In mid-October 2025, cybersecurity experts identified a new and sophisticated banking Trojan named Maverick, which has been actively targeting Brazilian users. This malware leverages WhatsApp, […]
Year: 2025
Critical Vulnerabilities in Windows BitLocker Expose Encrypted Data to Physical Attacks
Microsoft has recently disclosed two significant vulnerabilities in its Windows BitLocker encryption feature, identified as CVE-2025-55338 and CVE-2025-55333. These flaws enable attackers with physical access […]
Critical Zero-Day Vulnerability in Adobe Experience Manager Forms Exploited in Active Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert concerning a critical vulnerability in Adobe Experience Manager (AEM) Forms, identified as CVE-2025-54253. […]
Critical Samba RCE Vulnerability Enables Arbitrary Code Execution
Samba, the widely-used open-source implementation of the SMB/CIFS networking protocol, has disclosed a critical remote code execution (RCE) vulnerability identified as CVE-2025-10230. This flaw poses […]
Critical Apache ActiveMQ Vulnerability Enables Remote Code Execution
The Apache Software Foundation has disclosed a critical vulnerability in its ActiveMQ NMS AMQP Client, identified as CVE-2025-54539, which could allow attackers to execute arbitrary […]
Introducing nightMARE: A Comprehensive Python Library for Malware Analysis and Threat Intelligence
In October 2025, Elastic Security Labs unveiled nightMARE version 0.16, a robust Python library designed to enhance malware analysis and reverse engineering processes. This open-source […]
Capita Fined £14 Million for Data Breach Affecting 6.6 Million Individuals
In a landmark decision, the UK’s Information Commissioner’s Office (ICO) has levied a £14 million fine against outsourcing giant Capita for a significant data breach […]
Beware of Malicious Ivanti VPN Client Sites in Google Search That Deliver Malware
In early October 2025, cybersecurity researchers identified a sophisticated search engine optimization (SEO) poisoning campaign targeting individuals seeking the legitimate Ivanti Pulse Secure VPN client. […]
CISA Alerts on Active Exploitation of Windows Access Control Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical Microsoft Windows vulnerability, identified as CVE-2025-59230, to its Known Exploited Vulnerabilities catalog. This […]
PhantomVAI Loader: A Global Cyber Threat Deploying Multiple Infostealers
A sophisticated multi-stage malware campaign is currently targeting organizations worldwide, utilizing the PhantomVAI Loader to distribute various information-stealing malware. This campaign poses a significant threat […]