Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

  • Home
  • Toolkit
  • About
  • Services
  • Cybersecurity News
  • Contact
  • Facebook
  • X
  • LinkedIn
  • Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories

    Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories

    September 12, 2025
    Cyber News

    A security weakness has been disclosed in the artificial intelligence (AI)-powered code editor Cursor that could trigger code execution when a maliciously crafted repository is opened using the program. The issue stems from the fact that an out-of-the-box security setting is disabled by default, opening the door for attackers to run arbitrary code on users’…

  • Vyro AI Leak Reveals Poor Cyber Hygiene

    Vyro AI Leak Reveals Poor Cyber Hygiene

    September 11, 2025
    Cyber News

    The data leak underscores the larger issue of proprietary or sensitive data being shared with GenAI by users who should know better. ​ ​ ​Read More

  • ‘Gentlemen’ Ransomware Abuses Vulnerable Driver to Kill Security Gear

    ‘Gentlemen’ Ransomware Abuses Vulnerable Driver to Kill Security Gear

    September 11, 2025
    Cyber News

    By weaponizing the ThrottleStop.sys driver, attackers are disrupting antivirus and endpoint detection and response (EDR) systems. ​ ​ ​Read More

  • Apple CarPlay RCE Exploit Left Unaddressed in Most Cars

    Apple CarPlay RCE Exploit Left Unaddressed in Most Cars

    September 11, 2025
    Cyber News

    Even when a vulnerability is serious and a fix is available, actually securing cars is more difficult than one would hope. ​ ​ ​Read More

  • AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

    AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

    September 11, 2025
    Cyber News

    Cybersecurity researchers have disclosed details of a new campaign that leverages ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deliver a fleshless loader that drops a remote access trojan (RAT) called AsyncRAT to steal sensitive data from compromised hosts. “The attacker used ScreenConnect to gain remote access, then executed a layered VBScript…

  • Students Pose Inside Threat to Education Sector

    Students Pose Inside Threat to Education Sector

    September 10, 2025
    Cyber News

    The threats may not be malicious, but they are more than many security teams can handle. ​ ​ ​Read More

  • Chinese Hackers Allegedly Pose as US Lawmaker

    Chinese Hackers Allegedly Pose as US Lawmaker

    September 10, 2025
    Cyber News

    Chinese state-backed threat actors are suspected of posing as Michigan congressman John Moolenaar in a series of spear-phishing attacks. ​ ​ ​Read More

  • Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems

    Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems

    September 10, 2025
    Cyber News

    An advanced persistent threat (APT) group from China has been attributed to the compromise of a Philippines-based military company using a previously undocumented fileless malware framework called EggStreme. “This multi-stage toolset achieves persistent, low-profile espionage by injecting malicious code directly into memory and leveraging DLL sideloading to execute payloads,” Bitdefender ​ ​ ​Read More

  • Notes of cyber inspector: three clusters of threat in cyberspace

    Notes of cyber inspector: three clusters of threat in cyberspace

    September 10, 2025
    Cyber News

    Hacktivism and geopolitically motivated APT groups have become a significant threat to many regions of the world in recent years, damaging infrastructure and important functions of government, business, and society. In late 2022 we predicted that the involvement of hacktivist groups in all major geopolitical conflicts from now on will only increase and this is…

  • Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises

    Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises

    September 10, 2025
    Cyber News

    Phishing-as-a-Service (PhaaS) platforms keep evolving, giving attackers faster and cheaper ways to break into corporate accounts. Now, researchers at ANY.RUN has uncovered a new entrant: Salty2FA, a phishing kit designed to bypass multiple two-factor authentication methods and slip past traditional defenses.  Already spotted in campaigns across the US and EU, Salty2FA puts enterprises at ​…

Previous Page
1 … 19 20 21 22 23 … 28
Next Page
Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Privacy Policy

  • Facebook
  • X
  • LinkedIn