Aggregator
CVE-2025-52620 | HCL BigFix SaaS Remediate up to 8.1.13 SaaS Authentication Service cross site scripting (KB0123330 / EUVD-2025-25054)
CVE-2025-8995 | Authenticator Login up to 2.1.3 on Drupal authentication bypass (sa-contrib-2025-096 / EUVD-2025-25044)
CVE-2025-8959 | HashiCorp go-getter up to 1.7.7 link following (EUVD-2025-25049)
DoJ Seizes $2.8 Million in Crypto From Zeppelin Ransomware Operators
The U.S. Department of Justice (DoJ) announced the seizure of over $2.8 million in cryptocurrency, $70,000 in cash, and a luxury vehicle linked to Zeppelin ransomware operations. The warrants were unsealed on August 14, 2025, in federal courts across Virginia, California, and Texas. Authorities allege that the assets belong to Ianis Aleksandrovich Antropenko, who has […]
The post DoJ Seizes $2.8 Million in Crypto From Zeppelin Ransomware Operators appeared first on Cyber Security News.
How Threat Actors Persist In Your Microsoft 365
MDR to IR Handoffs: Stick The Landing
Ensuring Data Integrity in Incident Response
Weaponized Python Package Termncolor Attacking Leverages Windows Run Key to Maintain Persistence
A sophisticated supply chain attack targeting Python developers has emerged through a seemingly innocuous package named termncolor, which conceals a multi-stage malware operation designed to establish persistent access on compromised systems. The malicious package, distributed through the Python Package Index (PyPI), masquerades as a legitimate terminal color utility while secretly deploying advanced backdoor capabilities that […]
The post Weaponized Python Package Termncolor Attacking Leverages Windows Run Key to Maintain Persistence appeared first on Cyber Security News.