• Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

    The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT. The campaign, which is primarily aimed at Chinese-speaking users, employs trojanized NSIS installers masquerading as legitimate like Google Chrome and Microsoft Teams, according to…

    Read More

  • Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time

    Google has disclosed that the company’s continued adoption of the Rust programming language in Android has resulted in the number of memory safety vulnerabilities falling below 20% for the first time. “We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code.…

    Read More

  • RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

    The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request…

    Read More

  • Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies

    The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28,…

    Read More

  • Oregon Journalism Project: Nation’s Top Court Will Consider Ballot Deadline

    FREE NEWS from Oregon Journalism Project: Oregon is one of at least 19 states that allows the practice. In 2021, lawmakers passed House Bill 3291, which expanded voting laws to allow elections officials to count any ballot postmarked by election…

    Read More

  • Congressman Bentz Statement Supporting the Reopening of the Government

    FREE NEWS: On Wednesday, Nov. 12, Congressman Cliff Bentz (R-OR) voted YES on the “Senate Amendment to H.R. 531, Continuing Appropriations and Extension Act, 2026.”

    Read More

  • North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

    The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage malicious payloads. “The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware from trojanized code projects, with the lure,” NVISO…

    Read More

  • Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

    Cybersecurity researchers have uncovered critical remote code execution vulnerabilities impacting major artificial intelligence (AI) inference engines, including those from Meta, Nvidia, Microsoft, and open-source PyTorch projects such as vLLM and SGLang. “These vulnerabilities all traced back to the same root cause: the overlooked unsafe use of ZeroMQ (ZMQ) and Python’s pickle deserialization,”

    Read More

  • Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns

    Key Takeaways: 85 active ransomware and extortion groups observed in Q3 2025, reflecting the most decentralized ransomware ecosystem to date. 1,590 victims disclosed across 85 leak sites, showing high, sustained activity despite law-enforcement pressure. 14 new ransomware brands launched this quarter, proving how quickly affiliates reconstitute after takedowns. LockBit’s reappearance with

    Read More

  • Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign

    State-sponsored threat actors from China used artificial intelligence (AI) technology developed by Anthropic to orchestrate automated cyber attacks as part of a “highly sophisticated espionage campaign” in mid-September 2025. “The attackers used AI’s ‘agentic’ capabilities to an unprecedented degree – using AI not just as an advisor, but to execute the cyber attacks themselves,” the…

    Read More