INTERPOL Warns of Rising Phishing, Ransomware, and AI-Powered Scams Across Asia-Pacific

Cybercrime is growing rapidly across Asia-Pacific, and INTERPOL has warned that phishing attacks, ransomware campaigns, and AI-powered scams are becoming major threats across the region. According to its latest cyberthreat assessment, criminal groups are taking advantage of expanding digital services, new technologies, and increasing internet usage to target both organizations and individuals. The report found … Continued

Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers

Microsoft has linked the recent supply chain attack targeting the Mastra AI ecosystem to a North Korean threat group known as Sapphire Sleet. The attack affected the popular Mastra AI framework, which is widely used by developers to build AI agents, workflows, and automation tools. According to Microsoft, the attackers compromised the software supply chain … Continued

Canada’s Spy Agency Takes Down Botnet Threat Using Historic Court Warrant

Canada’s intelligence agency, the Canadian Security Intelligence Service (CSIS), has revealed that it used a special court-approved warrant to remove malware from infected devices across the country. According to a newly released Federal Court ruling, this is the first time CSIS has used its threat reduction powers in this way. The operation targeted two botnets … Continued

4,300 Legacy Routers Hijacked by AryStinger Malware to Power a Global Reconnaissance Network

Security researchers have discovered a newly identified malware family called AryStinger that is quietly infecting outdated internet routers around the world. According to researchers from QiAnXin XLab, more than 4,300 devices have already been compromised, and the number continues to grow. Unlike many router-based botnets that focus on launching DDoS attacks, AryStinger is designed to … Continued

Salesforce Disables Klue Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has disabled the connection between its platform and Klue Battlecards after a security incident involving the abuse of OAuth tokens. The company took the action as a precautionary measure after investigators discovered that attackers had used a compromised Klue integration to access customer data stored in Salesforce environments. Reports indicate that the issue was … Continued

AI-Generated Explicit Images Used in Cyberstalking Case, New York Man Faces Federal Charges

Federal prosecutors have charged a New York man in a cyberstalking case that highlights the growing misuse of artificial intelligence for online harassment. Authorities say 21-year-old Anthony Belford carried out a months-long campaign targeting a college student in Georgia. The case has drawn attention because it involved both AI-generated nude images and fake online identities … Continued

Apple Fixes Beats Studio Buds Flaw That Could Let Nearby Attackers Spy on Conversations

Apple has released an important security update for Beats Studio Buds after fixing a vulnerability that could allow nearby attackers to misuse the earbuds’ microphone. The issue affected devices that were not yet paired and were actively searching for Bluetooth connections. According to Apple’s security advisory, an attacker within Bluetooth range could potentially listen through … Continued

Novo Nordisk Breach Reveals Hidden Risks Inside Modern Software Pipelines

A recent security incident involving Novo Nordisk has drawn attention to an often-overlooked cybersecurity problem inside modern software development environments. Reports indicate that a leaked GitHub access token exposed weaknesses in the company’s development pipeline and highlighted how sensitive credentials can become a major security risk when not properly managed. The incident has become an … Continued

Your Checkout Page Has a Hidden Security Problem, PCI DSS Is Paying Attention

Many businesses believe that if their payment systems pass a PCI DSS assessment, their online checkout pages are secure. However, security experts are warning that this assumption is no longer true. Modern checkout pages rely on numerous third-party scripts such as analytics tools, marketing tags, chat widgets, and tracking technologies. If one of these scripts … Continued

Fake Reviews, AI Videos, and VirusTotal Comments Used to Spread Crypto Clipper Malware

Cybersecurity researchers have uncovered a large-scale crypto clipper campaign that uses fake online promotion techniques to spread malware and steal cryptocurrency from victims. According to findings from Check Point Research, the attackers are using paid articles on legitimate news websites, fake reviews, social media content, and software-hosting platforms to make their malicious tools appear trustworthy. … Continued

Newsletter line