Latest Cybersecurity News and Articles


Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners

13 January 2025
A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency miners. Cloud security firm Wiz said it's currently responding to "multiple incidents" involving the weaponization of CVE-2024-50603 (CVSS score: 10.0), a maximum severity bug that could result in

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [13 January]

13 January 2025
The cyber world’s been buzzing this week, and it’s all about staying ahead of the bad guys. From sneaky software bugs to advanced hacking tricks, the risks are real, but so are the ways to protect yourself. In this recap, we’ll break down what’s happening, why it matters, and what you can do to stay secure. Let’s turn awareness into action and keep one step ahead

Ransomware on ESXi: The mechanization of virtualized attacks

13 January 2025
In 2024, ransomware attacks targeting VMware ESXi servers reached alarming levels, with the average ransom demand skyrocketing to $5 million. With approximately 8,000 ESXi hosts exposed directly to the internet (according to Shodan), the operational and business impact of these attacks is profound. Most of the Ransomware strands that are attacking ESXi servers nowadays, are variants of the

Cybersecurity researchers discover malware targeting macOS users

13 January 2025
Cybersecurity researchers have discovered an information-stealing malware targeting macOS users. 

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

13 January 2025
Cybersecurity researchers are warning of a new stealthy credit card skimmer campaign that targets WordPress e-commerce checkout pages by inserting malicious JavaScript code into a database table associated with the content management system (CMS). "This credit card skimmer malware targeting WordPress websites silently injects malicious JavaScript into database entries to steal sensitive payment

Expired Domains Allowed Control Over 4,000 Backdoors on Compromised Systems

13 January 2025
No less than 4,000 unique web backdoors previously deployed by various threat actors have been hijacked by taking control of abandoned and expired infrastructure for as little as $20 per domain. Cybersecurity company watchTowr Labs said it pulled off the operation by registering over 40 domain names that the backdoors had been designed to use for command-and-control (C2). In partnership with the

Large companies saw a rise in email-based cyberattacks

13 January 2025
The financial sector faces an increase in email attacks.

Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content Creation

11 January 2025
Microsoft has revealed that it's pursuing legal action against a "foreign-based threat–actor group" for operating a hacking-as-a-service infrastructure to intentionally get around the safety controls of its generative artificial intelligence (AI) services and produce offensive and harmful content. The tech giant's Digital Crimes Unit (DCU) said it has observed the threat actors "develop

DoJ Indicts Three Russians for Operating Crypto Mixers Used in Cybercrime Laundering

11 January 2025
The U.S. Department of Justice (DoJ) on Friday indicted three Russian nationals for their alleged involvement in operating the cryptocurrency mixing services Blender.io and Sinbad.io. Roman Vitalyevich Ostapenko and Alexander Evgenievich Oleynik were arrested on December 1, 2024, in coordination with the Netherlands' Financial Intelligence and Investigative Service, Finland's National Bureau of

AI and other top cybersecurity predictions for 2025

10 January 2025
The new year brings new opportunities, but also the potential for new challenges. Security leaders share some of their predictions for 2025.

Taking the Pain Out of Cybersecurity Reporting: A Practical Guide for MSPs

10 January 2025
Cybersecurity reporting is a critical yet often overlooked opportunity for service providers managing cybersecurity for their clients, and specifically for virtual Chief Information Security Officers (vCISOs). While reporting is seen as a requirement for tracking cybersecurity progress, it often becomes bogged down with technical jargon, complex data, and disconnected spreadsheets that fail to

AI-Driven Ransomware FunkSec Targets 85 Victims Using Double Extortion Tactics

10 January 2025
Cybersecurity researchers have shed light on a nascent artificial intelligence (AI) assisted ransomware family called FunkSec that sprang forth in late 2024, and has claimed more than 85 victims to date. "The group uses double extortion tactics, combining data theft with encryption to pressure victims into paying ransoms," Check Point Research said in a new report shared with The Hacker News. "

Hands-On Walkthrough: Microsegmentation For all Users, Workloads and Devices by Elisity

10 January 2025
Network segmentation remains a critical security requirement, yet organizations struggle with traditional approaches that demand extensive hardware investments, complex policy management, and disruptive network changes. Healthcare and manufacturing sectors face particular challenges as they integrate diverse endpoints – from legacy medical devices to IoT sensors – onto their production networks.

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices

10 January 2025
Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity vulnerability, tracked as CVE-2024-49415 (CVSS score: 8.1), affects Samsung devices running Android versions 12, 13, and 14. "Out-of-bounds write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote

RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage Campaigns

10 January 2025
Mongolia, Taiwan, Myanmar, Vietnam, and Cambodia have been targeted by the China-nexus RedDelta threat actor to deliver a customized version of the PlugX backdoor between July 2023 and December 2024. "The group used lure documents themed around the 2024 Taiwanese presidential candidate Terry Gou, the Vietnamese National Holiday, flood protection in Mongolia, and meeting invitations, including an

CrowdStrike Warns of Phishing Scam Targeting Job Seekers with XMRig Cryptominer

10 January 2025
Cybersecurity company CrowdStrike is alerting of a phishing campaign that exploits its own branding to distribute a cryptocurrency miner that's disguised as an employee CRM application as part of a supposed recruitment process. "The attack begins with a phishing email impersonating CrowdStrike recruitment, directing recipients to a malicious website," the company said. "Victims are prompted to

The Green Bay Packers online store breached, customer information compromised

10 January 2025
The Green Bay Packers is notifying of a breach against its online store, which may have impacted the personal and/or financial data of customers.

Major Vulnerabilities Patched in SonicWall, Palo Alto Expedition, and Aviatrix Controllers

09 January 2025
Palo Alto Networks has released software patches to address several security flaws in its Expedition migration tool, including a high-severity bug that an authenticated attacker could exploit to access sensitive data. "Multiple vulnerabilities in the Palo Alto Networks Expedition migration tool enable an attacker to read Expedition database contents and arbitrary files, as well as create and

New Banshee Stealer Variant Bypasses Antivirus with Apple’s XProtect-Inspired Encryption

09 January 2025
Cybersecurity researchers have uncovered a new, stealthier version of a macOS-focused information-stealing malware called Banshee Stealer. "Once thought dormant after its source code leak in late 2024, this new iteration introduces advanced string encryption inspired by Apple's XProtect," Check Point Research said in a new analysis shared with The Hacker News. "This development allows it to

“U.S. Cyber Trust Mark” launched by the White House

09 January 2025
The White House announced a “U.S. Cyber Trust Mark,” establishing a label for American consumers to verify if their connected devices are cybersecure.