• Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

    Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

    Google on Monday released security updates for its Chrome browser to address two security flaws, including one that has come under active exploitation in the wild. The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8), a type confusion vulnerability in the V8 JavaScript and WebAssembly engine that could be exploited to achieve arbitrary code execution…

    Read More

  • New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

    New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

    Cybersecurity researchers have discovered malware campaigns using the now-prevalent ClickFix social engineering tactic to deploy Amatera Stealer and NetSupport RAT. The activity, observed this month, is being tracked by eSentire under the moniker EVALUSION. First spotted in June 2025, Amatera is assessed to be an evolution of ACR (short for “AcridRain”) Stealer, which was available…

    Read More

  • ⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

    ⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More

    This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. Criminals are building systems to make money,…

    Read More

  • Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

    Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

    The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT. The campaign, which is primarily aimed at Chinese-speaking users, employs trojanized NSIS installers masquerading as legitimate like Google Chrome and Microsoft Teams, according to…

    Read More

  • Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time

    Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time

    Google has disclosed that the company’s continued adoption of the Rust programming language in Android has resulted in the number of memory safety vulnerabilities falling below 20% for the first time. “We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code.…

    Read More

  • RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

    RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

    The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request…

    Read More

  • Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies

    Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies

    The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28,…

    Read More

  • Oregon Journalism Project: Nation’s Top Court Will Consider Ballot Deadline

    Oregon Journalism Project: Nation’s Top Court Will Consider Ballot Deadline

    FREE NEWS from Oregon Journalism Project: Oregon is one of at least 19 states that allows the practice. In 2021, lawmakers passed House Bill 3291, which expanded voting laws to allow elections officials to count any ballot postmarked by election…

    Read More

  • Congressman Bentz Statement Supporting the Reopening of the Government

    Congressman Bentz Statement Supporting the Reopening of the Government

    FREE NEWS: On Wednesday, Nov. 12, Congressman Cliff Bentz (R-OR) voted YES on the “Senate Amendment to H.R. 531, Continuing Appropriations and Extension Act, 2026.”

    Read More

  • North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

    North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

    The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage malicious payloads. “The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware from trojanized code projects, with the lure,” NVISO…

    Read More