Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republ… Continue reading Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Posted in Uncategorized

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.

According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishi… Continue reading HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Posted in Uncategorized

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.

Researchers named the operation Fuyao and att… Continue reading Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Posted in Uncategorized

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.

Both versions were released last month. In its la… Continue reading Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Posted in Uncategorized

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize … Continue reading Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Posted in Uncategorized

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing w… Continue reading Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Posted in Uncategorized