ποΈ 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged a new set of 175 malicious packages on the npm registry that have been used to facilitate credential harvesting attacks as part of an unusual campaign. The packages have been collectively downloaded 26,000 times, acting as an infrastructure for a widespread phishing campaign codenamed Beamglea targeting more than 135 industrial, technology, and energy.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity company Huntress said it has observed active inthewild exploitation of an unpatched security flaw impacting Gladinet CentreStack and TrioFox products. The zeroday vulnerability, tracked as CVE202511371 CVSS score 6.1, is an unauthenticated local file inclusion bug that allows unintended disclosure of system files. It impacts all versions of the software prior to and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Google Launches AI Bug Bounty with $30,000 Top Reward π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Google has introduced a new AI Vulnerability Reward Program offering up to 30,000 for bug discoveries in its AI products.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Google Launches AI Bug Bounty with $30,000 Top Reward
Google has introduced a new AI Vulnerability Reward Program offering up to $30,000 for bug discoveries in its AI products
π Google: Clop Accessed βSignificant Amountβ of Data in Oracle EBS Exploit π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
GTIG highlighted indicators that Clop is behind the extortion campaign targeting Oracle EBS instances, with its activity likely beginning as early as August 9.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Google: Clop Accessed βSignificant Amountβ of Data in Oracle EBS Exploit
GTIG highlighted indicators that Clop is behind the extortion campaign targeting Oracle EBS instances, with its activity likely beginning as early as August 9
π Pro-Russia Hacktivists βClaimβ Attack on Water Utility Honeypot π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Forescout said that the TwoNet actor was lured into attacking a honeypot disguised as a water treatment utility, providing insights into the groups tactics.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Pro-Russia Hacktivists βClaimβ Attack on Water Utility Honeypot
Forescout said that the TwoNet actor was lured into attacking a honeypot disguised as a water treatment utility, providing insights into the groupβs tactics
π When a $6 Billion Business Faces Purple Team Testing: Human and Technical Gaps Exposed π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
On paper, a 6 billion food production company in the United States looked unwavering. Having a reliable global reputation, 10,000 employees on board, Palo Alto WildFire and Cortex XDR in The post When a 6 Billion Business Faces Purple Team Testing Human and Technical Gaps Exposed appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Purple Team Testing: $6 billion business couldnβt stop the breach
When a $6 Billion Business Faces Purple Team Testing to uncover security gaps, despite the effectiveness of detection tools
π¦
Cyber Threats in the EU Escalate as Diverse Groups Target Critical Sectors π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
EU Threat Landscape " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202510EUThreatLandscape300x150.webp" datalargefile"httpscyble.comwpcontentuploads202510EUThreatLandscape1024x512.webp" title"Cyber Threats in the EU Escalate as Diverse Groups Target Critical Sectors 1" The European Union continues to face a complex web of cyber threats, according to the 2025 ENISA Threat Landscape report. Covering incidents from July 2024 through June 2025, the report details how a variety of threat actors are targeting the EUs digital infrastructure with overlapping tactics, highly technical attack models, and heightened collaboration. The EU Threat Landscape and Converging Threat Groups ENISAs latest analysis, based on 4,875 recorded cybersecurity incidents, reveals a reuse of...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
ποΈ From Detection to Patch: Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Fortra on Thursday revealed the results of its investigation into CVE202510035, a critical security flaw in GoAnywhere Managed File Transfer MFT that's assessed to have come under active exploitation since at least September 11, 2025. The company said it began its investigation on September 11 following a "potential vulnerability" reported by a customer, uncovering "potentially suspicious.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Oberig IT Becomes the Official Distributor of UnderDefense Solutions π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Oberig IT, a distributor of advanced integrated solutions in IT and cybersecurity, has signed a strategic distribution agreement with UnderDefense Cybersecurity, a global provider of cybersecurity services and solutions. The The post Oberig IT Becomes the Official Distributor of UnderDefense Solutions appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Oberig IT Becomes the Official Distributor of UnderDefense Solutions
Partnership between Oberig IT and UnderDefense to make cybersecurity more available in different regions.
π’ 'Payroll Pirates' target US universities, Microsoft warns π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Group uses simple but effective tactics to divert staff salaries to themselves.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
'Payroll Pirates' target US universities, Microsoft warns
Group uses simple but effective tactics to divert staff salaries to themselves
π’ Researchers sound alarm over AI hardware vulnerabilities that expose training data π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Hackers can abuse flaws in AI accelerators to break AI privacy and a reliable fix could be years away.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Researchers sound alarm over AI hardware vulnerabilities that expose training data
Hackers can abuse flaws in AI accelerators to break AI privacy β and a reliable fix could be years away
ποΈ Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of an active malware campaign called Stealit that has leveraged Node.js' Single Executable Application SEA feature as a way to distribute its payloads. According to Fortinet FortiGuard Labs, select iterations have also employed the opensource Electron framework to deliver the malware. It's assessed that the malware is being propagated through.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Microsoft Warns of βPayroll Piratesβ Hijacking HR SaaS Accounts to Steal Employee Salaries ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A threat actor known as Storm2657 has been observed hijacking employee accounts with the end goal of diverting salary payments to attackercontrolled accounts. "Storm2657 is actively targeting a range of U.S.based organizations, particularly employees in sectors like higher education, to gain access to thirdparty human resources HR software as a service SaaS platforms like Workday," the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
βοΈ DDoS Botnet Aisuru Blankets US ISPs in Record DDoS βοΈ
π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
The world's largest and most disruptive botnet is now drawing a majority of its firepower from compromised InternetofThings IoT devices hosted on U.S. Internet providers like ATT, Comcast and Verizon, new evidence suggests. Experts say the heavy concentration of infected devices at U.S. providers is complicating efforts to limit collateral damage from the botnet's attacks, which shattered previous records this week with a brief traffic flood that clocked in at nearly 30 trillion bits of data per second.π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
Krebs on Security
DDoS Botnet Aisuru Blankets US ISPs in Record DDoS
The world's largest and most disruptive botnet is now drawing a majority of its firepower from compromised Internet-of-Things (IoT) devices hosted on U.S. Internet providers like AT&T, Comcast and Verizon, new evidence suggests. Experts say the heavy concentrationβ¦
ποΈ New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its EBusiness Suite that it said could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE202561884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14. "Easily exploitable vulnerability allows an unauthenticated attacker with.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1
ποΈ Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity company Huntress on Friday warned of "widespread compromise" of SonicWall SSL VPN devices to access multiple customer environments. "Threat actors are authenticating into multiple accounts rapidly across compromised devices," it said. "The speed and scale of these attacks imply that the attackers appear to control valid credentials rather than bruteforcing." A significant chunk of.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Threat actors are abusing Velociraptor, an opensource digital forensics and incident response DFIR tool, in connection with ransomware attacks likely orchestrated by Storm2603 aka CLCRI1040 or Gold Salem, which is known for deploying the Warlock and LockBit ransomware. The threat actor's use of the security utility was documented by Sophos last month. It's assessed that the attackers.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Andesite vs. Swimlane: The 2025 AI SOC Dilemma π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
This guide cuts through the noise when Andesite and Swimlane land on the same shortlist. Its not what do they do?, youve seen the slides. Its what changes day one?, The post Andesite vs. Swimlane The 2025 AI SOC Dilemma appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Andesite vs. Swimlane: AI SOC Showdown for 2025
Compare Andesite vs. Swimlane in the 2025 AI SOC race. Explore costs, failure modes, and how each fits your stack.
π 9 ReliaQuest Alternatives for AIβDriven SOC in 2025 π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
This guide breaks down the top ReliaQuest alternatives. Below are 9 AI SOC platforms that offer a path forward whether you want true MDR, stronger automation, or smarter detection coverage. For The post 9 ReliaQuest Alternatives for AIDriven SOC in 2025 appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
9 Best ReliaQuest Alternatives for AI SOC in 2025
Evaluating ReliaQuest? We compare 9 credible alternatives. Understand strengths, blind spots, and cost realities.
π Sophos vs. Cisco-Splunk Ecosystem (2025): XDR Copilot vs. Agentic SOC π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Sophos vs. CiscoSplunk is a clash of AI philosophies in SecOps. Sophos drops an AI copilot into your XDR, speeding human judgment where investigations actually happen. Cisco and Splunk wire The post Sophos vs. CiscoSplunk Ecosystem 2025 XDR Copilot vs. Agentic SOC appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Sophos vs. Cisco-Splunk (2025): AI Copilot vs. Agentic SOC
Compare Sophos vs. CiscoβSplunk 2025. See how AI copilots and agentic SOCs reshape XDR, automation, and SecOps outcomes.
ποΈ New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a new Rustbased backdoor called ChaosBot that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. "Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an overprivileged Active Directory account named, 'serviceaccount,'" eSentire said in a technical report published.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity