News & Updates

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems.
The tech giant, in an update shared Wednesday, said the findings are based on an “expanded analysis and threat intelligence from our continued monitoring of exploitation activity by Storm-2603.”
The threat actor attributed to the financially
News & Updates

Imperva Customers Protected Against Critical “ToolShell” Zero‑Day in Microsoft SharePoint

A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, is under active exploitation in the wild. The vulnerability, with a CVSS score of 9.8, impacts on-premises SharePoint Server 2016, 2019, and Subscription Edition, and allows unauthenticated remote code execution (RCE). Microsoft issued patches as part of its July 2025 Patch Tuesday update, but attackers […]

The post Imperva Customers Protected Against Critical “ToolShell” Zero‑Day in Microsoft SharePoint appeared first on Blog.

News & Updates

Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace

Europol on Monday announced the arrest of the suspected administrator of XSS.is (formerly DaMaGeLaB), a notorious Russian-speaking cybercrime platform.
The arrest, which took place in Kyiv, Ukraine, on July 222, 2025, was led by the French Police and Paris Prosecutor, in collaboration with Ukrainian authorities and Europol. The action is the result of an investigation that was launched by the
News & Updates

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week CrushFTP warned of a zero-day, tracked as CVE-2025-54309 (CVSS score of 9.0), […]
News & Updates

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access

Cybersecurity researchers have uncovered a new stealthy backdoor concealed within the “mu-plugins” directory in WordPress sites to grant threat actors persistent access and allow them to perform arbitrary actions.
Must-use plugins (aka mu-plugins) are special plugins that are automatically activated on all WordPress sites in the installation. They are located in the “wp-content/mu-plugins”
Cybersecurity Tools

Banana Pro Hits $124.5M Weekly Volume as Meme Trading Goes Mainstream With Real-Time Tools and Built-In Rewards

Meme coin trading is no longer just a trend—it’s evolving into a full-scale movement with serious traction. In a market flooded with hype and volatility, Banana Pro has emerged as a breakout star, recording a staggering $124.5K in weekly trading volume. As the demand for streamlined, user-friendly crypto tools rises, Banana Pro stands out by […]

The post Banana Pro Hits $124.5M Weekly Volume as Meme Trading Goes Mainstream With Real-Time Tools and Built-In Rewards appeared first on SecureBlitz Cybersecurity.

Exit mobile version