• FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation

    FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation

    The U.S. Department of Justice (DoJ) on Tuesday disclosed that a court-authorized operation allowed the Federal Bureau of Investigation (FBI) to delete PlugX malware from over 4,250 infected computers as part of a “multi-month law enforcement operation.” PlugX, also known as Korplug, is a remote access trojan (RAT) widely used by threat actors associated with…

    Read More

  • 3 Actively Exploited Zero-Day Flaws Patched in Microsoft’s Latest Security Update

    3 Actively Exploited Zero-Day Flaws Patched in Microsoft’s Latest Security Update

    Microsoft kicked off 2025 with a new set of patches for a total of 161 security vulnerabilities across its software portfolio, including three zero-days that have been actively exploited in attacks. Of the 161 flaws, 11 are rated Critical, and 149 are rated Important in severity. One other flaw, a non-Microsoft CVE related to a…

    Read More

  • Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks

    Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks

    Cybersecurity researchers have disclosed multiple security flaws in SimpleHelp remote access software that could lead to information disclosure, privilege escalation, and remote code execution. Horizon3.ai researcher Naveen Sunkavally, in a technical report detailing the findings, said the “vulnerabilities are trivial to reverse and exploit.” The list of identified flaws is as follows –

    Read More

  • Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation

    Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation

    Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as “root” to bypass the operating system’s System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions. The vulnerability in question is CVE-2024-44243 (CVSS score: 5.5), a medium-severity bug

    Read More

  • Google OAuth Vulnerability Exposes Millions via Failed Startup Domains

    Google OAuth Vulnerability Exposes Millions via Failed Startup Domains

    New research has pulled back the curtain on a “deficiency” in Google’s “Sign in with Google” authentication flow that exploits a quirk in domain ownership to gain access to sensitive data. “Google’s OAuth login doesn’t protect against someone purchasing a failed startup’s domain and using it to re-create email accounts for former employees,” Truffle Security…

    Read More

  • Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners

    Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners

    A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency miners. Cloud security firm Wiz said it’s currently responding to “multiple incidents” involving the weaponization of CVE-2024-50603 (CVSS score: 10.0), a maximum severity bug that could result in

    Read More

  • ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [13 January]

    ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [13 January]

    The cyber world’s been buzzing this week, and it’s all about staying ahead of the bad guys. From sneaky software bugs to advanced hacking tricks, the risks are real, but so are the ways to protect yourself. In this recap, we’ll break down what’s happening, why it matters, and what you can do to stay…

    Read More

  • Ransomware on ESXi: The Mechanization of Virtualized Attacks

    Ransomware on ESXi: The Mechanization of Virtualized Attacks

    In 2024, ransomware attacks targeting VMware ESXi servers reached alarming levels, with the average ransom demand skyrocketing to $5 million. With approximately 8,000 ESXi hosts exposed directly to the internet (according to Shodan), the operational and business impact of these attacks is profound. Most of the Ransomware strands that are attacking ESXi servers nowadays, are…

    Read More

  • WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

    WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

    Cybersecurity researchers are warning of a new stealthy credit card skimmer campaign that targets WordPress e-commerce checkout pages by inserting malicious JavaScript code into a database table associated with the content management system (CMS). “This credit card skimmer malware targeting WordPress websites silently injects malicious JavaScript into database entries to steal sensitive payment

    Read More

  • Expired Domains Allowed Control Over 4,000 Backdoors on Compromised Systems

    Expired Domains Allowed Control Over 4,000 Backdoors on Compromised Systems

    No less than 4,000 unique web backdoors previously deployed by various threat actors have been hijacked by taking control of abandoned and expired infrastructure for as little as $20 per domain. Cybersecurity company watchTowr Labs said it pulled off the operation by registering over 40 domain names that the backdoors had been designed to use…

    Read More