Vishing Scam Uses Teams & QuickAssist to Deploy .NET Malware
A new vishing attack uses social engineering and legitimate Microsoft tools to run commands and deploy multi-stage .NET malware. Researchers found that the attack starts when threat actors impersonate IT [...]
Android Users Hit as Hackers Push Triada via Ad Networks
Adex, an anti-fraud platform under AdTech Holding, has uncovered and shut down a long-running malware scheme tied to the Triada Trojan. The operation had been active for several years and [...]
Major Tech Brands to Roll Out Always-On GPS in India Soon
India is weighing a new rule that would force all smartphones to keep GPS-based location tracking active at all times. If this becomes law, users would not be able to [...]
2.15M Next.js sites are exposed and being attacked — update ASAP.
Security teams around the world are rushing to fix systems after a major React vulnerability was revealed: CVE-2025-55182, also called “React2Shell.” This flaw affects React Server Components (RSC) and has [...]
ArrayOS AG VPN Flaw Exploited for Webshell Attacks
A critical command injection vulnerability in Array Networks’ ArrayOS AG systems is being actively exploited, with confirmed attacks on Japanese organizations since August 2025. According to JPCERT/CC, attackers are using [...]