Researchers found fake Python tools on GitHub spreading a new trojan called PyStoreRAT.
The repos look real, gain stars ⭐, and run hidden malware using a Windows tool.
The malware can steal crypto wallet files and stay hidden by pretending to be an NVIDIA update.
The repos look real, gain stars ⭐, and run hidden malware using a Windows tool.
The malware can steal crypto wallet files and stay hidden by pretending to be an NVIDIA update.
Hackers are attacking CentreStack and Triofox right now using a built-in key that never changes.
It lets them break in, read the web-config file, and run code on the server.
At least 9 companies have already been hit.
It lets them break in, read the web-config file, and run code on the server.
At least 9 companies have already been hit.
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
Cyber Dispatch™️
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
The addition of CVE-2018-4063 to the KEV catalog comes a day after a honeypot analysis conducted by Forescout over a 90-day period revealed that industrial routers are the most attacked devices in operational technology (OT) environments, with threat actors attempting to deliver botnet and cryptocurrency miner malware families like RondoDox, Redtail, and ShadowV2 by exploiting the following flaws -
CVE-2024-12856 (Four-Faith routers)
CVE-2024-0012, CVE-2024-9474, and CVE-2025-0108 (Palo Alto Networks PAN-OS)
CVE-2024-12856 (Four-Faith routers)
CVE-2024-0012, CVE-2024-9474, and CVE-2025-0108 (Palo Alto Networks PAN-OS)
Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads.
Google ads funnel Mac users to poisoned AI chats that spread the AMOS infostealer.
Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain.
Hackers built #ransomware — then left the key behind.
CyberVolk’s new VolkLocker targets 💻 Windows and 🐧 Linux.
The flaw? the lock key is hard-coded and saved as a plain file on the system.
Files can be unlocked for free — but after 48 hours, it can wipe 🗑️ personal folders.
CyberVolk’s new VolkLocker targets 💻 Windows and 🐧 Linux.
The flaw? the lock key is hard-coded and saved as a plain file on the system.
Files can be unlocked for free — but after 48 hours, it can wipe 🗑️ personal folders.
Notepad++ fixes a bug that was actively abused.
Notepad++ released version 8.8.9 to patch a critical updater flaw. Attackers hijacked update traffic and tricked users into installing malware instead of real updates.
Notepad++ released version 8.8.9 to patch a critical updater flaw. Attackers hijacked update traffic and tricked users into installing malware instead of real updates.
Poland Police detained three Ukrainian nationals after finding hacking 💻 and spying tools in their car.
Authorities say the gear could be used to attack key IT and telecom 📡 systems tied to national defense.
Charges include fraud and computer-related crimes.
Authorities say the gear could be used to attack key IT and telecom 📡 systems tied to national defense.
Charges include fraud and computer-related crimes.
A six-year-old router flaw is being used right now.
Hackers are actively attacking Sierra Wireless AirLink routers. The bug lets attackers upload a bad file and take full control of the device.
Hackers are actively attacking Sierra Wireless AirLink routers. The bug lets attackers upload a bad file and take full control of the device.
Starlink claims Chinese launch came within 200 meters of broadband satellite.
VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption.
Venezuela’s state-owned oil company says cyberattack targeted operations, blames US aggression.
Venezuela’s state-owned oil company PDVSA said on Monday that it was targeted by a cyberattack intended to disrupt its operations, describing the incident as part of a broader campaign of external pressure against the country’s energy sector.
Venezuela’s state-owned oil company PDVSA said on Monday that it was targeted by a cyberattack intended to disrupt its operations, describing the incident as part of a broader campaign of external pressure against the country’s energy sector.
Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode): Say hello to Kali Linux 2025.4!
The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release
The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release