—erases contents irreversibly, leaving behind empty 0 KB files. The malware campaign has targeted organizations across sectors such as healthcare and […]