Aggregator
Ensuring Data Integrity in Incident Response
Weaponized Python Package Termncolor Attacking Leverages Windows Run Key to Maintain Persistence
A sophisticated supply chain attack targeting Python developers has emerged through a seemingly innocuous package named termncolor, which conceals a multi-stage malware operation designed to establish persistent access on compromised systems. The malicious package, distributed through the Python Package Index (PyPI), masquerades as a legitimate terminal color utility while secretly deploying advanced backdoor capabilities that […]
The post Weaponized Python Package Termncolor Attacking Leverages Windows Run Key to Maintain Persistence appeared first on Cyber Security News.
CVE-2025-8361 | Config Pages up to 2.17.x on Drupal improper authorization (trib-2025-093)
CVE-2025-8092 | COOKiES Consent Management up to 1.2.15 on Drupal cross site scripting (sa-contrib-2025-092)
CVE-2025-7961 | Wulkano KAP 3.6.0 on macOS code injection
CVE-2025-8066 | Bunkerity Bunker Web 1.6.2 on Linux redirect (EUVD-2025-25039)
Noodlophile 恶意软件借版权钓鱼诱饵扩大全球影响力
【安全圈】Manpower与Workday相继披露数据泄露事件
【安全圈】PipeMagic:新型模块化后门被用于跨区域攻击
【安全圈】黑客利用 Telegram 进行数据窃取
【安全圈】PayPal千万账号遭泄露
提示词中间人攻击:ChatGPT 等 AI 工具的隐形威胁
Finding Relevant Alerts, Events and Logs
PolarD&N(WEB简单全解)
超 870 台N-able服务器未修补关键漏洞,CISA 证实已遭利用
XenoRAT 恶意软件活动袭击多个驻韩大使馆
Threats Actors Using Telegram as The Communication Channel to Exfiltrate The Stolen Data
Cybersecurity researchers have identified an alarming trend where threat actors are increasingly leveraging Telegram’s Bot API infrastructure as a covert communication channel for data exfiltration. This sophisticated attack methodology combines traditional phishing techniques with legitimate messaging services to bypass conventional security controls and establish persistent command-and-control operations. The malicious campaigns utilize fake login pages crafted […]
The post Threats Actors Using Telegram as The Communication Channel to Exfiltrate The Stolen Data appeared first on Cyber Security News.