
Month: July 2025
-
Caught in the Act: Uncovering SpyNote in Unexpected Places
Multiple samples of SpyNote, a sophisticated Android spyware, were discovered in open directories, disguised as legitimate apps like Google Translate,…
-
Radiology Associates of Richmond data breach impacts 1.4 million people
A data breach at Radiology Associates of Richmond has exposed the personal and health information of over 1.4 million individuals.———————————————————————————————————————————-Radiology…
-
Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards
Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.The vulnerabilities,…
-
SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access
A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed ‘ToolShell,’ enabling…
-
Popular npm linter packages hijacked via phishing to drop malware
Popular JavaScript libraries were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted…
-
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick…
-
Hackers Exploit FIDO MFA With Novel Phishing Technique
[Cybercrime](https://www.govinfosecurity.com/cybercrime-c-416) , [Fraud Management -& Cybercrime](https://www.govinfosecurity.com/fraud-management-cybercrime-c-409) , [Multi-factor -& Risk-based Authentication](https://www.govinfosecurity.com/multi-factor-risk-based-authentication-c-448)Hackers Exploit FIDO MFA With Novel Phishing Technique======================================================PoisonSeed Threat Actor…
-
Authorities released free decryptor for Phobos and 8base ransomware
Pierluigi Paganini reports: Japanese authorities released a free decryptor for Phobos and 8Base ransomware, allowing victims to recover files without…
-
Government will ‘robustly defend’ compensation claims from Afghans put at risk by data breach
So after putting their lives at risk, the UK’s Ministry of Defence will firmly resist giving anyone even a pence…
-
Fortinet FortiWeb flaw CVE-2025-25257 exploited hours after PoC release
Hackers exploited a Fortinet FortiWeb flaw the same day a PoC was published, compromising dozens of systems.————————————————————————————————————Hackers began exploiting a…

