Rising Browser-Based Attacks Threaten Business Apps and DataCybersecurity researchers warn of a sharp increase in browser-based attacks, with threat actors shifting their focus from endpoints and email to the web browsers where modern business apps live. What Are Browser-Based Attacks? Browser-based attacks d...Sep 19, 2025·2 min read
Apple Backports Critical Security Fixes for Actively Exploited ImageIO FlawApple on Monday released backported security updates to address a recently discovered flaw that has been actively exploited in the wild. The vulnerability, CVE-2025-43300 (CVSS score: 8.8), is an out-of-bounds write issue in the ImageIO component. If...Sep 19, 2025·2 min read
New FileFix Campaign Delivers StealC Malware via Sophisticated PhishingCybersecurity experts have uncovered a new campaign leveraging a variant of the FileFix social engineering tactic to deliver the StealC information-stealer malware. Acronis security researcher Eliad Kimhy explained, "The campaign uses highly convinci...Sep 19, 2025·2 min read
SlopAds Ad Fraud Hits 38M Downloads Across 228 CountriesCybersecurity researchers have uncovered a massive ad fraud operation dubbed SlopAds, which ran a cluster of 224 Android apps and racked up 38 million downloads across 228 countries and territories. According to HUMAN’s Satori Threat Intelligence and...Sep 19, 2025·2 min read
Critical Chaos Mesh Vulnerabilities Could Enable Kubernetes Cluster TakeoverCybersecurity researchers have disclosed several critical vulnerabilities in Chaos Mesh, an open-source cloud-native Chaos Engineering platform, that could allow attackers to take over Kubernetes clusters. According to JFrog, an attacker with minimal...Sep 19, 2025·2 min read
Microsoft Seizes 338 Domains Linked to RaccoonO365 Phishing ServiceMicrosoft’s Digital Crimes Unit (DCU) announced a coordinated effort with Cloudflare to seize 338 domains tied to RaccoonO365, a financially motivated threat group behind a phishing-as-a-service (PhaaS) toolkit. The tool had stolen over 5,000 Microso...Sep 19, 2025·2 min read
BreachForums Admin Resentenced to 3 Years Over CSAM and CybercrimeThe U.S. Department of Justice (DoJ) on Tuesday resentenced Conor Brian Fitzpatrick, former administrator of BreachForums, to three years in prison for his role in running the cybercrime forum and possessing child sexual abuse material (CSAM). Fitzpa...Sep 19, 2025·2 min read