New Banshee Stealer Variant Bypasses Antivirus with Apple’s XProtect-Inspired Encryption https://firewall.firm.in/wp-content/uploads/2025/01/macos.png Jan 09, 2025Ravie Lakshmanan Cybersecurity researchers have uncovered a new, stealthier version of a macOS-focused information-stealing malware called Banshee Stealer. “Once thought dormant after its source code leak in late 2024, this new iteration introduces advanced string encryption inspired by Apple’s XProtect,” Check Point Research said in a new ...
Read More »Vulnerabilities & Exploits
Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections
Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections https://firewall.firm.in/wp-content/uploads/2025/01/phishing.png Cybersecurity researchers have found that bad actors are continuing to have success by spoofing sender email addresses as part of various malspam campaigns. Faking the sender address of an email is widely seen as an attempt to make the digital missive more legitimate and get past security ...
Read More »Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks
Mirai Botnet Variant Exploits Four-Faith Router Vulnerability for DDoS Attacks https://firewall.firm.in/wp-content/uploads/2025/01/router-ddos.png Jan 08, 2025Ravie LakshmananMalware / Vulnerability A Mirai botnet variant has been found exploiting a newly disclosed security flaw impacting Four-Faith industrial routers since early November 2024 with the goal of conducting distributed denial-of-service (DDoS) attacks. The botnet maintains approximately 15,000 daily active IP addresses, with the infections primarily ...
Read More »Farewell to the Fallen: The Cybersecurity Stars We Lost Last Year
Farewell to the Fallen: The Cybersecurity Stars We Lost Last Year https://firewall.firm.in/wp-content/uploads/2025/01/main.gif It’s time once again to pay our respects to the once-famous cybersecurity solutions whose usefulness died in the past year. The cybercriminal world collectively mourns the loss of these solutions and the easy access they provide to victim organizations. These solutions, though celebrated in their prime, succumbed to ...
Read More »Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers
Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers https://firewall.firm.in/wp-content/uploads/2025/01/dna.png Jan 07, 2025Ravie LakshmananFirmware Security / Malware Cybersecurity researchers have uncovered firmware security vulnerabilities in the Illumina iSeq 100 DNA sequencing instrument that, if successfully exploited, could permit attackers to brick or plant persistent malware on susceptible devices. “The Illumina iSeq 100 used a very outdated implementation of ...
Read More »From $22M in Ransom to +100M Stolen Records: 2025’s All-Star SaaS Threat Actors to Watch
From $22M in Ransom to +100M Stolen Records: 2025’s All-Star SaaS Threat Actors to Watch https://firewall.firm.in/wp-content/uploads/2025/01/wing.png In 2024, cyber threats targeting SaaS surged, with 7,000 password attacks blocked per second (just in Entra ID)—a 75% increase from last year—and phishing attempts up by 58%, causing $3.5 billion in losses (source: Microsoft Digital Defense Report 2024). SaaS attacks are increasing, with ...
Read More »⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan] https://firewall.firm.in/wp-content/uploads/2025/01/recap.png Jan 06, 2025Ravie Lakshmanan Every tap, click, and swipe we make online shapes our digital lives, but it also opens doors—some we never meant to unlock. Extensions we trust, assistants we rely on, and even the codes we scan are turning into tools for attackers. The line ...
Read More »India Proposes Digital Data Rules with Tough Penalties and Cybersecurity Requirements
India Proposes Digital Data Rules with Tough Penalties and Cybersecurity Requirements https://firewall.firm.in/wp-content/uploads/2025/01/india-data.png Jan 06, 2025Ravie LakshmananRegulatory Compliance / Data Privacy The Indian government has published a draft version of the Digital Personal Data Protection (DPDP) Rules for public consultation. “Data fiduciaries must provide clear and accessible information about how personal data is processed, enabling informed consent,” India’s Press Information Bureau ...
Read More »U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns
U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns https://firewall.firm.in/wp-content/uploads/2025/01/china-usa.png Jan 04, 2025Ravie LakshmananCyber Espionage / IoT Botnet The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday issued sanctions against a Beijing-based cybersecurity company known as Integrity Technology Group, Incorporated for orchestrating several cyber attacks against U.S. victims. These attacks have been publicly attributed to a Chinese ...
Read More »Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution
Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution https://firewall.firm.in/wp-content/uploads/2025/01/attack.gif Jan 04, 2025Ravie LakshmananVulnerability / Software Security A high-severity security flaw has been disclosed in ProjectDiscovery’s Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass signature checks and potentially execute malicious code. Tracked as CVE-2024-43405, it carries a CVSS score of 7.4 out ...
Read More »