Security News

Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
2025-05-28 16:44

Over 9,000 ASUS routers are compromised by a novel botnet dubbed "AyySSHush" that was also observed targeting SOHO routers from Cisco, D-Link, and Linksys. [...]

Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization
2025-05-20 09:32

Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker that targeted an unnamed international organization in Saudi Arabia with a previously undocumented...

Communications Backdoor in Chinese Power Inverters
2025-05-16 13:55

This is a weird story: U.S. energy officials are reassessing the risk posed by Chinese-made devices that play a critical role in renewable energy infrastructure after unexplained communication...

Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
2025-05-13 05:08

A Türkiye-affiliated threat actor exploited a zero-day security flaw in an Indian enterprise communication platform called Output Messenger as part of a cyber espionage attack campaign since April...

Florida Backdoor Bill Fails
2025-05-12 11:01

A Florida bill requiring encryption backdoors failed to pass.

Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
2025-05-09 10:57

Cybersecurity researchers have flagged three malicious npm packages that are designed to target the Apple macOS version of Cursor, a popular artificial intelligence (AI)-powered source code...

⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors
2025-05-05 11:29

What if attackers aren't breaking in—they're already inside, watching, and adapting? This week showed a sharp rise in stealth tactics built for long-term access and silent control. AI is being...

WordPress plugin disguised as a security tool injects backdoor
2025-04-30 21:05

A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it. [...]

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
2025-04-28 08:06

Cybersecurity researchers are warning about a large-scale phishing campaign targeting WooCommerce users with a fake security alert urging them to download a "critical patch" but deploy a backdoor...

Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems
2025-04-19 15:11

Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities....