π Cisco just patched two critical vulnerabilities in Identity Services Engine (ISE) that could allow attackers to execute arbitrary commands and escalate privileges remotely.
β οΈ CVE-2025-20124 & CVE-2025-20125 carry CVSS scores of 9.9 and 9.1.
Read β https://thehackernews.com/2025/02/cisco-patches-critical-ise.html
β οΈ CVE-2025-20124 & CVE-2025-20125 carry CVSS scores of 9.9 and 9.1.
Read β https://thehackernews.com/2025/02/cisco-patches-critical-ise.html
π17π₯4π2π1
π North Korea-linked Kimsuky hacking group now using forceCopy, a new info-stealer malware targeting browser credentials.
Spear-phishing emails trick victims into opening disguised Windows shortcut files. PowerShell and mshta.exe trigger malware download, leading to deeper infection.
π Read More: https://thehackernews.com/2025/02/north-korean-apt-kimsuky-uses-lnk-files.html
Spear-phishing emails trick victims into opening disguised Windows shortcut files. PowerShell and mshta.exe trigger malware download, leading to deeper infection.
π Read More: https://thehackernews.com/2025/02/north-korean-apt-kimsuky-uses-lnk-files.html
π8π€7β‘3π3π1
π¨ New malware campaign "SparkCat" has been discovered on Apple and Google app stores, using OCR to target crypto wallet recovery phrases.
Read the full report: https://thehackernews.com/2025/02/sparkcat-malware-uses-ocr-to-extract.html
Read the full report: https://thehackernews.com/2025/02/sparkcat-malware-uses-ocr-to-extract.html
π€12π€―6π4π1
Ransomware is hitting harder in 2025. Hackers demand millionsβand paying up doesnβt guarantee youβll get your data back.
LockBit, Lynx, and Virlockβransomware groups are evolving, targeting everyone from small businesses to critical infrastructure.
Get the full breakdown on how to defend against these threats.: https://thehackernews.com/2025/02/top-3-ransomware-threats-active-in-2025.html
LockBit, Lynx, and Virlockβransomware groups are evolving, targeting everyone from small businesses to critical infrastructure.
Get the full breakdown on how to defend against these threats.: https://thehackernews.com/2025/02/top-3-ransomware-threats-active-in-2025.html
π14β‘8π€3π₯2
PAM isnβt just a cybersecurity tool. Itβs a game-changer for operational efficiency, compliance & security.
β’ Enforces the principle of least privilege
β’ Boosts regulatory compliance
β’ Protects from evolving threats
Donβt miss out on this essential shift in cybersecurity leadership.
Read: https://thehackernews.com/2025/02/the-evolving-role-of-pam-in.html
β’ Enforces the principle of least privilege
β’ Boosts regulatory compliance
β’ Protects from evolving threats
Donβt miss out on this essential shift in cybersecurity leadership.
Read: https://thehackernews.com/2025/02/the-evolving-role-of-pam-in.html
π8π₯7π1π€―1
β οΈ Big names like LockBit and BlackCat are collapsing, but smaller players are multiplying. Cybercriminals raked in $813.5M from ransomware in 2024βa sharp drop from $1.25B in 2023.
Smaller, faster, and more dangerousβransomware just got a whole lot trickier.
Get the full insights: https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html
Smaller, faster, and more dangerousβransomware just got a whole lot trickier.
Get the full insights: https://thehackernews.com/2025/02/ransomware-extortion-drops-to-8135m-in.html
π€―11π4π₯2π±1
Bogus websites masquerading as Google Chrome are now distributing ValleyRATβan evolving remote access trojan.
Targeting high-value roles in finance, accounting, and sales, this threat actorβSilver Foxβstrategically targets sensitive systems.
Read the full report: https://thehackernews.com/2025/02/fake-google-chrome-sites-distribute.html
Targeting high-value roles in finance, accounting, and sales, this threat actorβSilver Foxβstrategically targets sensitive systems.
Read the full report: https://thehackernews.com/2025/02/fake-google-chrome-sites-distribute.html
π10π₯8β‘6π3π1
π¨ URGENT: Attackers are exploiting newly discovered flaws in SimpleHelp RMM software to establish persistent access to networks and deploy ransomware.
CVE-2024-57726, CVE-2024-57727, CVE-2024-57728: Flaws enabling privilege escalation, remote code execution.
π Secure your systems and read the full details: https://thehackernews.com/2025/02/hackers-exploit-simplehelp-rmm-flaws.html
CVE-2024-57726, CVE-2024-57727, CVE-2024-57728: Flaws enabling privilege escalation, remote code execution.
π Secure your systems and read the full details: https://thehackernews.com/2025/02/hackers-exploit-simplehelp-rmm-flaws.html
π₯15π7β‘2π2π€―2
The RBI is introducing a dedicated "bank[.]in" domain to combat digital fraud and secure digital transactions.
Read the full article: https://thehackernews.com/2025/02/indias-rbi-introduces-exclusive-bankin.html
Read the full article: https://thehackernews.com/2025/02/indias-rbi-introduces-exclusive-bankin.html
π₯8π5β‘3π€2π€―2π1
π¨ Alert: Publicly exposed ASP'NET machine keys could give attackers an easy way to infiltrate your systems.
π Over 3,000 keys are now available for exploitation. Microsoft reveals how attackers can inject malicious code using these keys to gain remote code execution.
π Read full article: https://thehackernews.com/2025/02/microsoft-identifies-3000-publicly.html
π Over 3,000 keys are now available for exploitation. Microsoft reveals how attackers can inject malicious code using these keys to gain remote code execution.
π Read full article: https://thehackernews.com/2025/02/microsoft-identifies-3000-publicly.html
π₯9β‘6π5π3π1
π¨ CISA warns of active exploitation in Trimble Cityworks GIS software, with a high-severity vulnerability (CVE-2025-0994, CVSS 8.6) being weaponized in the wild.
If left unpatched, attackers could gain unauthorized access and deploy harmful payloads like Cobalt Strike and VShell.
Read: https://thehackernews.com/2025/02/cisa-warns-of-active-exploitation-in.html
If left unpatched, attackers could gain unauthorized access and deploy harmful payloads like Cobalt Strike and VShell.
Read: https://thehackernews.com/2025/02/cisa-warns-of-active-exploitation-in.html
π8π4β‘2π₯1
π AI-Powered Social Engineering is Here β And It's Evolving FAST!
Criminals are automating and personalizing attacks, making them more effective than ever.
AI-generated phishing emails and deepfake CFOs are tricking employees into transferring millions.
π Learn how to equip your workforce to spot deception: https://thehackernews.com/2025/02/ai-powered-social-engineering.html
Criminals are automating and personalizing attacks, making them more effective than ever.
AI-generated phishing emails and deepfake CFOs are tricking employees into transferring millions.
π Learn how to equip your workforce to spot deception: https://thehackernews.com/2025/02/ai-powered-social-engineering.html
π18π€8β‘3π2
π DeepSeek's iOS app is transmitting sensitive user data without encryption to a cloud platform linked to ByteDance (TikTok), leaving it wide open to hackers.
π See the full story and analysis here: https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html
π See the full story and analysis here: https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html
π€―62π46π18β‘5π€5π4
β οΈ Researchers have uncovered two malicious ML models on Hugging Face using a new attack methodβ"broken" pickle filesβto bypass detection.
These models execute a reverse shell right from the start, connecting to a hard-coded IP.
π§ Learn more: https://thehackernews.com/2025/02/malicious-ml-models-found-on-hugging.html
These models execute a reverse shell right from the start, connecting to a hard-coded IP.
π§ Learn more: https://thehackernews.com/2025/02/malicious-ml-models-found-on-hugging.html
π21π±12π₯11π7π€5π€―4β‘2
π XE Group has evolved. Theyβre no longer just stealing credit card dataβtheyβre exploiting zero-day vulnerabilities (like CVE-2024-57968 in VeraCore) to target supply chains
Once in, they can drop reverse shells, exfiltrate files, and even modify data
https://thehackernews.com/2025/02/xe-hacker-group-exploits-veracore-zero.html
Once in, they can drop reverse shells, exfiltrate files, and even modify data
https://thehackernews.com/2025/02/xe-hacker-group-exploits-veracore-zero.html
π8π4π±3β‘2π€2
Zimbra's latest patch addresses three new vulnerabilities:
β’ SQL Injection (CVE-2025-25064) exposing email metadata to authenticated attackers.
β’ XSS vulnerability in the Classic Web Client, risking user security.
β’ SSRF flaw (CVE-2025-25065) allowing unauthorized redirection to internal systems.
Upgrade ASAP to avoid potential exploitation and secure your systems.
Read: https://thehackernews.com/2025/02/zimbra-releases-security-updates-for.html
β’ SQL Injection (CVE-2025-25064) exposing email metadata to authenticated attackers.
β’ XSS vulnerability in the Classic Web Client, risking user security.
β’ SSRF flaw (CVE-2025-25065) allowing unauthorized redirection to internal systems.
Upgrade ASAP to avoid potential exploitation and secure your systems.
Read: https://thehackernews.com/2025/02/zimbra-releases-security-updates-for.html
π₯13π6π3β‘1
A Chinese-speaking hacker group, DragonRank, is targeting IIS servers across Asia with BadIIS malware, redirecting users to rogue gambling sites.
Critical sectorsβgovernments, universities, and tech firmsβare at risk.
π Read more: https://thehackernews.com/2025/02/dragonrank-exploits-iis-servers-with.html
Critical sectorsβgovernments, universities, and tech firmsβare at risk.
π Read more: https://thehackernews.com/2025/02/dragonrank-exploits-iis-servers-with.html
π11π10π₯3π€3β‘2π€―1
π¨ This Week in Cyber: Hackers Are Getting SmarterβAre You?
πΉ AI-powered fraud is on the rise
πΉ Stolen ASP .NET keys fuel cyberattacks
πΉ Ransomware payouts drop, but attacks surge
πΉ Abandoned cloud storage = hacker goldmine
Stay ahead of the threats. Read the full recap now: https://thehackernews.com/2025/02/thn-weekly-recap-top-cybersecurity_10.html
πΉ AI-powered fraud is on the rise
πΉ Stolen ASP .NET keys fuel cyberattacks
πΉ Ransomware payouts drop, but attacks surge
πΉ Abandoned cloud storage = hacker goldmine
Stay ahead of the threats. Read the full recap now: https://thehackernews.com/2025/02/thn-weekly-recap-top-cybersecurity_10.html
π11β‘5π4
β οΈ WARNING: Hackers are using Google Tag Manager (GTM) to deliver credit card skimming malware on Magento e-commerce sites.
Targeting checkout pages to capture credit card details
3 sites found infected; it could be more
Learn more about this attack: https://thehackernews.com/2025/02/hackers-exploit-google-tag-manager-to.html
Targeting checkout pages to capture credit card details
3 sites found infected; it could be more
Learn more about this attack: https://thehackernews.com/2025/02/hackers-exploit-google-tag-manager-to.html
π22π10π₯8β‘5
π Apple has released emergency security updates for iOS and iPadOS to patch a vulnerability exploited in the wild.
This flaw, identified as CVE-2025-24200, could allow attackers to disable USB Restricted Mode on locked devices.
Update your devices now: https://thehackernews.com/2025/02/apple-patches-actively-exploited-ios.html
This flaw, identified as CVE-2025-24200, could allow attackers to disable USB Restricted Mode on locked devices.
Update your devices now: https://thehackernews.com/2025/02/apple-patches-actively-exploited-ios.html
π₯19π6β‘3π€2