Latest Cybersecurity News and Articles

February 18, 2025

Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection

Earth Preta’s malware, a variant of the TONESHELL backdoor, is sideloaded with a legitimate Electronic Arts application and communicates with a command-and-control server for data exfiltration.

Black-Hat SEO Campaign Lures Indian Users Into Visiting Potential Phishing Schemes

In a recent development, analysts at CloudSEK have discovered the much maligned use of black hat Search Engine Poisoning by threat actors, to push Rummy and Investment focused websites to unsuspecting users.

Inconsistent Security Strategies Fuel Third-Party Threats

About 47% of organizations have experienced a data breach or cyberattack over the past 12 months that involved a third-party accessing their network, according to Imprivata and the Ponemon Institute.

PoC Exploits for Two Critical LibreOffice Vulnerabilities Released, Patch ASAP

These flaws—CVE-2024-12425 (Arbitrary File Write) and CVE-2024-12426 (Remote File Read)—require no user interaction beyond opening a malicious document, making them highly exploitable in both desktop and server environments.

South Korea Suspends Downloads of AI Chatbot DeepSeek

The Personal Information Protection Commission (PIPC) of South Korea announced the suspension on February 15, citing deficiencies in the app’s communication features and data processing practices.
February 18, 2025

EarthKapre Leverages Cloud Infrastructure and DLL Sideloading for Data Exfiltration

This latest attack chain showcases the group’s ability to weaponize legitimate tools, leveraging DLL sideloading techniques and cloud-based infrastructure to stealthily infiltrate networks and exfiltrate sensitive data.

Android's New Feature Blocks Fraudsters from Sideloading Apps During Calls

The new in-call anti-scammer protections include preventing Android users from turning on settings to install apps from unknown sources and granting access to the Accessibility Services.

Juniper Warns of Critical Authentication Bypass Flaw in Session Smart Routers

Currently, Juniper SIRT is not aware of any malicious exploitation of the CVE-2025-21589 vulnerability. However, given the severity of the flaw, prompt action is crucial to prevent potential attacks.

Microsoft Warns of New XCSSET macOS Malware Variant Used for Cryptocurrency Theft

A new variant of the XCSSET macOS modular malware has emerged in attacks that target users' sensitive information, including digital wallets and data from the legitimate Notes app.

AMD Patches Multiple Vulnerabilities in Embedded Processors

AMD has released security updates addressing multiple vulnerabilities in its EPYC and Ryzen Embedded processors, some of which could allow arbitrary code execution, memory corruption, or privilege escalation.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags