In a recent study, cybersecurity firm SquareX has identified a novel attack vector targeting AI-integrated web browsers. Dubbed the AI Sidebar Spoofing Attack, this method […]
Year: 2025
Bitter APT Exploits WinRAR Zero-Day to Deploy C# Backdoors via Weaponized Documents
The Bitter Advanced Persistent Threat (APT) group, also identified as APT-Q-37 and known in China as 蔓灵花, has initiated a sophisticated cyberespionage campaign targeting government […]
Cybercriminals Exploit Microsoft 365’s Direct Send Feature to Evade Security Measures
Microsoft 365’s Exchange Online includes a feature known as Direct Send, originally designed to facilitate email transmission from legacy devices and applications without the need […]
SharkStealer: Leveraging Blockchain for Covert Command-and-Control Channels
In the ever-evolving landscape of cybersecurity threats, a new malware strain named SharkStealer has surfaced, showcasing a sophisticated blend of programming and blockchain technology to […]
Threat Actors Exploit Azure Blob Storage to Breach Organizational Repositories
Cybersecurity experts have uncovered a sophisticated campaign where malicious actors are exploiting compromised credentials to infiltrate Azure Blob Storage containers. This strategy targets organizations’ critical […]
Introducing PDF Object Hashing: A New Tool to Detect Malicious PDFs
In the ever-evolving landscape of cybersecurity, malicious actors continually adapt their methods to exploit common file formats, with Portable Document Format (PDF) files being a […]
HP OneAgent Update Causes Entra ID Disconnection and Trust Issues
A recent update to HP’s OneAgent software has led to significant disruptions for users, particularly those utilizing Windows devices integrated with Microsoft Entra ID. The […]
Emerging Fileless Remcos Attacks Evade EDRs by Injecting Malicious Code into RMClient
In the third quarter of 2025, Remcos, a commercial remote access tool (RAT) originally designed for legitimate surveillance purposes, has emerged as the predominant infostealer […]
Toys R Us Canada Data Breach Exposes Customer Information
Toys R Us Canada has recently informed its customers of a significant data breach that has compromised personal information, raising concerns about data security in […]
Microsoft Releases Emergency Patch for Critical WSUS Remote Code Execution Vulnerability
Microsoft has issued an urgent out-of-band security update to address a critical remote code execution (RCE) vulnerability in Windows Server Update Services (WSUS). This flaw, […]