Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs post, oktober 1, 2025oktober 3, 2025 The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools… Continue Reading
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware post, september 30, 2025oktober 3, 2025 Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42… Continue Reading
VMware Zero-Day Under Attack By China-Linked Hackers Since October 2024 post, september 30, 2025oktober 3, 2025 Broadcom has published security advisory VMSA-2025-0015, disclosing six vulnerabilities in VMware products — among them four rated High / Important — and urging users to apply patches immediately. One of the more serious flaws is CVE-2025-41244, a local privilege escalation vulnerability (CVSS score 7.8) Continue Reading
CISA and UK NCSC Release Joint Guidance for Securing OT Systems post, september 29, 2025oktober 3, 2025 CISA, in collaboration with the Federal Bureau of Investigation, the United Kingdom’s National Cyber Security Centre, and other international partners has released new joint cybersecurity guidance: Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture. Building on the recent Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and… Continue Reading
UK Government To Underwrite £1.5 Billion loan Guarantee To Jaguar Land Rover Following Devastating Cyber-Attack post, september 29, 2025oktober 3, 2025 In an unprecedented move, the UK government has announced a £1.5 billion loan guarantee to Jaguar Land Rover (JLR) as the carmaker continues to grapple with the aftermath of a crippling cyber-attack that has brought its UK production lines to a standstill for nearly a month. The loan from a… Continue Reading
Sophisticated Campaign Targets Microsoft Teams Users With Oyster Malware post, september 28, 2025oktober 3, 2025 Cybersecurity researchers have uncovered a cyberattack method that illustrates the growing sophistication of modern malvertising campaigns. This new wave of attacks sees threat actors leverage SEO poisoning techniques and search engine advertisements to lure unsuspecting users into downloading fake Microsoft Teams installers. These deceptive downloads ultimately infect Windows systems with… Continue Reading
CISA Releases Advisory on Lessons Learned from an Incident Response Engagement post, september 23, 2025oktober 3, 2025 Today, CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool. This advisory, CISA Shares Lessons Learned from an Incident Response Engagement, highlights takeaways that illuminate the urgent… Continue Reading
Critical SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation post, september 23, 2025september 24, 2025 SolarWinds has issued an urgent security advisory regarding a critical remote code execution (RCE) vulnerability in its Web Help Desk (WHD) platform, warning customers of an actively exploitable flaw that could allow unauthenticated attackers to gain complete control over affected systems. The vulnerability, CVE-2025-26399, has been assigned a CVSS severity… Continue Reading
Widespread Supply Chain Compromise Impacting npm Ecosystem post, september 23, 2025september 24, 2025 CISA is releasing this Alert to provide guidance in response to a widespread software supply chain compromise involving the world’s largest JavaScript registry, npmjs.com. A self-replicating worm—publicly known as “Shai-Hulud”—has compromised over 500 packages.[i] After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive… Continue Reading
Major Cyberattack Disrupts Heathrow & Other European Airports post, september 20, 2025september 22, 2025 Air travel across several major European hubs has been severely disrupted after what is being described as a cyber-attack on a key service provider responsible for check-in and boarding systems. The incident, which has impacted airports including London’s Heathrow, Brussels Airport, and Berlin Brandenburg Airport, has led to widespread delays,… Continue Reading