A newly identified ransomware strain, NailaoLocker, has emerged as a significant threat to Windows systems, marking the first documented use of China’s SM2 cryptographic standard […]
Day: July 22, 2025
Threat Actors Hijack Popular npm Packages to Steal Project Maintainers’ Authentication Tokens
In a sophisticated supply chain attack, cybercriminals have compromised several widely-used npm packages, including `eslint-config-prettier` and `eslint-plugin-prettier`. The attackers successfully stole maintainer authentication tokens through […]
DeerStealer Malware Delivered via Weaponized .LNK Files Exploiting LOLBin Techniques
A sophisticated phishing campaign has recently been identified, deploying the DeerStealer malware through malicious .LNK shortcut files. This method exploits legitimate Windows binaries, a tactic […]
Greedy Sponge Hackers Target Mexican Financial Institutions with Enhanced AllaKore RAT
Since 2021, a cybercriminal group known as Greedy Sponge has been orchestrating targeted attacks against financial institutions in Mexico. Utilizing a significantly modified version of […]
Microsoft Releases Emergency Patches for Actively Exploited SharePoint Zero-Day Vulnerabilities
In July 2025, Microsoft identified and addressed two critical zero-day vulnerabilities in its on-premises SharePoint Server software, designated as CVE-2025-53770 and CVE-2025-53771. These vulnerabilities have […]
Louis Vuitton Faces Multiple Cybersecurity Breaches: A Comprehensive Overview
In recent months, luxury fashion house Louis Vuitton has encountered a series of significant cybersecurity incidents affecting its global operations. These breaches have compromised sensitive […]
Wireshark 4.4.8 Released: Enhancements and Bug Fixes for Improved Network Analysis
The Wireshark Foundation has announced the release of Wireshark 4.4.8, the latest maintenance update for the widely-used network protocol analyzer. This version focuses on enhancing […]
Emergence of GLOBAL GROUP: A Sophisticated Cross-Platform Ransomware Threat
In June 2025, a new ransomware entity known as GLOBAL GROUP surfaced on the Ramp4u cybercrime forum. Operated by an individual using the alias $$$, […]
Emerging Android Malware Merges Click Fraud with Credential Theft
A new strain of Android malware is combining click fraud and credential theft, posing a significant threat to users across Southeast Asia, Latin America, and […]
ExpressVPN Addresses Critical Windows Client Vulnerability Exposing User IPs During RDP Sessions
ExpressVPN, a leading provider of virtual private network (VPN) services, recently identified and addressed a significant security vulnerability within its Windows desktop application. This flaw […]