Malware & Threats

Two-Year-Old Ray AI Framework Flaw Exploited in Ongoing Campaign

Two-Year-Old Ray AI Framework Flaw Exploited in Ongoing Campaign 2025-11-19 at 15:31 By Ionut Arghire Threat actors are exploiting a two-year-old vulnerability in the Ray AI framework in a fresh campaign that hit numerous clusters, Oligo reports. Maintained by Anyscale, Ray is an open source framework for scaling Python-based AI and ML applications. Ray clusters […]

Two-Year-Old Ray AI Framework Flaw Exploited in Ongoing Campaign Read More »

Iranian Hackers Target Defense and Government Officials in Ongoing Campaign

Iranian Hackers Target Defense and Government Officials in Ongoing Campaign 2025-11-17 at 16:30 By Ionut Arghire The state-sponsored APT has been targeting the victims’ family members to increase pressure on their targets. The post Iranian Hackers Target Defense and Government Officials in Ongoing Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Iranian Hackers Target Defense and Government Officials in Ongoing Campaign Read More »

CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks

CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks 2025-11-13 at 17:14 By Ionut Arghire Federal agencies have reported as ‘patched’ ASA or FTD devices running software versions vulnerable to attacks. The post CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks appeared first on SecurityWeek. This article is an excerpt

CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks Read More »

Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm

Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm 2025-11-13 at 15:18 By Ionut Arghire The spam campaign is likely orchestrated by an Indonesian threat actor, based on code comments and the packages’ random names. The post Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm appeared first on SecurityWeek. This article is

Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm Read More »

Landfall Android Spyware Targeted Samsung Phones via Zero-Day

Landfall Android Spyware Targeted Samsung Phones via Zero-Day 2025-11-07 at 19:39 By Eduard Kovacs Threat actors exploited CVE-2025-21042 to deliver malware via specially crafted images to users in the Middle East.  The post Landfall Android Spyware Targeted Samsung Phones via Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Landfall Android Spyware Targeted Samsung Phones via Zero-Day Read More »

ClickFix Attacks Against macOS Users Evolving

ClickFix Attacks Against macOS Users Evolving 2025-11-07 at 15:41 By Eduard Kovacs ClickFix prompts typically contain instructions for Windows users, but now they are tailored for macOS and they are getting increasingly convincing. The post ClickFix Attacks Against macOS Users Evolving appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ClickFix Attacks Against macOS Users Evolving Read More »

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns 2025-11-05 at 17:25 By Eduard Kovacs Google has released a report describing the novel ways in which malware has been using AI to adapt and evade detection. The post Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns Read More »

Transportation Companies Hacked to Steal Cargo

Transportation Companies Hacked to Steal Cargo 2025-11-04 at 17:17 By Ionut Arghire Threat actors engage in elaborate attack chains to infect trucking and logistics companies with remote access tools. The post Transportation Companies Hacked to Steal Cargo appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Transportation Companies Hacked to Steal Cargo Read More »

Open VSX Downplays Impact From GlassWorm Campaign

Open VSX Downplays Impact From GlassWorm Campaign 2025-10-31 at 19:32 By Ionut Arghire Open VSX fully contained the GlassWorm attacks and says it was not a self-replicating worm in the traditional sense. The post Open VSX Downplays Impact From GlassWorm Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Open VSX Downplays Impact From GlassWorm Campaign Read More »

In Other News: WhatsApp Passkey-Encrypted Backups, Russia Targets Meduza Malware, New Mastercard Solution

In Other News: WhatsApp Passkey-Encrypted Backups, Russia Targets Meduza Malware, New Mastercard Solution 2025-10-31 at 17:18 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: several interesting Android malware families, UN cybercrime treaty, criminal complaint against Clearview AI in Europe. The post In Other News: WhatsApp Passkey-Encrypted Backups, Russia Targets Meduza

In Other News: WhatsApp Passkey-Encrypted Backups, Russia Targets Meduza Malware, New Mastercard Solution Read More »

Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks

Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks 2025-10-31 at 12:37 By Ionut Arghire The Windows shortcut vulnerability has been seen in attacks conducted by Mustang Panda to drop the PlugX malware. The post Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks Read More »

136 NPM Packages Delivering Infostealers Downloaded 100,000 Times

136 NPM Packages Delivering Infostealers Downloaded 100,000 Times 2025-10-30 at 12:59 By Ionut Arghire The packages deployed malicious code harvesting system information, credentials, tokens, API keys, and other sensitive information. The post 136 NPM Packages Delivering Infostealers Downloaded 100,000 Times appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

136 NPM Packages Delivering Infostealers Downloaded 100,000 Times Read More »

XWiki Vulnerability Exploited in Cryptocurrency Mining Operation

XWiki Vulnerability Exploited in Cryptocurrency Mining Operation 2025-10-29 at 12:54 By Ionut Arghire Exploits have been available publicly for over half a year, but the bug was previously targeted only for reconnaissance. The post XWiki Vulnerability Exploited in Cryptocurrency Mining Operation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

XWiki Vulnerability Exploited in Cryptocurrency Mining Operation Read More »

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks 2025-10-28 at 16:27 By Ionut Arghire A new class of Mirai-based DDoS botnets have been launching massive attacks, but their inability to spoof traffic enables device remediation. The post TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks appeared first on SecurityWeek. This article is an

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks Read More »

Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums

Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums 2025-10-28 at 15:11 By Ionut Arghire The email addresses were pulled from various sources and 16.4 million of them were not present in previous data breaches. The post Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums appeared first on SecurityWeek. This article is

Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums Read More »

Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign

Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign 2025-10-21 at 17:34 By Ionut Arghire A threat actor has been infecting servers of high-profile entities with backdoors to exfiltrate information and deploy additional payloads. The post Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign Read More »

Lumma Stealer Activity Drops After Doxxing

Lumma Stealer Activity Drops After Doxxing 2025-10-20 at 16:07 By Ionut Arghire The identities of alleged core members of the Lumma Stealer group were exposed in an underground doxxing campaign. The post Lumma Stealer Activity Drops After Doxxing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Lumma Stealer Activity Drops After Doxxing Read More »

Cisco Routers Hacked for Rootkit Deployment

Cisco Routers Hacked for Rootkit Deployment 2025-10-16 at 14:17 By Ionut Arghire Threat actors are exploiting CVE-2025-20352, a recent Cisco zero-day, to deploy a rootkit on older networking devices. The post Cisco Routers Hacked for Rootkit Deployment appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Routers Hacked for Rootkit Deployment Read More »

SonicWall SSL VPN Accounts in Attacker Crosshairs

SonicWall SSL VPN Accounts in Attacker Crosshairs 2025-10-13 at 16:41 By Ionut Arghire Threat actors have rapidly compromised more than 100 SonicWall SSL VPN accounts pertaining to over a dozen entities. The post SonicWall SSL VPN Accounts in Attacker Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall SSL VPN Accounts in Attacker Crosshairs Read More »

Scroll to Top