Cyber Security

Cyber Security
Cyber Security

Stronger Incident Prevention Takes Just One CISO Decision

stronger-incident-prevention-takes-just-one-ciso-decision

There is a comforting illusion in cybersecurity leadership: when things get noisy, you add more people. More analysts. More shifts. More headcount. It feels decisive. It looks responsible. It even photographs well for internal reports.  But SOC inefficiency is rarely a staffing problem. It is a signal problem.  When More People Don’t Mean Better Security  Across industries, security […]

Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware

malicious-app-on-the-google-play-with-50k+-downloads-deploy-anatsa-banking-malware

A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users searching for legitimate file management tools. This discovery highlights how cybercriminals continue to exploit official […]

DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data

dynowiper-data-wiping-malware-attacking-energy-companies-to-destroy-data

A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. Unlike typical ransomware that encrypts files for monetary gain, DynoWiper operates with a single […]

New Punishing Owl Hacker Group Targeting Networks of Russian Government Security Agency

new-punishing-owl-hacker-group-targeting-networks-of-russian-government-security-agency

A previously unknown hacktivist group called Punishing Owl has emerged with sophisticated cyberattacks targeting Russian government security agencies. The group first surfaced on December 12, 2025, when it announced the successful breach of a Russian government security agency’s network. The attackers published stolen internal documents on a data leak site and duplicated the files on […]

Windows 11 New Security Feature Denies Unauthorized Access to System Files

windows-11-new-security-feature-denies-unauthorized-access-to-system-files

Microsoft has introduced a significant security control in the latest Windows 11 preview update designed to restrict unauthorized interaction with critical system files. Released as part of the January 2026 non-security preview (KB5074105), this enhancement specifically targets the Storage settings menu, a sensitive area of the operating system that reveals detailed information about drive usage, […]

Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

critical-johnson-controls-products-vulnerabilities-enables-remote-sql-injection-attacks

A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper neutralization of special elements used in command injection, allowing remote […]

Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys

moltbook-ai-vulnerability-exposes-email-addresses,-login-tokens,-and-api-keys

A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million “users.” Researchers revealed an exposed database misconfiguration allowing unauthenticated access to agent profiles, enabling bulk data extraction. This […]

AutoPentestX Automated Penetration Testing Toolkit Designed for Linux systems

autopentestx-automated-penetration-testing-toolkit-designed-for-linux-systems

AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional PDF reports while emphasizing safe, non-destructive testing. AutoPentestX targets Kali Linux, Ubuntu, and Debian-based distributions, automating OS detection, port scanning, service enumeration, and vulnerability checks. […]

Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

metasploit-releases-7-new-exploit-modules-covering-freepbx,-cacti-and-smartermail

The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules directed at FreePBX, alongside critical remote code execution (RCE) capabilities for Cacti and SmarterMail. This […]

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

uat-8099-targets-vulnerable-iis-servers-using-web-shells,-powershell,-and-region-customized-badiis

A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and Vietnam, marking a strategic shift toward region-specific operations. The attackers exploit unpatched […]