Latest Articles

North Korea-linked APT abuses Google Find Hub for device wiping and spying

North Korea-linked APT abuses Google Find Hub for device wiping and spying

A state-sponsored threat actor affiliated with APT37 (and the KONNI activity cluster) has been observed abusing Google Find Hub to geolocate Android devices and perform remote wipes after credential...

Attack on Polish Loan Platform SuperGrosz Data Breach

Attack on Polish Loan Platform SuperGrosz Data Breach

SuperGrosz, a Poland-based online loan platform run by AIQLABS, disclosed a major security incident that exposed sensitive personal and financial data for thousands of customers. National authorities...

Gladinet Triofox Unauthenticated RCE CVE-2025-12480: Active Exploitation and Immediate Response

Gladinet Triofox Unauthenticated RCE CVE-2025-12480: Active Exploitation and Immediate Response

Summary: A critical improper access control vulnerability in Gladinet Triofox, tracked as CVE-2025-12480, has been exploited in the wild to bypass authentication, upload arbitrary payloads, and...

Microsoft patches Windows Kernel zero-day CVE-2025-62215

Microsoft patches Windows Kernel zero-day CVE-2025-62215

Microsoft’s November security update closes a locally exploitable Windows Kernel elevation of privilege vulnerability that was observed in the wild. Administrators must prioritize deployment to...

Bulwark Malware Exposed: Analysis, IoCs, and Tactical Guidance for Defenders

Bulwark Malware Exposed: Analysis, IoCs, and Tactical Guidance for Defenders

Bulwark is a commercialized evasion packer and toolkit first observed in 2025. It is sold to operators to hide Windows payloads from endpoint detection platforms by transforming binaries at runtime,...

US Treasury Department Hacked by Chinese Actors

US Treasury Department Hacked by Chinese Actors

A sophisticated intrusion through a third-party contractor compromised employee systems and unclassified documents, marking a major escalation in nation-state cyber operations. ...

APT37 Exploits Google Find Hub in Android Data-Wiping Attacks Against South Korean Targets

APT37 Exploits Google Find Hub in Android Data-Wiping Attacks Against South Korean Targets

Date: November 10, 2025 Overview: A newly identified campaign attributed to the North Korean threat actor APT37 (also known as “ScarCruft”) has been found abusing Google’s Find Hub service for...

KnownSec Data Breach Exposes Offensive Cyber Tools and Global Target Lists

KnownSec Data Breach Exposes Offensive Cyber Tools and Global Target Lists

Chinese cybersecurity firm KnownSec Information Technology Co., Ltd. has suffered a major data breach that resulted in the leak of thousands of internal files. The exposed data reportedly includes...

Insider Data Theft at Intel Exposes Major Gaps in Corporate Security

Insider Data Theft at Intel Exposes Major Gaps in Corporate Security

Intel Corporation has disclosed an insider data theft involving a former software engineer accused of stealing approximately 18,000 confidential and proprietary files before leaving the company. The...

ENEA Data Breach: Source Code Leak from Swedish Telecom Software Firm

ENEA Data Breach: Source Code Leak from Swedish Telecom Software Firm

Critical Exposure of Proprietary Telecom Infrastructure Code Published on November 10, 2025 In a significant cybersecurity...

Qilin Ransomware Attacks on U.S. Organizations

Qilin Ransomware Attacks on U.S. Organizations

A coordinated wave of cyberattacks disrupts manufacturing, legal, and HR sectors Published: November 9, 2025 In a troubling escalation of cyber threats, the...

Strengthening Email Security Against Emerging Phishing-as-a-Service Operations

Strengthening Email Security Against Emerging Phishing-as-a-Service Operations

Phishing-as-a-Service, or PhaaS, has evolved into a mature criminal economy. Platforms now offer complete phishing kits, automation tools, and even customer support for attackers with minimal...

Samsung Zero-Click WhatsApp Spyware Hits Galaxy Devices - Zero-Day (CVE-2025-21042) Exploited by “LANDFALL” Campaign

Samsung Zero-Click WhatsApp Spyware Hits Galaxy Devices - Zero-Day (CVE-2025-21042) Exploited by “LANDFALL” Campaign

Date: November 9, 2025 Overview: Security researchers have disclosed a widespread targeted spyware operation — dubbed “LANDFALL” — that exploited a zero-day vulnerability in a Samsung...

High Alert: CERT-In Urges Immediate Android Patching for Critical Zero-Click Flaw

High Alert: CERT-In Urges Immediate Android Patching for Critical Zero-Click Flaw

The cybersecurity community is on high alert following a critical advisory issued by the Indian Computer Emergency Response Team (CERT-In). The national cyber defense agency has urged millions of...

 University of Pennsylvania (UPenn) Data Breach

University of Pennsylvania (UPenn) Data Breach

University of Pennsylvania Data Breach: A Major Cybersecurity Wake-Up Call body { font-family: Arial, sans-serif; line-height: 1.6; margin: 0; ...

U.S. Congressional Budget Office Confirms Cyber Attack Affecting Internal Systems

U.S. Congressional Budget Office Confirms Cyber Attack Affecting Internal Systems

The U.S. Congressional Budget Office confirmed it was the victim of a cyber attack that disrupted internal communications and certain data systems. The agency, which provides nonpartisan economic and...

Washington Post Confirms Impact From Oracle E-Business Suite Breach

Washington Post Confirms Impact From Oracle E-Business Suite Breach

The Washington Post said it was affected by a cyber incident linked to Oracle E-Business Suite. The disclosure followed external reporting and listings on an extortion site that named multiple...

Google Releases Emergency Chrome Update

Google Releases Emergency Chrome Update

Five High-Severity Vulnerabilities Patched – Immediate Update Required Published: November 7, 2025 ⚠️ Action Required: All Chrome users on Windows, macOS, Linux, Android,...

Hyundai AutoEver America Data Exposure

Hyundai AutoEver America Data Exposure

November 6, 2025 In a troubling escalation of cybersecurity threats facing the automotive sector, Hyundai AutoEver America (HAEA), a key IT subsidiary of the Hyundai Motor...

PROMPTFLUX: Google Uncovers First AI Malware That Rewrites Its Code Hourly Using Gemini

PROMPTFLUX: Google Uncovers First AI Malware That Rewrites Its Code Hourly Using Gemini

The cybersecurity landscape has been fundamentally altered following a startling new discovery by the Google Threat Intelligence Group (GTIG). In a recent report, Google unveiled an...