Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

  • Home
  • Toolkit
  • About
  • Services
  • Cybersecurity News
  • Contact
  • Facebook
  • X
  • LinkedIn
  • Southeast Asian Scam Centers Face More Financial Sanctions

    Southeast Asian Scam Centers Face More Financial Sanctions

    September 10, 2025
    Cyber News

    Firms cooperating with cybercrime syndicates in Burma and Cambodia face sanctions by the US government and enforcement actions by China, but the scams continue to grow. ​ ​ ​Read More

  • Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

    Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

    September 10, 2025
    Cyber News

    Adobe has warned of a critical security flaw in its Commerce and Magento Open Source platforms that, if successfully exploited, could allow attackers to take control of customer accounts. The vulnerability, tracked as CVE-2025-54236 (aka SessionReaper), carries a CVSS score of 9.1 out of a maximum of 10.0. It has been described as an improper…

  • SAP Patches Critical NetWeaver (CVSS Up to 10.0) and High-Severity S/4HANA Flaws

    SAP Patches Critical NetWeaver (CVSS Up to 10.0) and High-Severity S/4HANA Flaws

    September 10, 2025
    Cyber News

    SAP on Tuesday released security updates to address multiple security flaws, including three critical vulnerabilities in SAP Netweaver that could result in code execution and the upload arbitrary files. The vulnerabilities are listed below – CVE-2025-42944 (CVSS score: 10.0) – A deserialization vulnerability in SAP NetWeaver that could allow an unauthenticated attacker to submit a…

  • Microsoft Patch Tuesday, September 2025 Edition

    Microsoft Patch Tuesday, September 2025 Edition

    September 9, 2025
    Cyber News

    Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known “zero-day” or actively exploited vulnerabilities in this month’s bundle from Redmond, which nevertheless includes patches for 13 flaws that earned Microsoft’s most-dire “critical” label. Meanwhile, both Apple and Google recently released updates…

  • 20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

    20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

    September 9, 2025
    Cyber News

    Multiple npm packages have been compromised as part of a software supply chain attack after a maintainer’s account was compromised in a phishing attack. The attack targeted Josh Junon (aka Qix), who received an email message that mimicked npm (“support@npmjs[.]help”), urging them to update their update their two-factor authentication (2FA) credentials before September 10, 2025,…

  • 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage

    45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage

    September 9, 2025
    Cyber News

    Threat hunters have discovered a set of previously unreported domains, some going back to May 2020, that are associated with China-linked threat actors Salt Typhoon and UNC4841. “The domains date back several years, with the oldest registration activity occurring in May 2020, further confirming that the 2024 Salt Typhoon attacks were not the first activity…

  • 18 Popular Code Packages Hacked, Rigged to Steal Crypto

    18 Popular Code Packages Hacked, Rigged to Steal Crypto

    September 8, 2025
    Cyber News

    At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved in maintaining the projects was phished. The attack appears to have been quickly contained and was narrowly focused on stealing cryptocurrency. But experts warn that a…

  • ‘MostereRAT’ Malware Blends In, Blocks Security Tools

    ‘MostereRAT’ Malware Blends In, Blocks Security Tools

    September 8, 2025
    Cyber News

    A threat actor is using a sophisticated EDR-killing malware tool in a campaign to maintain long-term, persistent access on Windows systems. ​ ​ ​Read More

  • Salesloft Breached via GitHub Account Compromise

    Salesloft Breached via GitHub Account Compromise

    September 8, 2025
    Cyber News

    The breach kickstarted a massive supply chain attack that led to the compromise of hundreds of Salesforce instances through stolen OAuth tokens. ​ ​ ​Read More

  • Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

    Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

    September 6, 2025
    Cyber News

    A threat actor possibly of Russian origin has been attributed to a new set of attacks targeting the energy sector in Kazakhstan. The activity, codenamed Operation BarrelFire, is tied to a new threat group tracked by Seqrite Labs as Noisy Bear. The threat actor has been active since at least April 2025. “The campaign is…

Previous Page
1 … 20 21 22 23 24 … 28
Next Page
Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Secure Cyber Labs | Cybersecurity Resources by DrewNet Cybersecurity

Privacy Policy

  • Facebook
  • X
  • LinkedIn