Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

  • Home
  • Toolkit
  • About
  • Services
  • Cybersecurity News
  • Contact
  • Facebook
  • X
  • LinkedIn
  • Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies

    Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies

    July 31, 2025
    Cyber News

    The Russian nation-state threat actor known as Secret Blizzard has been observed orchestrating a new cyber espionage campaign targeting foreign embassies located in Moscow by means of an adversary-in-the-middle (AitM) attack at the Internet Service Provider (ISP) level and delivering a custom malware dubbed ApolloShadow. “ApolloShadow has the capability to install a trusted root certificate…

  • 3 Things CFOs Need to Know About Mitigating Threats

    3 Things CFOs Need to Know About Mitigating Threats

    July 31, 2025
    Cyber News

    To reposition cybersecurity as a strategic, business-critical investment, CFOs and CISOs play a critical role in articulating the significant ROI that robust security measures can deliver. ​ ​ ​Read More

  • Nimble ‘Gunra’ Ransomware Evolves With Linux Variant

    Nimble ‘Gunra’ Ransomware Evolves With Linux Variant

    July 29, 2025
    Cyber News

    The emerging cybercriminal gang, which initially targeted Microsoft Windows systems, is looking to go cross-platform using sophisticated, multithread encryption. ​ ​ ​Read More

  • Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

    Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

    July 29, 2025
    Cyber News

    Cybersecurity researchers have disclosed a now-patched critical security flaw in a popular vibe coding platform called Base44 that could allow unauthorized access to private applications built by its users. “The vulnerability we discovered was remarkably simple to exploit — by providing only a non-secret app_id value to undocumented registration and email verification endpoints, an attacker…

  • PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

    PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

    July 29, 2025
    Cyber News

    The maintainers of the Python Package Index (PyPI) repository have issued a warning about an ongoing phishing attack that’s targeting users in an attempt to redirect them to fake PyPI sites. The attack involves sending email messages bearing the subject line “[PyPI] Email verification” that are sent from the email address noreply@pypj[.]org (note that the…

  • The Hidden Threat of Rogue Access

    The Hidden Threat of Rogue Access

    July 29, 2025
    Cyber News

    With the right IGA tools, governance policies, and risk thresholds, enterprises can continuously detect and act on rogue access before attackers do. ​ ​ ​Read More

  • Critical Flaw in Vibe-Coding Platform Base44 Exposes Apps

    Critical Flaw in Vibe-Coding Platform Base44 Exposes Apps

    July 29, 2025
    Cyber News

    A now-patched authentication issue on the popular vibe-coding platform gave unauthorized users open access to any private application on Base44. ​ ​ ​Read More

  • Insurance Giant Allianz Life Grapples With Breach Affecting ‘Majority’ of Customers

    Insurance Giant Allianz Life Grapples With Breach Affecting ‘Majority’ of Customers

    July 28, 2025
    Cyber News

    The company has yet to report an exact number of how many individuals were impacted by the breach and plans to start the notification process around Aug. 1. ​ ​ ​Read More

  • Chaos Ransomware Rises as BlackSuit Gang Falls

    Chaos Ransomware Rises as BlackSuit Gang Falls

    July 28, 2025
    Cyber News

    Researchers detailed a newer double-extortion ransomware group made up of former members of BlackSuit, which was recently disrupted by international law enforcement. ​ ​ ​Read More

  • Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads

    Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads

    July 28, 2025
    Cyber News

    In what’s the latest instance of a software supply chain attack, unknown threat actors managed to compromise Toptal’s GitHub organization account and leveraged that access to publish 10 malicious packages to the npm registry. The packages contained code to exfiltrate GitHub authentication tokens and destroy victim systems, Socket said in a report published last week.…

Previous Page
1 2 3 4
Next Page
Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Privacy Policy

  • Facebook
  • X
  • LinkedIn