Aggregator
11,000 Android Devices Hacked by Chinese Threats Actors to Deploy PlayPraetor Malware
A sophisticated malware-as-a-service operation orchestrated by Chinese-speaking threat actors has successfully compromised over 11,000 Android devices worldwide through the deployment of PlayPraetor, a powerful Remote Access Trojan designed for on-device fraud. The campaign represents a significant escalation in mobile banking malware operations, with the botnet expanding at an alarming rate of over 2,000 new infections […]
The post 11,000 Android Devices Hacked by Chinese Threats Actors to Deploy PlayPraetor Malware appeared first on Cyber Security News.
CVE-2025-54418
What the Top 20 OSS Vulnerabilities Reveal About the Real Challenges in Security Governance
CVE-2019-2413 | Oracle Reports Developer 12.2.1.3 OpenSSL access control (EDB-46187 / BID-106603)
CVE-2019-10685 | Heidelberg Prinect Archiver 1.0 Reflected cross site scripting (EDB-46804)
CVE-2019-2861 | Oracle Hyperion Planning 11.1.2.4 Security access control (EDB-47196)
CVE-2019-5893 | Nelson Open Source ERP 6.3.1 db/utils/query/data.xml Query sql injection (EDB-46118)
CVE-2019-11013 | Nimble Streamer up to 3.0.4-9 on WordPress path traversal (ID 154196 / EDB-47301)
银狐黑产组织相关攻击技术汇总-上
Why Legal Woes Continue to Mount Over Health Data Trackers
Noma Raised $100M to Expand Agentic AI Security Platform
With agentic AI deployments accelerating, Noma Security’s $100 million Series B will fuel development of risk management and runtime protection features. CEO Niv Braun said demand for securing agentic AI has surged among Fortune 500 firms and healthcare and financial institutions.
Genomics Gear Firm Pays $9.8M to Settle False Cyber Claims
Genomics sequencing firm Illumina Inc. has agreed to pay $9.8 million to resolve False Claims Act whistleblower allegations that it sold software and systems containing cybersecurity vulnerabilities over more than seven years to government agencies.
Safe Raises $70M Series C to Scale Cyber Risk Management
Safe's $70 million Series C will fund expanded capabilities across its cyber risk quantification, exposure management and third-party oversight tools. The company says its agentic AI vision – cyber AGI – will transform how enterprises manage and mitigate cyberthreats.
ISMG Editors: ToolShell Exploit Blurs Crime and Espionage
In this week's update, four ISMG editors discussed the latest on the ToolShell exploit and the rise of Warlock ransomware, why IT-OT integration may not be the best answer for industrial security and what to expect next week from ISMG Studio at Black Hat Conference 2025.
Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks
Cybercriminals have discovered a sophisticated new attack vector by exploiting Microsoft 365’s Direct Send feature to deliver phishing campaigns that masquerade as legitimate internal communications. This emerging threat leverages a legitimate Microsoft service designed for multifunction printers and legacy applications, turning it into a weapon for social engineering attacks that bypass traditional email security controls. […]
The post Hackers Abuse Microsoft 365’s Direct Send Feature to Deliver Internal Phishing Attacks appeared first on Cyber Security News.