North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware
https://cybersecuritynews.com/north-korean-hackers-weaponized-67-malicious-npm-packages/
https://cybersecuritynews.com/north-korean-hackers-weaponized-67-malicious-npm-packages/
Cyber Security News
North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware
North Korean hackers planted 67 malicious npm packages with 17K+ downloads, using new XORIndex malware in an evolving supply chain attack.
Octalyn Stealer Steals VPN Configurations, Passwords and Cookies in Structured Folders
https://cybersecuritynews.com/octalyn-stealer-steals-vpn-configurations/
https://cybersecuritynews.com/octalyn-stealer-steals-vpn-configurations/
Cyber Security News
Octalyn Stealer Steals VPN Configurations, Passwords and Cookies in Structured Folders
Octalyn Stealer on GitHub poses as a forensic tool, stealing VPN, browser, and crypto data via stealthy C++/Delphi malware builder.
VMware ESXi and Workstation Vulnerabilities Let Attackers Execute Malicious Code on Host
https://cybersecuritynews.com/vmware-esxi-and-workstation-vulnerabilities/
https://cybersecuritynews.com/vmware-esxi-and-workstation-vulnerabilities/
Cyber Security News
VMware ESXi and Workstation Vulnerabilities Let Attackers Execute Malicious Code on Host
Multiple severe vulnerabilities have been addressed affecting VMware ESXi, Workstation, Fusion, and Tools that could allow attackers to execute malicious code on host systems.
NCSC Expands Vulnerability Research to Tackle Evolving Cyber Threats
https://thecyberexpress.com/ncsc-vulnerability-research/
https://thecyberexpress.com/ncsc-vulnerability-research/
The Cyber Express
NCSC Vulnerability Research Enhances UK Cyber Resilience
Here’s how NCSC vulnerability research and the VRI strengthen UK cybersecurity through collaboration with experts, and the UK government.
Police disrupt “Diskstation” ransomware gang attacking NAS devices
https://www.bleepingcomputer.com/news/security/police-disrupt-diskstation-ransomware-gang-attacking-nas-devices/
https://www.bleepingcomputer.com/news/security/police-disrupt-diskstation-ransomware-gang-attacking-nas-devices/
BleepingComputer
Police disrupt “Diskstation” ransomware gang attacking NAS devices
An international law enforcement action dismantled a Romanian ransomware gang known as 'Diskstation,' which encrypted the systems of several companies in the Lombardy region, paralyzing their businesses.
North Korean XORIndex malware hidden in 67 malicious npm packages
https://www.bleepingcomputer.com/news/security/north-korean-xorindex-malware-hidden-in-67-malicious-npm-packages/
https://www.bleepingcomputer.com/news/security/north-korean-xorindex-malware-hidden-in-67-malicious-npm-packages/
BleepingComputer
North Korean XORIndex malware hidden in 67 malicious npm packages
North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems.
Microsoft Fixed 130+ Flaws With July Patch Tuesday
https://latesthackingnews.com/2025/07/15/microsoft-fixed-130-flaws-with-july-patch-tuesday/
https://latesthackingnews.com/2025/07/15/microsoft-fixed-130-flaws-with-july-patch-tuesday/
LHN
Microsoft Fixed 130+ Flaws With July Patch Tuesday
Microsoft has rolled out the Patch Tuesday updates for July 2025, ensuring the updates. This month’s update bundle is rather huge, addressing 137 different vulnerabilities across different products. Users with eligible devices should ensure keeping
Windows KB5064489 emergency update fixes Azure VM launch issues
https://www.bleepingcomputer.com/news/microsoft/windows-kb5064489-emergency-update-fixes-azure-vm-launch-issues/
https://www.bleepingcomputer.com/news/microsoft/windows-kb5064489-emergency-update-fixes-azure-vm-launch-issues/
BleepingComputer
Windows KB5064489 emergency update fixes Azure VM launch issues
Microsoft has released an emergency update to fix a bug that prevents Azure virtual machines from launching when the Trusted Launch setting is disabled and Virtualization-Based Security (VBS) is enabled.
AsyncRAT seeds family of more than 30 remote access trojans
https://cyberscoop.com/asyncrat-malware-variants-eset/
https://cyberscoop.com/asyncrat-malware-variants-eset/
CyberScoop
AsyncRAT seeds family of more than 30 remote access trojans
ESET researchers observed tens of thousands of machines infected with AsyncRAT and its variants over the past year. The open-source malware is a popular tool among cybercriminals.
Waltz brushes off SignalGate questions, points finger at CISA
https://cyberscoop.com/waltz-signal-gate-cisa-guidance-senate-foreign-relations/
https://cyberscoop.com/waltz-signal-gate-cisa-guidance-senate-foreign-relations/
CyberScoop
Waltz brushes off SignalGate questions, points finger at CISA
In congressional testimony, President Trump’s former national security adviser said his use of Signal to coordinate military operations was “driven by” cybersecurity guidance from CISA.
Abacus dark web drug market goes offline in suspected exit scam
https://www.bleepingcomputer.com/news/security/abacus-dark-web-drug-market-goes-offline-in-suspected-exit-scam/
https://www.bleepingcomputer.com/news/security/abacus-dark-web-drug-market-goes-offline-in-suspected-exit-scam/
OpenAI's image model gets built-in style feature on ChatGPT
https://www.bleepingcomputer.com/news/artificial-intelligence/openais-image-model-gets-built-in-style-feature-on-chatgpt/
https://www.bleepingcomputer.com/news/artificial-intelligence/openais-image-model-gets-built-in-style-feature-on-chatgpt/
BleepingComputer
OpenAI's image model gets built-in style feature on ChatGPT
OpenAI's image gen model, which is available via ChatGPT for free, now lets you easily create AI images even if you're not familiar with trends or prompt engineering.
Urgent Chrome Update: Google Patches Critical Zero-Day (CVE-2025-6558) Under Active Attack
https://securityonline.info/urgent-chrome-update-google-patches-critical-zero-day-cve-2025-6558-under-active-attack/
https://securityonline.info/urgent-chrome-update-google-patches-critical-zero-day-cve-2025-6558-under-active-attack/
Daily CyberSecurity
Urgent Chrome Update: Google Patches Critical Zero-Day (CVE-2025-6558) Under Active Attack
Google released a critical Chrome update (138.0.7204.157/.158) patching six vulnerabilities, including CVE-2025-6558, a high-severity zero-day actively exploited in the wild. Update immediately!
Broadcom Addresses Critical Vulnerabilities in VMware ESXi, Workstation, and Fusion
https://securityonline.info/broadcom-addresses-critical-vulnerabilities-in-vmware-esxi-workstation-and-fusion/
https://securityonline.info/broadcom-addresses-critical-vulnerabilities-in-vmware-esxi-workstation-and-fusion/
Daily CyberSecurity
Broadcom Addresses Critical Vulnerabilities in VMware ESXi, Workstation, and Fusion
Broadcom has released urgent patches for four critical (CVSS up to 9.3) VMware vulnerabilities affecting ESXi, Workstation, and Fusion, allowing host code execution.
Apache CXF Vulnerability: DoS and Data Leak Risks Exposed (CVE-2025-48795)
https://securityonline.info/apache-cxf-vulnerability-dos-and-data-leak-risks-exposed-cve-2025-48795/
https://securityonline.info/apache-cxf-vulnerability-dos-and-data-leak-risks-exposed-cve-2025-48795/
Daily CyberSecurity
Apache CXF Vulnerability: DoS and Data Leak Risks Exposed (CVE-2025-48795)
Apache CXF versions are vulnerable to DoS attacks and sensitive data leaks (CVE-2025-48795) due to improper handling of large messages. Update immediately!
Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others
https://cyberscoop.com/cameron-wagenius-att-snowflake-guilty-plea/
https://cyberscoop.com/cameron-wagenius-att-snowflake-guilty-plea/
CyberScoop
Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others
Cameron Wagenius faces a maximum of 27 years in prison. A researcher that helped with the investigation called this ‘one of the most significant wins in the fight against cybercrime.'
US Army Soldier “kiberphant0m” Pleads Guilty to Telecom Hacking & $1M Extortion Scheme
https://securityonline.info/us-army-soldier-kiberphant0m-pleads-guilty-to-telecom-hacking-1m-extortion-scheme/
https://securityonline.info/us-army-soldier-kiberphant0m-pleads-guilty-to-telecom-hacking-1m-extortion-scheme/
Daily CyberSecurity
US Army Soldier "kiberphant0m" Pleads Guilty to Telecom Hacking & $1M Extortion Scheme
A former US Army soldier, Cameron John Wagenius (kiberphant0m), pleaded guilty to hacking telecom companies, stealing data, and attempting to extort $1 million.
Google’s $3B Hydropower Bet: Fueling AI While Facing Data Center Water Crisis
https://securityonline.info/googles-3b-hydropower-bet-fueling-ai-while-facing-data-center-water-crisis/
https://securityonline.info/googles-3b-hydropower-bet-fueling-ai-while-facing-data-center-water-crisis/
Daily CyberSecurity
Google's $3B Hydropower Bet: Fueling AI While Facing Data Center Water Crisis
Google secures 3GW of hydropower in a $3B deal to power its AI data centers, while the tech industry faces mounting criticism over its massive water consumption.
New PhantomRemote Backdoor Targets Russian Healthcare & IT, Linked to Rainbow Hyena Attacks
https://securityonline.info/new-phantomremote-backdoor-targets-russian-healthcare-it-linked-to-rainbow-hyena-attacks/
https://securityonline.info/new-phantomremote-backdoor-targets-russian-healthcare-it-linked-to-rainbow-hyena-attacks/
Daily CyberSecurity
New PhantomRemote Backdoor Targets Russian Healthcare & IT, Linked to Rainbow Hyena Attacks
The Rainbow Hyena threat cluster is unleashing PhantomRemote, a new backdoor, in phishing attacks against Russia's healthcare and IT sectors, leveraging compromised emails.
GLOBAL GROUP: New Ransomware Giant Emerges with AI Negotiators, Affiliate Incentives, and Industrial-Scale Attacks
https://securityonline.info/global-group-new-ransomware-giant-emerges-with-ai-negotiators-affiliate-incentives-and-industrial-scale-attacks/
https://securityonline.info/global-group-new-ransomware-giant-emerges-with-ai-negotiators-affiliate-incentives-and-industrial-scale-attacks/
Daily CyberSecurity
GLOBAL GROUP: New Ransomware Giant Emerges with AI Negotiators, Affiliate Incentives, and Industrial-Scale Attacks
GLOBAL GROUP, a rebranded RaaS operation, is aggressively targeting critical infrastructure worldwide, leveraging AI chatbots for automated, high-pressure ransom negotiations.
Warning: “Educational” Octalyn Forensic Toolkit is a Dangerous Telegram-Controlled Credential Stealer
https://securityonline.info/warning-educational-octalyn-forensic-toolkit-is-a-dangerous-telegram-controlled-credential-stealer/
https://securityonline.info/warning-educational-octalyn-forensic-toolkit-is-a-dangerous-telegram-controlled-credential-stealer/
Daily CyberSecurity
Warning: "Educational" Octalyn Forensic Toolkit is a Dangerous Telegram-Controlled Credential Stealer
Cyfirma uncovers "Octalyn Forensic Toolkit," a GitHub-hosted "educational" tool that's actually a modular credential stealer exfiltrating data via Telegram.