Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Targets Global Defense Networks

A new cyber espionage campaign known as Operation SkyCloak is targeting military and defense organizations in Russia and Belarus. Security researchers have discovered that the attackers are using phishing emails with fake military documents to deliver malicious files. The campaign appears to be focused on stealing sensitive information and maintaining long-term access to defense systems. … Continued

BankBot-YNRK and DeliveryRAT: New Android Trojans Stealing Banking Data Exposed

Researchers have discovered two new Android malware strains named BankBot-YNRK and DeliveryRAT that are actively stealing users’ financial and personal information. These trojans were found disguised as legitimate applications and are spreading through deceptive downloads and fake app packages targeting Android devices. BankBot-YNRK is a mobile banking trojan that hides inside apps pretending to be … Continued

Top 10 Free Application Security Testing Tools

Application Security (AppSec) has become an essential part of modern software development. It ensures that applications stay secure during their design, build, and deployment phases. As DevOps pipelines speed up and cloud-native systems grow, organizations increasingly depend on Application Security Testing (AST) tools to find and fix vulnerabilities early in the lifecycle. A previous post, … Continued

CISA Warns of Actively Exploited VMware Zero-Day (CVE-2025-41244) Used by China-Linked Hackers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a new VMware zero-day vulnerability, tracked as CVE-2025-41244. The flaw has been added to CISA’s Known Exploited Vulnerabilities (KEV) list, which means it is being actively used in real-world attacks. Security experts say this vulnerability needs immediate attention from all organizations using … Continued

Top 10 Cloud Security Certifications

As organizations move to cloud environments, the need for skilled cloud security professionals is rising. The global cloud security market, valued at $35.84 billion in 2024, is expected to grow to $75.26 billion by 2030, with a compound annual growth rate of 13.3% [Grand View Research]. The urgency is further emphasized by the alarming statistic … Continued

Data Leak Outs Students of Iran’s MOIS-Linked Ravin Academy

A major data breach has occurred at Ravin Academy, a cybersecurity training centre established in 2019 in Tehran and linked to Iran’s Ministry of Intelligence and Security (MOIS). The academy confirmed the incident through a statement on its official Telegram channel on October 22, saying that one of its online platforms was attacked and that … Continued

10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux

Security researchers recently discovered that ten malicious npm packages were uploaded to the public npm registry. These packages were designed to look like legitimate ones but had slightly altered names, a trick known as typosquatting. The goal was to make developers accidentally install them, allowing attackers to secretly execute malicious code during the installation process … Continued

Newsletter line