Iranian Hackers Target Defense and Government Officials in Ongoing Campaign

Iranian cyber espionage group APT42, associated with IRGC, has been targeting defense and government officials using social engineering and long-term relationship-building tactics. Their sophisticated operation employs modular malware and covert communication channels like Telegram and Discord for persistent data exfiltration. #APT42 #IRGC #TameCat #SpearSpecter…

Read More
North Korea’s Contagious Interview APT Uses JSON Keeper and GitLab to Deliver BeaverTail Spyware

Security researchers have uncovered an evolved North Korean-linked malware campaign called Contagious Interview that uses JSON storage services to host malicious code. The attackers target software developers and Web3 professionals through spoofed recruiter messages and deliver payloads like BeaverTail and InvisibleFerret for credential theft and remote access. #ContagiousInterview #BeaverTail #InvisibleFerret #NorthKorea…

Read More
CISA warns feds to fully patch actively exploited Cisco flaws

CISA has issued warnings and emergency directives urging U.S. federal agencies to urgently patch two critical vulnerabilities in Cisco ASA and Firepower devices, which are actively exploited in ongoing attacks. Despite previous updates, some organizations remain unpatched, leaving their networks vulnerable to remote code execution and complete device takeover. #CISA #CiscoASA #ZeroDay #ArcaneDoor

Read More
Fantasy Hub: Russian-sold Android RAT boasts full device espionage as MaaS

Zimperium researchers have identified Fantasy Hub, a Russian Android RAT offered as Malware-as-a-Service, capable of device control, spying, and data theft through Telegram. This sophisticated MaaS platform targets banks and enterprise users, leveraging native droppers, WebRTC streaming, and SMS abuse to evade detection. #FantasyHub #RussianThreatActors #BankingTrojan…

Read More
Cybersecurity News | Daily Recap [13 Nov 2025]

Daily Recap, APT & Malware campaigns underpin a surge in weaponized documents and backdoors like Comebacker and ChaCha20, while vulnerabilities in Triofox, runC, and expr-eval threaten broader ecosystems. The news also covers credential phishing trends via Quantum Route Redirect and LinkedIn, regulatory actions on NY pricing and data privacy whistleblowers, plus notable incidents at Asahi and GitHub secrets leaks.
#ChaCha20 #Comebacker #KONNI #APT37 #FindHub #Triofox #runC #expr-eval #Yanluowang #Asahi #GitHub

Read More
CISA orders feds to patch Samsung zero-day used in spyware attacks

A critical Samsung vulnerability (CVE-2025-21042) was exploited in zero-day attacks to deploy the LandFall spyware via WhatsApp, affecting flagship Galaxy devices. U.S. federal agencies are mandated to patch this flaw to prevent further breaches, with potential targets including multiple countries and espionage activities. #CVE-2025-21042 #LandFallSpyware

Read More
New Microsoft Teams Feature Exposes Users to Phishing and Malware Risks

Microsoft is launching a new Teams update that allows users to chat with anyone using just an email address, increasing connectivity across multiple platforms. However, security experts warn that this feature significantly enlarges the attack surface, raising risks of phishing, malware distribution, and data breaches. #MicrosoftTeams #B2BGuest #Phishing #OAuth #Malware…

Read More