Cybersecurity News

The Crowded Battle: Key Insights from the 2025 State of Pentesting Report

Tue, 20 May 2025 16:30:00 +0530
The Hacker News

In the newly released 2025 State of Pentesting Report, Pentera surveyed 500 CISOs from global enterprises (200 from within the USA) to understand the strategies, tactics, and tools they use to cope with the thousands of security alerts, the persisting breaches and the growing cyber risks they have to handle. The findings reveal a complex picture of progress, challenges, and a shifting mindset

South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware

Tue, 20 May 2025 16:27:00 +0530
The Hacker News

High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder. "The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries received the malicious content," Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and Prakas

Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization

Tue, 20 May 2025 15:02:00 +0530
The Hacker News

Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker that targeted an unnamed international organization in Saudi Arabia with a previously undocumented backdoor dubbed MarsSnake. ESET, which first discovered the hacking group's intrusions targeting the entity in March 2023 and again a year later, said the activity leverages spear-phishing emails using

Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse

Tue, 20 May 2025 13:55:00 +0530
The Hacker News

Cybersecurity researchers are calling attention to a new Linux cryptojacking campaign that's targeting publicly accessible Redis servers. The malicious activity has been codenamed RedisRaider by Datadog Security Labs. "RedisRaider aggressively scans randomized portions of the IPv4 space and uses legitimate Redis configuration commands to execute malicious cron jobs on vulnerable systems,"

Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts

Tue, 20 May 2025 11:19:00 +0530
The Hacker News

Cybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to validate stolen email addresses against TikTok and Instagram APIs. All three packages are no longer available on PyPI. The names of the Python packages are below - checker-SaGaF (2,605 downloads) steinlurks (1,049 downloads) sinnercore (3,300 downloads)

RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer

Mon, 19 May 2025 21:18:00 +0530
The Hacker News

The official site for RVTools has been hacked to serve a compromised installer for the popular VMware environment reporting utility. "Robware.net and RVTools.com are currently offline. We are working expeditiously to restore service and appreciate your patience," the company said in a statement posted on its website. "Robware.net and RVTools.com are the only authorized and supported websites for

Ransomware Gangs Use Skitnet Malware for Stealthy Data Theft and Remote Access

Mon, 19 May 2025 20:08:00 +0530
The Hacker News

Several ransomware actors are using a malware called Skitnet as part of their post-exploitation efforts to steal sensitive data and establish remote control over compromised hosts. "Skitnet has been sold on underground forums like RAMP since April 2024," Swiss cybersecurity company PRODAFT told The Hacker News. "However, since early 2025, we have observed multiple ransomware operators using it

Why CTEM is the Winning Bet for CISOs in 2025

Mon, 19 May 2025 16:30:00 +0530
The Hacker News

Continuous Threat Exposure Management (CTEM) has moved from concept to cornerstone, solidifying its role as a strategic enabler for CISOs. No longer a theoretical framework, CTEM now anchors today’s cybersecurity programs by continuously aligning security efforts with real-world risk. At the heart of CTEM is the integration of Adversarial Exposure Validation (AEV), an advanced, offensive