Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

  • Home
  • Toolkit
  • About
  • Services
  • Cybersecurity News
  • Contact
  • Facebook
  • X
  • LinkedIn
  • Can a Global, Decentralized System Save CVE Data?

    Can a Global, Decentralized System Save CVE Data?

    November 18, 2025
    Cyber News

    As vulnerabilities in the Common Vulnerabilities and Exposures ecosystem pile up, one Black Hat Europe presenter hopes for a global, distributed alternative. ​ ​ ​Read More

  • Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

    Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar

    November 18, 2025
    Cyber News

    The malware authors associated with a Phishing-as-a-Service (PhaaS) kit known as Sneaky 2FA have incorporated Browser-in-the-Browser (BitB) functionality into their arsenal, underscoring the continued evolution of such offerings and further making it easier for less-skilled threat actors to mount attacks at scale. Push Security, in a report shared with The Hacker News, said it observed…

  • Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam

    Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam

    November 18, 2025
    Cyber News

    A malware campaign presents fake websites that can check if a visitor is a potential victim or a security researcher, and then proceed accordingly to defraud or evade. ​ ​ ​Read More

  • Bug Bounty Programs Rise as Key Strategic Security Solutions

    Bug Bounty Programs Rise as Key Strategic Security Solutions

    November 18, 2025
    Cyber News

    Bug bounty programs create formal channels for organizations to leverage external security expertise, offering researchers legal protection and financial incentives for ethical vulnerability disclosure. ​ ​ ​Read More

  • Critical Fortinet FortiWeb WAF Bug Exploited in the Wild

    Critical Fortinet FortiWeb WAF Bug Exploited in the Wild

    November 17, 2025
    Cyber News

    The vulnerability could allow an unauthenticated attacker to remotely execute administrative commands. ​ ​ ​Read More

  • New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

    New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

    November 17, 2025
    Cyber News

    Cybersecurity researchers have discovered malware campaigns using the now-prevalent ClickFix social engineering tactic to deploy Amatera Stealer and NetSupport RAT. The activity, observed this month, is being tracked by eSentire under the moniker EVALUSION. First spotted in June 2025, Amatera is assessed to be an evolution of ACR (short for “AcridRain”) Stealer, which was available…

  • Cursor Issue Paves Way for Credential-Stealing Attacks

    Cursor Issue Paves Way for Credential-Stealing Attacks

    November 17, 2025
    Cyber News

    Researchers discovered a security weakness in the AI-powered coding tool that allows malicious MCP server to hijack Cursor’s internal browser. ​ ​ ​Read More

  • ⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

    ⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

    November 17, 2025
    Cyber News

    This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. Criminals are building systems to make money,…

  • RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

    RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

    November 15, 2025
    Cyber News

    The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request…

  • Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies

    Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies

    November 15, 2025
    Cyber News

    The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28,…

Previous Page
1 … 10 11 12 13 14 … 45
Next Page
Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Privacy Policy

  • Facebook
  • X
  • LinkedIn