Russian hackers have launched a new cyberattack campaign targeting Ukrainian

Russian hackers have launched a new cyberattack campaign targeting Ukrainian organizations. Security researchers discovered that these hackers used legitimate system tools already present on computers instead of traditional malware. This stealthy method allowed them to move through networks quietly, steal information, and remain undetected for long periods. The investigation revealed that two Ukrainian organizations were … Continued

SideWinder Adopts ClickOnce-Based Attack Chain Targeting South Asian Diplomats

SideWinder, a known hacking group, has launched a new cyber campaign targeting diplomats and government organizations across South Asia. Security experts from the Trellix Advanced Research Center uncovered this operation and revealed that the group is now using PDF files and ClickOnce installers to spread malware. This shows how SideWinder continues to evolve its techniques … Continued

Security Crunch at F5: Breach Sparks Market Drop and Revenue Warning

In a startling development for the cybersecurity sector, F5 Networks (NASDAQ: FFIV) has sounded the alarm: a significant security incident is now expected to impact its sales momentum and has already precipitated a slide in its share price. The Incident at a Glance F5 disclosed that adversaries — believed to be state-backed actors — achieved … Continued

CISA Orders Immediate Patch for Critical Windows Server WSUS Flaw Exploited in Ongoing Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to all federal agencies, asking them to immediately patch a serious flaw in Windows Server Update Services (WSUS). The vulnerability, tracked as CVE-2025-59287, is being actively used by attackers. This security issue allows hackers to remotely run malicious code on vulnerable systems … Continued

Qilin Ransomware Unleashes Hybrid Attack with Linux Payload and BYOVD Exploit

A new ransomware campaign by the Qilin group, also known as Agenda, has been discovered combining a Linux payload with a BYOVD (Bring Your Own Vulnerable Driver) technique. This hybrid approach allows the attackers to run Linux-based ransomware on Windows systems while bypassing security tools. Cyber experts say this cross-platform method makes detection and defense … Continued

GlassWorm: Self-Spreading Malware Infects VS Code Extensions in Major Supply-Chain Attack

A new cyber threat named GlassWorm has been discovered attacking Visual Studio Code (VS Code) extensions. Security experts have confirmed it as the first-ever self-spreading worm targeting developers. It has already infected extensions on both the Microsoft VS Code Marketplace and the OpenVSX registry, with over 35,000 downloads recorded so far. GlassWorm hides its malicious … Continued

The Gift Card Scam Hidden in the Cloud: Unmasking the Jingle Thief Operation

A new cyber-fraud campaign called Jingle Thief is targeting retailers and companies that issue gift cards. Hackers break into cloud accounts and use legitimate company tools to issue unauthorized gift cards. This method makes the fraud hard to spot and allows theft at large scale. The reported losses run into the millions. The attack starts … Continued

Lazarus Group Targets European Drone Manufacturers in New Espionage Campaign

A North Korea–linked hacking group, Lazarus, has launched a new cyber-espionage campaign targeting European drone and defense manufacturers. Security researchers found that the attackers focused on stealing sensitive data, design documents, and technology related to unmanned aerial vehicles (UAVs). The motive appears to be supporting North Korea’s growing interest in military drone development. Cybersecurity firm … Continued

New Oracle E-Business Suite Flaw Exploited in the Wild, CISA Issues Warning

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are actively exploiting a serious vulnerability in Oracle’s E-Business Suite. The flaw, identified as CVE-2025-61884, is a Server-Side Request Forgery (SSRF) bug found in the Oracle Configurator component. It allows attackers to send unauthorized requests to internal systems. CISA has now added this flaw … Continued

Newsletter line