
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CISA flags critical Ray flaw, citing active exploitation. CVE-2025-62593 can lead to remote code execution via web browsers like Firefox and Safari.
Stories tagged “Threat Intelligence.”
30 stories

CISA flags critical Ray flaw, citing active exploitation. CVE-2025-62593 can lead to remote code execution via web browsers like Firefox and Safari.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. However, generative AI is collapsing that ranking, allowing attackers to close knowledge gaps and accelerate research.

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete.

A vulnerability in the Coldcard hardware wallet has been linked to a $70 million Bitcoin theft. The flaw was caused by a firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random n…

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025.

A Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. The agent found internet-facing systems and selected public exploits after an initial Telegram instruction.

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. The attack caused a plant outage, communications failures, or affected automated controls in sever…

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. Tengu supports 25 distributed denial-of-service (DDoS) methods and can also run a SOCKS5 proxy, execute shell commands,…

A critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation, allowing remote code execution and potential system compromise. Arista has released patches and provided indicators of compromise.

The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices insid…

Zscaler ThreatLabz has detailed a multi-stage cyber campaign by an East Asia-linked threat actor targeting Middle East governments using three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.

A China-nexus operation, tracked as JadeProx, has been targeting government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.

A previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT has been flagged by cybersecurity researchers. It masquerades as NVIDIA software to blend into target environments.

Microsoft has detailed three methods used by attackers, linked to ShinyHunters, to steal data from Salesforce over the past year. These attacks bypass traditional security by exploiting trusted connections rather than platform vulnerabilities.

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. The attack chain involved the threat actor establishing Remote Desktop Protocol (RDP) access onto a domain-…

Datadog Security Labs has warned of several overlapping campaigns that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. The campaigns employ a mix of automated scanner tools, over 50 dormant accounts, a…

A new threat actor, Lurking Lizard, has been operating a malicious residential proxy business since August 2022, using fake software installers to turn victim devices into proxy nodes.

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices.

A high-severity remote code execution (RCE) vulnerability in Microsoft SharePoint Server (CVE-2026-45659) has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, despite Microsoft's earlier "Exploitation Less Likely" assessment.

A new attack vector called 'phantom squatting' involves attackers registering non-existent domains that AI models hallucinate, then using them for phishing and malware distribution.

CISA warns Fortinet customers of a sweeping campaign targeting FortiGate appliances, with 86,644 devices compromised. The threat actor uses a bespoke tool to spray login and password combinations to break into devices.

Supply-chain attacks often have early warning signs in dark web forums and marketplaces, appearing as leaked access to GitHub, private repositories, or vendor data, which can expose critical credentials and internal system information before a public incident.

PRODAFT says The Gentlemen ransomware has claimed 478 victims since March 2025 and can spread rapidly across networks.

Researchers say JDY has grown into a 1,500-device botnet used for targeted reconnaissance and service fingerprinting across exposed systems.

PCPJack used hijacked cloud servers to build a covert SMTP relay network across AWS, Google Cloud, and Azure. Hunt.io says the infrastructure was still active and syncing verified proxies every five minutes.

Gamaredon is abusing a WinRAR flaw to launch a malware chain that delivers a worm and an info-stealer against Ukrainian targets.