RedDirection Malicious Browser Extensions

The RedDirection campaign revealed a network of 18 malicious browser extensions across Chrome and Edge that infected over 2.3 million users by hijacking browsers while providing legitimate functionality. These extensions exploited trust signals such as verified badges and featured placements to silently deploy malware through updates and enable persistent surveillance and redirection attacks. #RedDirection #ColorPicker #BrowserHijacking

Read More
Likely Belarus-Nexus Threat Actor Delivers Downloader to Poland

A malicious CHM file named deklaracja.chm was uploaded from Poland, initiating an infection chain that deploys a C++ downloader through obfuscated JavaScript and a CAB file payload. The downloader fetches an encrypted payload from rustyquill[.]top, associated with the FrostyNeighbor and UNC1151 threat actors, targeting Eastern European countries. #deklaracja_chm #FrostyNeighbor #UNC1151 #rustyquill_top

Read More
Canadian Electric Utility Says Power Meters Disrupted by Cyberattack

A cyberattack on Nova Scotia Power disrupted communication with power meters and led to a data breach affecting thousands of customers, including some in the United States. The incident involved ransomware, resulting in the theft of sensitive personal and billing information, with the threat actor unknown. #Ransomware #DataBreach #NovaScotiaPower #Emera #Cyberattack…

Read More
Cybersecurity News | Daily Recap [08 Jul 2025]

Cybersecurity experts report a surge in sophisticated spyware campaigns, including the Batavia and Atomic Stealer strains, targeting Russian firms and Mac users globally. Additionally, new botnets like RondoDox and hpingbot are exploiting vulnerabilities and enabling stealthy DDoS attacks, highlighting persistent threats to organizations worldwide. #Batavia #AtomicStealer #RondoDox #hpingbot

Read More
Count(er) Strike – Data Inference Vulnerability in ServiceNow

Varonis Threat Labs discovered a critical vulnerability named Count(er) Strike in ServiceNow’s platform that allowed minimal-access users to infer and exfiltrate sensitive data across multiple tables. ServiceNow addressed the issue by releasing security updates and introducing new access control mechanisms like Query ACLs and Security Data Filters. #CounterStrike #ServiceNow #CVE-2025-3648…

Read More
Android malware Anatsa infiltrates Google Play to target US banks

The Anatsa banking trojan has been distributed through fake apps on Google Play, which pose as utilities like PDF viewers and QR readers, with downloads exceeding 50,000. Once installed, it overlays banking apps with fake messages and performs malicious activities such as keylogging and transaction automation, while Google has removed the malicious app from the store. #Anatsa #GooglePlay #BankingTrojan

Read More