Cybersecurity & Privacy
Iran’s ‘MuddyWater’ Levels Up With MuddyViper Backdoor The Iran-aligned cyberespionage group MuddyWater has evolved its tactics, employing new tools like the MuddyViper backdoor and Fooder loader for more stealthy operations. This shift from historically noisier methods indicates an increased focus on espionage and defense evasion, with potential collaboration observed with another Iran-aligned actor, Lyceum.
Korea arrests suspects selling intimate videos from hacked IP cameras Korean police have arrested four suspects for hacking over 120,000 IP cameras and selling the stolen intimate videos on an overseas adult website. Investigations are ongoing against the website’s operators and buyers, with authorities collaborating internationally to shut down the platform and prevent further harm to victims.
The search engine deceiver: how TrackMeNot hides your queries in a cloud of noise
Update note: TrackMeNot is no longer actively maintained—the last update was in November 2019. The extension still functions on Firefox and can be manually installed on Chromium browsers, but users should understand that unmaintained browser extensions pose security risks. Without ongoing updates, the extension won’t receive patches for newly discovered vulnerabilities or adapt to changes in browser APIs. If you choose to use TrackMeNot, you’re accepting these trade-offs in exchange for the obfuscation benefits it provides.
Your search history is a window into your soul. It reveals your fears, your ambitions, your health concerns, your political leanings, your midnight curiosities. Every query you type into Google, Bing, Yahoo, or DuckDuckGo gets logged, analyzed, and folded into an ever-expanding profile of who you are.
The ad blocker that fights back: why AdNauseam deserves your attention
When most people think about ad blockers, they picture a simple transaction: install the extension, ads disappear, browsing improves. But what if I told you there is an ad blocker that does more than hide from the surveillance economy — it actively sabotages it?
Meet AdNauseam, and prepare to have your assumptions about online privacy challenged.
Washington Post says it is among victims of cyber breach tied to Oracle software | Reuters The Washington Post has announced it is a victim of a cyber breach linked to Oracle software, specifically the Oracle E-Business Suite platform. This breach is attributed to the ransomware group CL0P, which has targeted numerous organizations using this Oracle software.
What’s That Coming Over The Hill? (Monsta FTP Remote Code Execution CVE-2025-34299) This article details a pre-authenticated Remote Code Execution vulnerability (CVE-2025-34299) found in Monsta FTP, a web-based FTP client. Despite attempts to patch, the vulnerability persisted in later versions until version 2.11.3 was released on August 26, 2025.
Vibe-coded ransomware proof-of-concept ended up on Microsoft’s marketplace | CSO Online A Visual Studio Code extension containing ransomware-style behavior and data-stealing capabilities, dubbed Ransomvibe, was successfully published to Microsoft’s marketplace. Despite containing obvious red flags like hardcoded credentials and decryption tools, the extension bypassed review and highlights a failure in Microsoft’s marketplace security.
Cisco fixes critical UCCX flaw allowing Root command execution Cisco has addressed a critical vulnerability (CVE-2025-20354) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute commands with root privileges. The flaw stems from improper authentication in the Java RMI process, enabling unauthenticated attackers to upload files and run commands on affected systems.
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation Nine malicious NuGet packages have been discovered, containing logic bombs set to detonate in August 2027 and November 2028, targeting database operations and industrial control systems. The packages, published by user “shanhai666” and collectively downloaded nearly 9,500 times, employ sophisticated techniques to disguise attacks as random failures, making incident response extremely difficult.
Fake 0-Day Exploit Emails Trick Crypto Users Into Running Malicious Code – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More A new cryptocurrency scam uses fake 0-day exploit emails to trick users into running malicious JavaScript code, leading them to believe they can achieve massive profits. The attackers manipulate the user’s browser to display inflated payouts and hijack transactions, directing funds to their own crypto wallets.