AsyncRAT Abuses ConnectWise ScreenConnect to Steal Passwords and Cryptocurrency

Cybersecurity researchers have discovered that attackers are misusing ConnectWise ScreenConnect, a widely used remote access tool, to deliver AsyncRAT, a dangerous Remote Access Trojan. The malicious campaign is designed to steal sensitive data, login credentials, and even cryptocurrency from unsuspecting victims. The attack begins when a victim downloads or installs a tampered version of the … Continued

SAP S/4HANA Users Urged to Patch Critical Exploited Bug

A new security report has revealed that a dangerous flaw in Apple’s Messages app was used to spy on journalists. At the same time, businesses using SAP S/4HANA are being warned about a critical vulnerability that attackers are already exploiting. Both cases show how quickly hackers move and why updating software immediately is more important … Continued

WEEPSTEEL Malware Deployed in Ongoing Sitecore Zero-Day Campaign

A new zero-day vulnerability has been discovered in Sitecore, and attackers are already taking advantage of it. The flaw is tracked as CVE-2025-53690 and has been linked to active exploitation in the wild. Security researchers from Mandiant revealed that hackers are using this weakness to run malicious code on vulnerable servers, giving them a direct … Continued

How Attackers Used Google’s Own Crawler to Boost Gambling Websites

Security researchers have discovered a cyber campaign where Chinese-linked hackers are secretly manipulating Google search results to push gambling websites. The operation, uncovered by cybersecurity company ESET, has been named GhostRedirector. Evidence shows it started in August 2024 and was still active in June 2025, running undetected for many months. The attackers managed to compromise … Continued

Iranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Campaign

A new cyber-espionage campaign has come to light, this time linked to hackers connected with Iran. Security researchers discovered that attackers compromised more than 100 embassy and government email accounts to target diplomats around the world. By abusing official mailboxes, the hackers were able to make their phishing messages look completely authentic. Investigators found that … Continued

Rising WordPress Attacks: Fake Updates and Hidden Redirects Endanger Users

WordPress, the world’s most widely used website platform, is facing yet another wave of security issues. Researchers have revealed that many WordPress sites are being compromised and abused through malicious or vulnerable plugins. These hacked sites are being used to spread two major threats, known as ClickFix attacks and Traffic Distribution Systems (TDS). Both of … Continued

Newsletter line