Monday, June 9, 2025

THREATS

Hackers Leverage New ClickFix Tactic to Exploit Human Error with Deceptive Prompts

A sophisticated social engineering technique known as ClickFix baiting has gained traction among cybercriminals, ranging from individual hackers to state-sponsored Advanced Persistent Threat (APT) groups like Russia-linked APT28 and...

Hundreds of Malicious GitHub Repos Targeting Novice Cybercriminals Traced to Single User

Sophos X-Ops researchers have identified over 140 GitHub repositories laced with malicious backdoors, orchestrated by a single threat actor associated with the email address...

ViperSoftX Malware Used by Threat Actors to Steal Sensitive Information

The AhnLab Security Intelligence Center (ASEC) has recently issued a detailed report confirming the persistent distribution of ViperSoftX malware by threat actors, with notable...

Paste.ee Turned Cyber Weapon: XWorm and AsyncRAT Delivered by Malicious Actors

The widespread text-sharing website Paste.ee has been used as a weapon by bad actors to spread powerful malware strains like XWorm and AsyncRAT, which...

Threat Actors Exploit Malware Loaders to Circumvent Android 13+ Accessibility Safeguards

Threat actors have successfully adapted to Google’s stringent accessibility restrictions introduced in Android 13 and later versions. These safeguards, rolled out in May 2022, were...

SCATTERED SPIDER Hackers Target IT Support Teams & Bypass Multi-Factor Authentication

A cybercriminal group known as SCATTERED SPIDER has emerged as a formidable threat, targeting sectors like hospitality, telecommunications, finance, and retail with unprecedented sophistication. This...

Lumma Infostealer Developers Persist in Their Malicious Activities

A coordinated operation by Europol, the FBI, Microsoft, and other public and private sector partners targeted the Lumma infostealer, a prolific malware distributed via...

Threat Actors Abuse ‘Prove You Are Human’ System to Distribute Malware

Threat actors have been found exploiting the ubiquitous "Prove You Are Human" verification systems to distribute malicious software. Specifically, this campaign leverages spoofed websites mimicking...

Russian Hacker Black Owl Targets Critical Industries to Steal Financial Data

A pro-Ukrainian hacktivist group known as BO Team, also operating under aliases such as Black Owl, Lifting Zmiy, and Hoody Hyena, has emerged as...

North Face Fashion Brand Alerts Customers to Credential Stuffing Attack

The North Face, a prominent outdoor fashion brand under VF Outdoor, LLC, detected unusual activity on its website, thenorthface.com. Following a swift and thorough...

New Report: Governments Struggle to Regain Backdoor Access to Secure Communications

A crucial point has been reached in the conflict between personal privacy and governmental monitoring in a time when digital communication is essential. Governments worldwide...