Broadcom Warns VMware Users of Critical Zero-Day Exploits

Broadcom has issued a security alert warning VMware customers about three zero-day vulnerabilities attackers are actively exploiting in the wild. The flaws – CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 – impact VMware ESX products, including VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform.  The VMware Nightmare: What You Need …

Typosquatted Go Packages Distribute Malware Loader Targeting Linux and macOS

Researchers from Socket have identified an ongoing campaign involving at least seven typosquatted Go packages. These packages impersonate well-known Go libraries and are designed to deploy loader malware on Linux and macOS systems.   Typosquatted packages are malicious software components designed to mimic the names of popular, legitimate packages. In the …

Silk Typhoon Targets IT Supply Chain in Evolving Cyber Campaign

Microsoft Threat Intelligence has warned of a shift in tactics by Silk Typhoon, a Chinese espionage group that is now exploiting vulnerabilities in common IT solutions—including remote management tools and cloud applications—to gain initial access to target entities.   The software giant says it has not observed direct attacks against its …

Mad, Bad, and Dangerous to Know: Cybercriminals are More Sophisticated than Ever 

Cybercriminals are more sophisticated than ever, a new report from CrowdStrike reveals. Breakout times are falling, social engineering is becoming more common and effective, and cyber espionage – particularly that originating in China – is growing increasingly aggressive.   “Our latest research demonstrates that adversaries are becoming more efficient, focused, and …

Expert Q&A: How To Safely Turn AI Into Your Security Ally

Admins are in a tough position right now. Enterprise ecosystems are expanding, role responsibilities are growing, and hackers are getting smarter. Rather than viewing AI as another potential vulnerability, Hexnode CEO Apu Pavithran argues that admins must embrace it as a powerful ally. In this exclusive interview with Information Security …

Google Issues Urgent Alert for Exploited Android Vulnerabilities

Google has issued an urgent security alert addressing two critical Android vulnerabilities, CVE-2024-43093 and CVE-2024-50302, which are actively being exploited in coordinated attacks targeting devices running Android versions 12 through 15.   The vulnerabilities, patched in the March 2025 Android Security Bulletin (security patch level 2025-03-05), could allow malicious actors to …

Attackers Target Over 4000 IP Addresses of US, China ISPs

The Splunk Threat Research Team has uncovered a widespread cyber campaign targeting Internet Service Provider (ISP) infrastructure providers on the West Coast of the United States and in China. Over 4,000 ISP-related IPs were explicitly targeted in this campaign.  The attack, believed to have originated from Eastern Europe, uses brute-force …