Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Emerging DOGE Big Balls ransomware campaign leverages multi-stage tooling and BYOVD exploits

10 May 2025  |  securebulletin.com  |  Ransomware

A recent analysis of newly discovered payloads linked to the DOGE Big Balls ransomware operation reveals a complex infection chain combining open-source tools, kernel-level exploits, and psychological warfare....

>> read more

Malicious npm packages hijack macOS Cursor AI IDE

9 May 2025  |  securebulletin.com  |  Vulnerability

The Socket Threat Research Team has uncovered a sophisticated supply chain attack targeting macOS developers using the Cursor AI code editor. Three malicious npm packages-sw-cur, sw-cur1, and aiide-cur-have...

>> read more

Stealthy Linux backdoor leveraging residential proxies and NHAS reverse SSH

4 May 2025  |  securebulletin.com  |  Vulnerability

A recently discovered Linux backdoor (SHA256: ea41b2bf1064efcb6196bb79b40c5158fc339a36a3d3ddee68c822d797895b4e) employs advanced evasion techniques to bypass detection while establishing persistent access via SOCKS5 proxies and in-memory payload execution. This analysis breaks...

>> read more

US indicts Black Kingdom ransomware operator: technical analysis of ProxyLogon exploitation and law enforcement response

3 May 2025  |  securebulletin.com  |  Ransomware

The U.S. Department of Justice unsealed charges against Yemeni national Rami Khaled Ahmed (36) for deploying Black Kingdom ransomware via ProxyLogon exploits (CVE-2021-26855) against 1,500+ systems, including U.S....

>> read more

Sophisticated npm malware campaign exploits Cross-Ecosystem typosquatting

3 May 2025  |  securebulletin.com  |  Malware

A coordinated malware operation targeting npm employs cross-ecosystem typosquatting to mimic popular libraries from Python, Java, C++, and .NET ecosystems. Attackers uploaded packages like beautifulsoup4 (masquerading as Python’s...

>> read more

Dismantling “764”: inside the takedown of a sophisticated child exploitation network

1 May 2025  |  securebulletin.com  |  Cybercrime

In a significant development for cybersecurity and child protection efforts, law enforcement agencies have successfully apprehended two key figures allegedly behind “764,” a highly organized online child exploitation...

>> read more

Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels

1 May 2025  |  securebulletin.com  |  Spyware

In the ever-evolving landscape of cybersecurity, attackers are increasingly exploiting trusted services to establish covert command-and-control (C2) channels. By leveraging platforms like Gmail and Google Drive, threat actors...

>> read more

Kintetsu World Express ransomware attack: technical overview and response

30 April 2025  |  securebulletin.com  |  Ransomware

Kintetsu World Express (KWE), a major Japanese global logistics provider, has confirmed a significant ransomware attack that began impacting its operations in late April 2025. The incident has...

>> read more