Grinex, A7A5, and the Crypto Comeback Nobody Wanted

In March 2025, law enforcement agencies shut down Garantex, a notorious cryptocurrency exchange that facilitated illicit financial activity. But as history has shown, the fall of one platform often marks the rise of another. Now, all eyes are on Grinex – a similar exchange that’s now doing the work of Garantex. Background Grantex had operated … Continued

Uyghur Exiles Targeted in Sophisticated Malware Campaign by China

A targeted cyberattack on Uyghur exiles and senior members of the World Uyghur Congress (WUC) has been reported by Citizen Lab. It is believed to be orchestrated by threat actors linked to the Chinese government. In March 2025, WUC members living in exile were subjected to a spear phishing campaign that delivered Windows-based malware disguised … Continued

Attackers Exploit SAP NetWeaver Zero-Day Vulnerability Worldwide

A critical vulnerability in SAP’s Netweaver Visual Composer tool is being actively exploited by attackers in the wild, raising alarm across industries that rely on the enterprise software platform. The vulnerability, tracked as CVE-2025-31324, carries the maximum CVSS severity score of 10 and affects all SAP NetWeaver 7.xx versions. The vulnerability allows unauthenticated, remote attackers … Continued

Indian Army nursing college website hacked by Pro-Pakistan Hackers

Amid rising tensions between India and Pakistan following the Pahalgam incident, anticipation of retaliatory action between the two nations has grown. But as cybersecurity community often warns—before the missiles fly, the cyberattacks strike. Today, the website of India’s Army Nursing College was hacked by a pro-Pakistan hacker group known as “Team Insane PK.” The cyberattack … Continued

Russian Hackers Exploit OAuth 2.0 to Hack Ukraine-Linked Organizations

In a new wave of cyberattacks, Russia-linked threat actors are exploiting legitimate Auth 2.0 authentication processes to compromise Microsoft 365 accounts belonging to individuals affiliated with Ukraine and human rights organizations, according to a report by cybersecurity firm Volexity. The adversaries—tracked by Volexity as UTA0352 and UTA0355—have been conducting the operation since early March, shortly … Continued

Critical Commvault Vulnerability (CVE-2025-34028) Allows Remote Code Execution

A newly disclosed high-severity vulnerability in CommVault’s Command Center has caused a stir in the cybersecurity community. The product, often deployed at the core of critical infrastructure, contains serious flaws that could potentially compromise the entire system if exploited. Commvault Vulnerability CVE-2025-34028 The vulnerability, tracked as CVE-2025-34028, affects Commvault Command Center versions 11.38.0 through 11.38.19 … Continued

Critical Langflow Vulnerability CVE-2025-3248 Exposes AI Platforms to Remote Code Execution Attacks

A newly discovered critical vulnerability in Langflow has been discovered by Zscaler, an open-source platform widely used for visually composing AI agents and workflows. Tracked as CVE-2025-3248, the flaw allows unauthenticated attackers to remotely execute arbitrary code on vulnerable servers, with a severity score of 9.8 on the Common Vulnerability Scoring System (CVSS). Overview of … Continued

North Korea’s Void Dokkaebi exploits job seekers through fake company BlockNovas

Cybersecurity researchers at Trend Micro have uncovered a sophisticated campaign by North Korea-linked threat actor group Void Dokkaebi, which used a fictitious company called BlockNovas to lure job seekers into downloading malware disguised as part of an interview process. This campaign, run across platforms like LinkedIn, Upwork, and Freelancer, has already affected hundreds of applicants … Continued

Zyxel Issues Security Patches for USG FLEX H Firewall

Zyxel has released critical security updates for its USG FLEX H series firewalls, addressing two vulnerabilities tracked as CVE-2025-1731 and CVE-2025-1732 allow attackers to escalate privileges on affected systems. Vulnerability Details CVE-2025-1732 pertains to improper privilege management within the firmware’s recovery function. This vulnerability could allow a local attacker with administrative access to upload a … Continued

SK Telecom Hit by Malware Attack

SK Telecom, South Korea’s largest mobile operator, has confirmed a security breach involving customer SIM-related information following a malware infection discovered late on April 19. The attack, which occurred around 11:00 PM local time on Saturday, exploited a period when many organizations typically operate with reduced staffing. SK Telecom servers approximately 34 million subscribers and … Continued

Newsletter line