Malware

Trojans, spyware, stalkerware, and RATs.

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw
Malware

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw

US Cyber Security and Infrastructure Security Agency (CISA) has directed all federal agencies to patch a critical vulnerability in Oracle WebLogic Server. The flaw poses significant security risks and could be exploited by threat actors to compromise government systems. WebLogic Server, widely used for business applications, requires immediate patching to prevent potential attacks. The directive mandates agencies complete patching within specified timeframes as part of critical infrastructure protection measures. Organizations running WebLogic Server deployments should prioritize applying available security updates to mitigate exploitation risks. Source: SC Media.

via GoogleNews: vulnerability CVERead source
Password Stealer Attacks Surge 20%, Threatening Indian Business Data
Malware

Password Stealer Attacks Surge 20%, Threatening Indian Business Data

Kaspersky reports a concerning 20% increase in password stealer attacks targeting Indian businesses, putting corporate credentials at significant risk. These malicious tools are designed to extract login information from employees' systems, enabling unauthorized access to sensitive business accounts and data. The surge highlights growing threats to organizational cybersecurity infrastructure across India. Businesses are advised to implement robust security measures, including multi-factor authentication, regular password updates, and employee security awareness training. IT teams should monitor network activity for suspicious behavior and deploy advanced threat detection solutions. This trend underscores the importance of proactive credential protection strategies for enterprises operating in India's digital ecosystem. Source: Deccan Herald.

via GoogleNews: ransomware IndiaRead source
US Agencies Warn of Cyber Attacks on Tank Gauge Systems
Malware

US Agencies Warn of Cyber Attacks on Tank Gauge Systems

US cybersecurity authorities, including CISA, FBI, NSA, and other agencies, have identified malicious cyber activity targeting automatic tank gauge (ATG) systems used across energy, chemical, food, agriculture, and transportation sectors in America. These systems monitor fuel levels, temperature, and detect leaks in storage tanks. Attackers are exploiting vulnerabilities through authentication bypass, hardcoded credentials, and command execution to compromise internet-exposed ATG systems. The agencies recommend operators secure systems with strong passwords and disconnect them from the internet to minimize exposure. The attack source remains unattributed to any specific nation-state or threat group. Source: CISA.

via RSS: CISA AlertsRead source
CISA Lists Two Active Exploited Vulnerabilities
Malware

CISA Lists Two Active Exploited Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has identified two vulnerabilities actively exploited by attackers: CVE-2022-0492 affecting Linux Kernel authentication and CVE-2025-48595 impacting Android Framework. These have been added to CISA's Known Exploited Vulnerabilities catalog, which tracks threats to critical infrastructure. While mandatory remediation applies to US federal agencies under Binding Operational Directive 22-01, CISA recommends all organizations prioritize patching these vulnerabilities to reduce cyberattack exposure. The catalog serves as a living resource for vulnerability management practices globally. Source: CISA.

via RSS: CISA AlertsRead source
WhatsApp Scam 2025 ❌ ये इमेज डाउनलोड की और अकाउंट साफ | Cyber Fraud | Steganography
8:35
Malware

WhatsApp Scam 2025 ❌ ये इमेज डाउनलोड की और अकाउंट साफ | Cyber Fraud | Steganography

mybigguide

अप्रैल 2025 में एक मध्य प्रदेश निवासी रमेश कुमार के साथ हुए एक WhatsApp स्कैम ने यह साबित कर दिया है कि एक साधारण फोटो डाउनलोड करना कितना खतरनाक हो सकता है। रमेश ने अनजान नंबर से आई एक गुमशुदा महिला की तस्वीर डाउनलोड की, जिसके बाद उनके खाते से ₹2 लाख की राशि चोरी हो गई। यह साइबर अपराध स्टेग्नोग्राफी तकनीक का उपयोग करके किया गया, जिसमें बिना ओटीपी या पासवर्ड के, केवल एक फोटो डाउनलोड करने से हैकर्स ने उनके बैंकिंग विवरण तक पहुँच प्राप्त कर ली। इसके बचाव के लिए अनजान नंबरों से आती फाइलों को डाउनलोड न करना, जानकारी के बिना फाइलें खोलना, और यदि संदेह हो तो तुरंत फोन का डेटा ऑफ करना आवश्यक है। अनुभव में, यदि किसी का फोन हैक हो जाता है तो उन्हें तुरंत साइबर क्राइम सेल में रिपोर्ट करनी चाहिए और अपने सभी पासवर्ड तत्काल बदलने चाहिए। एक मजबूत एंटीवायरस एप्लिकेशन भी उपयोग करना चाहिए।