Category: Cyber News


  • Cisco VPNs, Email Services Hit in Separate Threat Campaigns

    The company suffered one sophisticated five-alarm campaign and one messy spray-and-pray attack, mere days apart. ​ ​ ​Read More

  • Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers

    A suspected Russia-aligned group has been attributed to a phishing campaign that employs device code authentication workflows to steal victims’ Microsoft 365 credentials and conduct account takeover attacks. The activity, ongoing since September 2025, is being tracked by Proofpoint under the moniker UNK_AcademicFlare. The attacks involve using compromised email addresses belonging to government ​ ​…

  • LongNosedGoblin Caught Snooping on Asian Governments

    New China-aligned APT group is deploying Group Policy to sniff through government networks across Southeast Asia and Japan. ​ ​ ​Read More

  • Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

    Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as CountLoader. The campaign “uses CountLoader as the initial tool in a multistage attack for access, evasion, and delivery of additional malware families,” Cyderes…

  • The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and corruption. These shifts, along with the president’s efforts to restrict free speech and freedom of…

  • SonicWall Edge Access Devices Hit by Zero-Day Attacks

    In the latest attacks against the vendor’s SMA1000 devices, threat actors have chained a new zero-day flaw with a critical vulnerability disclosed earlier this year. ​ ​ ​Read More

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware

    A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan. The end goal of these attacks is cyber espionage, Slovak cybersecurity company ESET said in a report published today. The threat activity cluster has been assessed to be active since…

  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

    Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution. The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all systems via a…

  • ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

    This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s activity shows just how fluid the threat…

  • North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

    Threat actors with ties to the Democratic People’s Republic of Korea (DPRK or North Korea) have been instrumental in driving a surge in global cryptocurrency theft in 2025, accounting for at least $2.02 billion out of more than $3.4 billion stolen from January through early December. The figure represents a 51% increase year-over-year and $681…