70,000 Discord users had government ID photos and private data exposed via a third-party vendor breach. See Discord’s full response and critical security steps to protect your identity. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Author: Deeba Ahmed
A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube as lures to install them. “Once active, the spyware can exfiltrate SMS messages, call logs, notifications, and device information; taking photos … Read More “New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps – The Hacker News” »
Sen. Peters tries another approach to extend expired cyber threat information-sharing law – CyberScoop
A top Senate Democrat introduced legislation Thursday to extend and rename an expired information-sharing law, and make it retroactive to cover the lapse that began Oct. 1. Michigan Sen. Gary Peters, the ranking member of the Homeland Security and Governmental Affairs Committee, introduced the Protecting America from Cyber Threats (PACT) Act, to replace the expired … Read More “Sen. Peters tries another approach to extend expired cyber threat information-sharing law – CyberScoop” »
Clop, the notorious ransomware group, began targeting Oracle E-Business Suite customers three months ago and started exploiting a zero-day affecting the enterprise platform to steal massive amounts of data from victims as early as Aug. 9, Google Threat Intelligence Group and Mandiant said in a report Thursday. “We’re still assessing the scope of this incident, … Read More “Dozens of Oracle customers impacted by Clop data theft for extortion campaign – CyberScoop” »
ThreatsDay Bulletin: MS Teams Hack, MFA Hijacking, $2B Crypto Heist, Apple Siri Probe & More – The Hacker News
Cyber threats are evolving faster than ever. Attackers now combine social engineering, AI-driven manipulation, and cloud exploitation to breach targets once considered secure. From communication platforms to connected devices, every system that enhances convenience also expands the attack surface. This edition of ThreatsDay Bulletin explores these converging risks and the safeguards that help – Read … Read More “ThreatsDay Bulletin: MS Teams Hack, MFA Hijacking, $2B Crypto Heist, Apple Siri Probe & More – The Hacker News” »
SquareX Shows AI Browsers Fall Prey to OAuth Attacks, Malware Downloads and Malicious Link Distribution – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Palo Alto, California, 9th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Your Shipment Notification is Now a Malware Dropper – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Forcepoint X-Labs reports a surge in sophisticated email attacks using obfuscated JavaScript and steganography to deliver dangerous RATs and info-stealers like Formbook and Agent Tesla. Learn how to defend against the threat. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
SonicWall on Wednesday disclosed that an unauthorized party accessed firewall configuration backup files for all customers who have used the cloud backup service. “The files contain encrypted credentials and configuration data; while encryption remains in place, possession of these files could increase the risk of targeted attacks,” the company said. It also noted that it’s … Read More “Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks – The Hacker News” »
A new report from SquareX Labs highlights security weaknesses in AI browsers like Comet, revealing new cyber-risks – Read More –
New Chaos-C++ Ransomware Targets Windows by Wiping Data, Stealing Crypto – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
FortiGuard Labs reveals Chaos-C++, a new Chaos ransomware variant that deletes files over 1.3 GB instead of encrypting them and uses clipboard hijacking to steal cryptocurrency. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Lightship Security and the OpenSSL Corporation Submit OpenSSL 3.5.4 for FIPS 140-3 Validation – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Newark, United States, 9th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
A new ClayRat spyware campaign has been observed targeting Russian users via fake apps on Telegram and exfiltrating data – Read More –
Token theft is a leading cause of SaaS breaches. Discover why OAuth and API tokens are often overlooked and how security teams can strengthen token hygiene to prevent attacks. Most companies in 2025 rely on a whole range of software-as-a-service (SaaS) applications to run their operations. However, the security of these applications depends on small … Read More “SaaS Breaches Start with Tokens – What Security Teams Must Watch – The Hacker News” »
SonicWall said that a threat actor has accessed files containing encrypted credentials and configuration data for all customers who have used its cloud backup service – Read More –
Fake Teams Installers Dropping Oyster Backdoor (aka Broomstick) – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Hackers are using fake Microsoft Teams installers found in search results and ads to deploy the Oyster backdoor. Learn how to protect your PC from this remote-access threat. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has reached a new level in the first half of 2025 (H1 2025), the country’s State Service for Special Communications and Information Protection (SSSCIP) said. “Hackers now employ it not only to generate phishing messages, but some of the malware samples we have … Read More “From Phishing to Malware: AI Becomes Russia’s New Cyber Weapon in War on Ukraine – The Hacker News” »
The ICO has won an Upper Tribunal appeal against Clearview AI over its ability to fine the company – Read More –
The UK’s National Cyber Security Centre has released new guidance to help firms improve observability and threat hunting – Read More –
A new report from TeamViewer found that 40% of global endpoints still run Windows 10, just days before security updates and support ends for the operating system – Read More –
Who is Ultimately Responsible for Business Email Compromise? – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
Business email compromise, commonly known as “BEC” has become a major issue inthe corporate world. Globally, this condition has been a challenge for the legalauthorities as to exactly who is liable for the damages caused by BEC. South Africancompanies are suffering under the weight of BEC crimes as the courts grapple with themultitude of cases … Read More “Who is Ultimately Responsible for Business Email Compromise? – Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.” »
Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme – The Hacker News
Threat actors are actively exploiting a critical security flaw impacting the Service Finder WordPress theme that makes it possible to gain unauthorized access to any account, including administrators, and take control of susceptible sites. The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects the Service Finder Bookings, a WordPress plugin bundled with the … Read More “Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme – The Hacker News” »
The Indian digital governance on the issue has finally gotten its way with the Digital Personal Data Protection (DPDP)… The post DPDP Act Explained: What Every CISO Must Know in 2025 appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
Posted by Seralys Research Team via Fulldisclosure on Oct 08 Seralys Security Advisory | https://www.seralys.com/research ====================================================================== Title: SQL Injection Vulnerability Product: Open Web Analytics (OWA) Affected: Confirmed on 1.8.0 (older versions likely affected) Fixed in: 1.8.1 Vendor: Open Web Analytics (open-source) Discovered: August 2025 Severity: HIGH CWE: CWE-89: SQL Injection CVE: CVE-2025-59397… – Read More … Read More “CVE-2025-59397 – Open Web Analytics SQL Injection – Full Disclosure” »
Smashing Security podcast #438: When your mouse turns snitch, and hackers grow a conscience – Graham Cluley
Your computer’s mouse might not be as innocent as it looks – and one ransomware crew has a crisis of conscience that nobody saw coming. We talk about how something as ordinary as a web page could turn your mouse into a surprisingly nosey neighbour, and why ransomware gangs need to think carefully about their … Read More “Smashing Security podcast #438: When your mouse turns snitch, and hackers grow a conscience – Graham Cluley” »
Voting rights groups are asking a court to block an ongoing Trump administration effort to merge disparate federal and state voter data into a massive citizenship and voter fraud database. Last week, the League of Women Voters, the Electronic Privacy Information Center (EPIC) and five individuals sued the federal government in D.C. District Court, saying … Read More “Voting groups ask court for immediate halt to Trump admin’s SAVE database overhaul – CyberScoop” »
Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. “Site visitors get injected content that was drive-by malware like fake Cloudflare verification,” Sucuri researcher Puja Srivastava said in an analysis published last week. The website security company – … Read More “Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks – The Hacker News” »
UK Police Arrest Two Teens Over Kido Nursery Ransomware Attack – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Met Police arrested two teenagers over the Kido nursery ransomware attack, which exposed data for 8,000 children. Full details on the hack and police investigation. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
The Scattered LAPSUS$ Hunters hacking group claims to have accessed data from around 40 customers of Salesforce, the cloud-based customer relationship management service, stealing almost one billion records. Read more in my article on the Fortra blog. – Read More – Graham Cluley
Threat actors with suspected ties to China have turned a legitimate open-source monitoring tool called Nezha into an attack weapon, using it to deliver a known malware called Gh0st RAT to targets. The activity, observed by cybersecurity company Huntress in August 2025, is characterized by the use of an unusual technique called log poisoning (aka … Read More “Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave – The Hacker News” »
Encryption lives on in Europe. For now. The German government has said it will oppose a piece of European Union legislation later this month that would subject phones and other devices to mass scanning — prior to encryption — by the government for evidence of child sexual abuse material. Federal Minister of Justice Stefanie Hubig … Read More “German government says it will oppose EU mass-scanning proposal – CyberScoop” »
Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing – Zero Day Initiative – Blog
In April of 2025, my colleague Mat Powell was hunting for vulnerabilities in Autodesk Revit 2025. While fuzzing RFA files, he found the following crash (CVE-2025-5037 / ZDI-CAN-26922, addressed by Autodesk in July 2025): Is this an exploitable crash? From the debugger output crash point as seen above, unclear whether anything is controllable. At around … Read More “Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing – Zero Day Initiative – Blog” »
Three prominent ransomware groups DragonForce, LockBit, and Qilin have announced a new strategic ransomware alliance, once underscoring continued shifts in the cyber threat landscape. The coalition is seen as an attempt on the part of the financially motivated threat actors to conduct more effective ransomware attacks, ReliaQuest said in a report shared with The Hacker … Read More “LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem – The Hacker News” »
A cyber campaign using Nezha has been identified, targeting vulnerable web apps with PHP web shells and Ghost RAT – Read More –
OpenAI Finds Growing Exploitation of AI Tools by Foreign Threat Groups – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
OpenAI’s new report warns hackers are combining multiple AI tools for cyberattacks, scams, and influence ops linked to China, Russia, and North Korea. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Miggo Security Named a Gartner® Cool Vendor in AI Security – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Tel Aviv, Israel, 8th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
According to TransUnion, digital fraud has cost companies $534bn in losses globally with US business hit hardest – Read More –
Cybersecurity researchers have disclosed details of a now-patched vulnerability in the popular figma-developer-mcp Model Context Protocol (MCP) server that could allow attackers to achieve code execution. The vulnerability, tracked as CVE-2025-53967 (CVSS score: 7.5), is a command injection bug stemming from the unsanitized use of user input, opening the door to a scenario where an … Read More “Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now – The Hacker News” »
Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t need advanced tools; they just need one careless login. For IT teams, that means endless resets, compliance struggles, and sleepless nights worrying about the next credential leak. This Halloween, The Hacker News and Specops … Read More “Step Into the Password Graveyard… If You Dare (and Join the Live Session) – The Hacker News” »
New Shuyal Stealer Targets 17 Web Browsers for Login Data and Discord Tokens – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Researchers warn of Shuyal Stealer, malware that gathers browser logins, system details, and Discord tokens, then erases evidence via Telegram. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Jaguar Land Rover has reported a 25% drop in volume sales in the three months up to September 30, largely due to the impact of the ongoing cyber incident – Read More –
North Korean hackers have stolen over $2bn in cryptocurrency already this year, says Elliptic – Read More –
Two 17-year-olds have been arrested following a cyber-attack on the Kido nursery group – Read More –
How organisations can improve their ability to both detect and discover cyber threats. – Read More – NCSC Feed
OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks – The Hacker News
OpenAI on Tuesday said it disrupted three activity clusters for misusing its ChatGPT artificial intelligence (AI) tool to facilitate malware development. This includes a Russian‑language threat actor, who is said to have used the chatbot to help develop and refine a remote access trojan (RAT), a credential stealer with an aim to evade detection. The … Read More “OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks – The Hacker News” »
Data is now being used as a strategic asset and a major vulnerability as global businesses become increasingly digital… The post The Road Ahead: India’s Data Protection in 2026 appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
A cybercriminal group that used voice phishing attacks to siphon more than a billion records from Salesforce customers earlier this year has launched a website that threatens to publish data stolen from dozens of Fortune 500 firms if they refuse to pay a ransom. The group also claimed responsibility for a recent breach involving Discord … Read More “ShinyHunters Wage Broad Corporate Extortion Spree – Krebs on Security” »
Microsoft Threat Intelligence said a cybercriminal group it tracks as Storm-1175 has exploited a maximum-severity vulnerability in GoAnywhere MFT to initiate multi-stage attacks including ransomware. Researchers observed the malicious activity Sept. 11, Microsoft said in a blog post Monday. Microsoft’s research adds another substantive chunk of evidence to a growing collection of intelligence confirming the … Read More “Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate Storm-1175 – CyberScoop” »
A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones. That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting … Read More “OpenAI: Threat actors use us to be efficient, not make new tools – CyberScoop” »
Re: Defense in depth — the Microsoft way (part 93): SRP/SAFER whitelisting goes black on Windows 11 – Full Disclosure
Posted by Stefan Kanthak via Fulldisclosure on Oct 07 On a fresh installation of the just released Windows 11 25H2 the former file %SystemRoot%System32SecurityHealth10.0.27840.1000-0SecurityHealthHost.exe is %SystemRoot%System32SecurityHealthHost.exe now, but the BUG persists: | svchost.exe (PID = 9876) identified \?C:WindowsSystem32SecurityHealthHost.exe | as Disallowed using default rule, Guid = 11015445-d282-4f86-96a2-9e485f593302 stay tuned, and far away from bug-riddled … Read More “Re: Defense in depth — the Microsoft way (part 93): SRP/SAFER whitelisting goes black on Windows 11 – Full Disclosure” »
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain → Secure Enclave Key Theft, Wormable RCE, Crypto Theft – Full Disclosure
Posted by full on Oct 07 Substack is down. If there is a replacement, it is appreciated. -x9p – Read More – Full Disclosure