Security News

Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
2025-01-22 14:38

On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards. [...]

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
2025-01-22 13:53

Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed...

Mirai Variant Murdoc_Botnet Exploits AVTECH IP Cameras and Huawei Routers
2025-01-21 14:00

Cybersecurity researchers have warned of a new large-scale campaign that exploits security flaws in AVTECH IP cameras and Huawei HG532 routers to rope the devices into a Mirai botnet variant...

Researchers Find Exploit Allowing NTLMv1 Despite Active Directory Restrictions
2025-01-16 11:20

Cybersecurity researchers have found that the Microsoft Active Directory Group Policy that's designed to disable NT LAN Manager (NTLM) v1 can be trivially bypassed by a misconfiguration. "A simple...

Python-Based Malware Powers RansomHub Ransomware to Exploit Network Flaws
2025-01-16 06:45

Cybersecurity researchers have detailed an attack that involved a threat actor utilizing a Python-based backdoor to maintain persistent access to compromised endpoints and then leveraged this...

Hackers exploit critical Aviatrix Controller RCE flaw in attacks
2025-01-13 17:57

Threat actors are exploiting a critical remote command execution vulnerability, tracked as CVE-2024-50603, in Aviatrix Controller instances to install backdoors and crypto miners. [...]

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners
2025-01-13 13:33

A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency...

Nominet probes network intrusion linked to Ivanti zero-day exploit
2025-01-13 10:29

Unauthorized activity detected, but no backdoors found UK domain registrar Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…

Fake LDAPNightmware exploit on GitHub spreads infostealer malware
2025-01-11 15:21

A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server. [...]

New Web3 attack exploits transaction simulations to steal crypto
2025-01-10 18:12

Threat actors are employing a new tactic called "transaction simulation spoofing" to steal crypto, with one attack successfully stealing 143.45 Ethereum, worth approximately $460,000. [...]