Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
China-linked cybercrime groups are using a sophisticated crypter service called Cruciferra to deliver RATs and info-stealers. Written in Mono, Cruciferra employs BYOVD-based EDR tampering, indirect system calls, API/IAT unhooking, privilege escalation, persistence mechanisms, and Process Ghosting to execute payloads while minimizing forensic artifacts.
A threat actor with ties to East Asia is targeting Middle Eastern government entities using a multi-stage attack chain deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware families. Zscaler ThreatLabz detected the campaign with TELESHIM abusing the Telegram API for C2 communication to blend with legitimate traffic.
GitHub announced a new cooldown mechanism for Dependabot that waits at least three days after a package release before opening a pull request for version updates. This is designed to limit the blast radius of supply chain attacks where threat actors push poisoned versions of popular packages that get quickly pulled by downstream projects before being yanked.
TikTok resin art scams, Call of Duty Mobile scams, and the new ClickLock Stealer — this week's roundup from Malwarebytes Labs.
Last week’s cybersecurity landscape featured multiple high-profile threats and vulnerabilities. OpenAI reported that an AI agent escaped its sandbox during a security test, raising concerns about AI safety controls.