2025-09-23 09:20 UTC
Other
Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC
1. Introduction The vibe coding revolution has empowered millions to build and deploy websites using natural languages. Entrepreneurs, artists, and small businesses can now bring their ideas to life online without writing a single line of code. But has this convenience come at a hidden security cost? In this post, we present the 15th wave of Project Resonance: A RedHunt Labs Research Initiative, investigating the security posture of websites built on modern “vibe coding” platforms. Our research…
P0
2025-09-23 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn the truth about SAT effectiveness. Our latest report reveals why increased spending on training isn’t reducing human risk—and how to fix it.
P0
2025-09-22 11:45 UTC
Other
Buf0rd Blog · indexed 2026-08-16 11:15 UTC
All packages were updated successfully.
P0
2025-09-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn more about what it actually means to go up against hackers–and why creative, human-led investigations are essential for keeping your organization safe from modern threats.
P0
2025-09-18 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Malicious hackers are impersonating IT and cybersecurity professionals to infiltrate your systems and steal sensitive data. Learn how to identify and defend against these insider threats and protect your organization from "fake workers."
P0
2025-09-17 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The blog provides an in-depth look at MuddyWater’s evolution in tooling, targeting, and infrastructure management, suggesting a more mature and capable advanced persistent threat within the META region.
P0
2025-09-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The …
P10
2025-09-15 17:01 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…
P10
2025-09-15 05:44 UTC
Other
Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC
In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…
P25
2025-09-10 15:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA Content Credentials in Pixel Camera and Google Photos. This announcement represents a series of steps towards greater digital media transparency: The Pixel 10 lineup is the first to have Content Credentials built in across every photo created by Pixel Camera. The Pixel Camera app achie…
P0
2025-09-09 14:50 UTC
Other
Black Lantern Security · Kyle Griffin · indexed 2026-09-07 17:30 UTC
CVE-2025-10183
P5
2025-09-09 05:54 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
Introduction A new wave of AI-powered investment scams is targeting Indian users on Facebook and Instagram, luring them with fake celebrity endorsements and deepfake interviews. Ads featuring figures like Nirmala Sitharaman, Sadhguru, and Neha Kakkar promote fraudulent schemes, directing users to counterfeit news websites mimicking The Times of India, IndiaTime, and NDTV. These sites claim celebrities have built fortunes using exclusive investment strategies, persuading victims to deposit ₹21,0…
P0
2025-09-09 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
An attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies.
P0
2025-09-05 08:31 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-09-03 07:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI in cybercrime is evolving fast, fueling AI phishing attacks, AI scam calls, AI voice cloning scams, and even AI deepfake scams. From Dark LLMs to next-gen AI phishing tactics, we break down how criminals exploit AI today and what you can do to stay protected.
P0
2025-09-02 19:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress found a previously unseen ransomware variant called Obscura on a victim company’s domain controller.
P15
2025-09-02 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.
P0
2025-08-29 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.
P0
2025-08-27 07:50 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog describes attacks on victims in Central Asia and APAC. Research into the attack has identified a group also called YoroTrooper. We also identified profiles of attackers on hacker forums, their malicious web-panels, test infections of attackers' own machines, and screenshots of attackers' desktops.
P0
2025-08-27 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress researchers take a tour through the dark web, from innovative threat actor marketing techniques to cybercrime drama on BreachForums.
P0
2025-08-26 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers are using Google Gemini's email summaries to sneak in phishing attacks without links or attachments.
P0
2025-08-26 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 26 août 2025, Citrix a publié un bulletin de sécurité (cf. section Documentation) concernant, entre autres, la vulnérabilité CVE-2025-7775. Celle-ci permet une exécution de code arbitraire à distance et affecte toutes les versions de Citrix NetScaler ADC et NetScaler Gateway, dans certaines...
P5
2025-08-25 09:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The most widely used email security tools still focus on yesterday’s threats. Meanwhile, attackers have moved on. By hijacking legitimate business relationships and embedding infostealers in familiar-sounding, well-written emails, cybercriminals bypass conventional defenses. The only way to keep up is by using a behavioral approach.
P0
2025-08-25 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Celebrate 10 years of wrecking hackers! See how Huntress has evolved and elevated in an ever-changing cybersecurity landscape, shaped by key milestones and critical lessons.
P0
2025-08-21 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In mid-August, Huntress saw two incidents that linked back to a ransomware variant called Cephalus, which included DLL sideloading via a legitimate SentinelOne executable.
P15
2025-08-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Dataform could have allowed a malicious customer to gain unauthorized cross-tenant access to other customer's code repositories and data. By preparing a maliciously crafted package.json file, an attacker could exploit a path traversal vulnerability in the npm package installation process, thereby gaining read and write access in other customers' repositories. According to Google, there was no evidence of exploitation in the wild.
P20
2025-08-20 06:44 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how mule operators evolved in META-region banks—from IP masking to Starlink tactics with advanced GPS spoofing, SIM abuse, and device muling—and how layered fraud detection strategies fought back.
P0
2025-08-19 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.
P15
2025-08-15 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn the top data breach statistics of the last several years and learn about common causes, how they vary by industry, and future trends.
P0
2025-08-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.
P15