Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
In Q3 2025, Cybereason’s Incident Response (IR) team identified a significant rise in the use of Living Off the Land Binaries (LOLBINs) and the exploitation of known vulnerabilities, particularly CVE-2025-1234 and CVE-2025-5678, by threat actors. LOLBINs, legitimate system tools like PowerShell and Windows Management Instrumentation (WMI), were leveraged to evade detection while executing malicious activities such as lateral movement and data exfiltration.
Multiple vulnerabilities were identified in PHP. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass, denial of service condition, sensitive information disclosure and data manipulation on the targeted system. Impact Remote Code Execution Security Restriction Bypass Data Manipulation Denial of Service Information Disclosure System / Technologies affected PHP version prior to 8.5.9 PHP version prior to 8.4.24 PHP version prior to 8.3.33 PHP version prior to 8.2.33 Solutions Before installation of the software, please visit the software manufacturer web-site for more details.
Trend™ Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems. This cross-platform execution can make detection challenging for enterprises.
This Trend Micro analysis covers ransomware threats including attack chains, indicators of compromise, and recommended defensive measures. Ransomware continues to be a primary cyber risk for organizations across all sectors.
Trend™ Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems. This cross-platform execution can make detection challenging for enterprises.
Trend™ Research examines the complex collaborative relationship between China-aligned APT groups via the new “Premier Pass-as-a-Service” model, exemplified by the recent activities of Earth Estries and Earth Naga.