Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Meta Ads Push StreamRat Android Trojan, Exposing Users to Near-Complete Device Control A worrying trend has emerged in the world of mobile security, as a notorious malware strain is being pushed through seemingly innocuous ads on the Meta platform. The StreamRat Android Trojan has been making headlines for its ability to gain near-complete control over … Read more

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Cybersecurity Threats Take a Sophisticated Turn as BGP Hijack Allows Malicious Update of Virtualizor with Persistent Root Access A recent and disturbing incident has highlighted the continued threat posed by cyber attacks on critical infrastructure, as hackers successfully exploited a Border Gateway Protocol (BGP) hijacking to inject malicious code into the Virtualizor control panel. This … Read more

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A critical vulnerability in a popular open-source web server software has been exploited by attackers, causing a Brazilian government website to redirect visitors to malicious betting pages. The attack, which was discovered on September 1st, highlights the ongoing threat of cyber attacks against public institutions and underscores the importance of robust security measures. The compromised … Read more

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

A Silent Threat Lurks in Open-Source Code Repositories: Malicious .git Configs Can Hijack AI Agents In a disturbing trend, cybersecurity researchers have uncovered a new attack vector that leverages seemingly innocuous open-source code repositories to compromise high-profile artificial intelligence (AI) agents. The malicious tactic involves exploiting the configuration files of popular AI tools like Claude, … Read more

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

A notorious Russian hacker, extradited from Eastern Europe, is set to face charges related to a sophisticated malware campaign that exploited Microsoft Excel vulnerabilities to infect thousands of computers worldwide. The complex cyberattack, which leveraged cross-domain privilege escalation techniques, has left security experts scrambling to understand its intricacies. At the heart of this operation was … Read more

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

A critical vulnerability in GeoNetwork, a popular open-source geospatial repository system used by governments and organizations worldwide, has been patched after researchers discovered an unauthenticated remote code execution (RCE) chain. The flaw, which affects GeoNetwork versions 2022.01 and earlier, can be exploited to gain unauthorized access to sensitive data and disrupt backend systems. GeoNetwork is … Read more

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

A Critical SonicWall Vulnerability Exposes Organizations Worldwide to Active Attacks Attackers have been exploiting two zero-day vulnerabilities in SonicWall’s SMA 1000 series, a network security appliance used by thousands of organizations worldwide. The exploitation of these flaws may lead to an attack chain that compromises sensitive data and allows hackers to move laterally within the … Read more

How to Secure Enterprise AI: From Adoption to Incident Readiness

**Enterprise AI Security Crisis: Identity Exposure Exposes Vulnerable Attack Paths** Imagine your company’s cutting-edge artificial intelligence (AI) system, touted as a game-changer in efficiency and productivity, is quietly exposing itself to catastrophic cyber threats. Sounds far-fetched? Think again. A recent analysis of 11 real-world cases reveals that identity exposure has become a ticking time bomb … Read more

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

A Critical Vulnerability in Switchvox Exposes Organizations to Remote Attacks, No Credentials Required A disturbing trend has emerged as threat actors have begun exploiting a critical flaw in Switchvox, an open-source IP PBX system used by thousands of organizations worldwide. By capitalizing on this vulnerability, attackers can establish reverse shells on compromised servers without needing … Read more