Cybersecurity

RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features

Mar 30, 2025Ravie LakshmananVulnerability / Zero-Day The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has shed light on a new malware called RESURGE that has...

Stealing user credentials with evilginx – Sophos News

Evilginx, a tool based on the legitimate (and widely used) open-source nginx web server, can be used to steal usernames, passwords, and session tokens,...

Operation ForumTroll exploits zero-days in Google Chrome

In mid-March 2025, Kaspersky technologies detected a wave of infections by previously unknown and highly sophisticated malware. In all cases, infection occurred immediately after...

Sitecore “thumbnailsaccesstoken” Deserialization Scans (and some new reports) CVE-2025-27218

On March 6th, Searchlight Cyber published a blog revealing details about a new deserialization vulnerability in Sitecore . Sitecore calls itself a "Digital Experience...

I, for one, welcome our new robot overlords! • Graham Cluley

In episode 43 of The AI Fix, our hosts discover a robot that isn’t terrifying, a...

Kill List – Darknet Diaries

Full Transcript The dark web is full of mystery. Some of it’s just made up though. Chris Monteiro wanted to see...

Katharine Hayhoe: The most important climate equation

The atmospheric scientist makes a compelling case for a head-to-heart-to-hands connection as...

Weekly Update 444

It's time to fly! 🇬🇧 🇮🇸 🇮🇪 That's two new flags (or if you're on Windows and can't see flag emojis, that's two new...

The future of MFA is clear – but is it here yet? – Sophos News

Over the years the industry has tied itself in knots in its attempts at augmenting (or upgrading) the password, using all sorts of confusing...

UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

Mar 21, 2025Ravie LakshmananThreat Hunting / Vulnerability Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities in...

New Arcane stealer spreading via YouTube and Discord

At the end of 2024, we discovered a new stealer distributed via YouTube videos promoting game cheats. What’s intriguing about this malware is how...

Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 and CVE-2024-20440

In September, Cisco published an advisory noting two vulnerabilities : CVE-2024-20439: Cisco Smart Licensing Utility Static Credential Vulnerability CVE-2024-20440: Cisco Smart Licensing Utility Information Disclosure Vulnerability These...

Recent articles