Author: AmbreenChaudhary

A newly uncovered phishing campaign is targeting employees in the hospitality sector by impersonating Booking.com, one of the world’s largest online travel agencies. At the heart of the campaign is a clever trick called ClickFix—a social engineering tactic that convinces users to execute malware on their own systems. First detected in December 2024, the campaign has been traced to a threat actor Microsoft tracks as Storm-1865, and its impact has stretched across North America, Europe, Oceania, and Southeast Asia. The goal? Steal login credentials, plant malware, and commit financial fraud. A Simple Email, a Fake Review, and a Deceptive Link…

Read More

This week’s global cybersecurity roundup shows just how fast things are moving on both sides of the cyber battlefield. On one end, threat actors are breaking into outdated routers, sneaking into app stores, and spreading malware through trusted platforms like YouTube and GitHub. On the other end, researchers are building new decryptors, governments are pressing charges, and security vendors are tightening controls. Here’s your in-depth look at the stories shaping cyber defense and offense for March 2025. China-Linked UNC3886 Breaches End-of-Life Juniper Routers Old routers are still powering networks—and attackers know it One of the biggest threats this week came…

Read More

A severe Windows zero-day vulnerability, active since at least 2017, is being used by state-backed hackers from North Korea, China, Iran, and Russia. Despite its long-running exploitation across various industries and nations, the flaw still remains unpatched. Tracked as ZDI-CAN-25373 by Trend Micro’s Zero Day Initiative (ZDI), the flaw allows attackers to use specially crafted .LNK files — commonly known as Windows shortcuts — to run harmful commands without alerting the user. What’s more troubling is that Microsoft has classified it as low priority and has no immediate plans to fix it. A Silent Danger Hidden in Everyday Files How…

Read More

Cybercriminals have found a clever new way to distribute malware by uploading fake game cheat videos to YouTube, aimed at Russian-speaking users. These videos lead unsuspecting players to download password-protected files that hide a stealthy malware known as Arcane, a powerful stealer designed to collect a wide range of sensitive data. This new threat highlights how attackers continue to evolve, using popular platforms and interests like gaming to slip past defenses and infect devices silently. A Dangerous Setup Behind Game Cheat Promises Malware Hidden in Cheat Downloads The infection starts with a simple YouTube video promising free cheats or hacks…

Read More

A new cybercrime toolkit named VanHelsing is quickly making headlines in the digital underground. First spotted in early March 2025, this ransomware service already counts three victims and appears to be gathering momentum fast. VanHelsing is part of a growing trend where cybercriminals no longer need to build malware from scratch. Instead, they can buy access to full-featured ransomware platforms, complete with payment systems, attack controls, and a business model designed to split profits. A Ransomware Platform for Cybercriminal Entrepreneurs How the Affiliate Structure Works The VanHelsing platform operates like a franchise system for cybercrime. Affiliates, once accepted, can launch…

Read More

In a shocking revelation, cybersecurity firm Sygnia has reported that a major Asian telecommunications company was compromised by a group of Chinese state-sponsored hackers. This long-term breach, carried out by a group identified as Weaver Ant, allowed the attackers to quietly operate within the network for over forty eight months, collecting sensitive information without being detected. Although the name of the affected telecom provider has not been disclosed, the implications are significant, highlighting the evolving strategies and persistence of modern cyber espionage operations. Weaver Ant — A Stealthy and Persistent Threat Actor Sygnia describes Weaver Ant as a stealth-focused, highly…

Read More

Cybercriminals are weaponizing a tool called Atlantis AIO Multi-Checker to launch credential stuffing attacks on a massive scale. According to a new analysis by Abnormal Security, this tool is empowering attackers to test millions of stolen credentials quickly and efficiently across more than one hundred forty platforms. Credential stuffing involves using stolen usernames and passwords to gain unauthorized access to user accounts on unrelated systems. Unlike brute force attacks that attempt to guess passwords, credential stuffing depends on large lists of pre-compromised credentials, often acquired through previous data breaches or purchased from underground marketplaces. What Is Atlantis AIO and Why…

Read More

On February 6, 2025, the Government of Canada unveiled its latest National Cyber Security Strategy (NCSS), reinforcing its commitment to protecting individuals, businesses, and critical infrastructure from digital threats. This new strategy builds on its 2018 predecessor, which established key institutions like the Canadian Centre for Cyber Security and the National Cybercrime Coordination Unit (NCCU) under the RCMP. The updated version intensifies the fight against cyber threats by fostering collaborations, investments in innovation, and stronger cyber threat detection and disruption mechanisms. A Holistic Approach to Cybersecurity The 2025 NCSS is driven by two key principles: Three Key Pillars of the NCSS The strategy is built around three main pillars, each…

Read More