X-Worm Malware
X-Worm is a Windows-based Remote Access Trojan (RAT) that has gained popularity in underground forums due to…
continue reading..
CVE-2025-15095: Silent XSS Risk in Postman Labs httpbin Testing Service
Vulnerability Summary CVE ID: CVE-2025-15095CVE Name: Postman Labs httpbin Reflected Cross-Site ScriptingCVSS Score: 3.5 / 10.0Severity: Low…
continue reading..
Unsecured Credentials (T1552): The Simplest Path to Total Compromise
Unsecured Credentials (T1552) is one of the most abused techniques in the Credential Access tactic of the…
continue reading..
Living Off the Cloud: Threat Actors Exploiting .onmicrosoft.com
What is .onmicrosoft.com? .onmicrosoft.com is the default domain automatically assigned when someone creates a tenant in Microsoft’s…
continue reading..
MacSync Stealer’s New Tricks: How macOS Malware Is Getting More Sophisticated
In the ever-changing landscape of cybersecurity threats, macOS users have long believed their systems to be relatively…
continue reading..
CVE-2020-12812 — FortiOS SSL VPN : Active exploitation in the wild of this older vulnerability
CVE-2020-12812 is a critical authentication bypass vulnerability in the SSL VPN component of FortiOS, the operating system…
continue reading..
Massive Spotify Music Scrape Exposed: Inside Anna’s Archive’s 300TB Data Release
A group known as Anna’s Archive—previously recognized for hosting and distributing large-scale “shadow libraries” of books and…
continue reading..
CVE-2025-14847: A Critical MongoDB Vulnerability Demanding Immediate Action
At its core, CVE-2025-14847 is a memory disclosure vulnerability caused by improper handling of zlib-compressed protocol headers.…
continue reading..
SideWinder APT Targets Indian Organizations via DLL Side-Loading and Fake Income Tax Portals
SideWinder APT has resurfaced with a highly targeted cyber-espionage campaign aimed at Indian organizations, abusing trusted Microsoft…
continue reading..
