05/01

Hackers abuse IPv6 networking feature to hijack software updates

https://www.bleepingcomputer.com/news/security/hackers-abuse-ipv6-networking-feature-to-hijack-software-updates/
Hackers abuse IPv6 networking feature to hijack software updates

FBI shares massive list of 42,000 LabHost phishing domains

https://www.bleepingcomputer.com/news/security/fbi-shares-massive-list-of-42-000-labhost-phishing-domains/
FBI shares massive list of 42,000 LabHost phishing domains

Malicious PyPI packages abuse Gmail, websockets to hijack systems

https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-abuse-gmail-websockets-to-hijack-systems/
Malicious PyPI packages abuse Gmail, websockets to hijack systems

CVE-2024-10442 (CVSS 10): Zero-Click RCE in Synology DiskStation, PoC Publishes

https://securityonline.info/cve-2024-10442-cvss-10-zero-click-rce-in-synology-diskstation-poc-publishes/
CVE-2024-10442 (CVSS 10): Zero-Click RCE in Synology DiskStation, PoC Publishes

Luxury store Harrods is latest retail victim of cyber attackers | Money News | Sky News

https://news.sky.com/story/luxury-store-harrods-is-latest-retail-victim-of-cyber-attackers-13359363
Luxury store Harrods is latest retail victim of cyber attackers | Money News | Sky News

ThreatBook

https://threatbook.io/ip/185.174.102.21
ThreatBook

New Research Reveals: 95% of AppSec Fixes Don't Reduce Risk

https://thehackernews.com/2025/05/new-research-reveals-95-of-appsec-fixes.html
New Research Reveals: 95% of AppSec Fixes Don't Reduce Risk

NCSC statement: Incident impacting retailers - NCSC.GOV.UK

https://www.ncsc.gov.uk/news/retailers-incident
NCSC statement: Incident impacting retailers - NCSC.GOV.UK

North Korean operatives have infiltrated hundreds of Fortune 500 companies | CyberScoop

https://cyberscoop.com/north-korea-workers-infiltrate-fortune-500/
North Korean operatives have infiltrated hundreds of Fortune 500 companies | CyberScoop

Yet Another NodeJS Backdoor (YaNB): A Modern Challenge

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/yet-another-nodejs-backdoor-yanb-a-modern-challenge/
Yet Another NodeJS Backdoor (YaNB): A Modern Challenge

Drag and Pwnd: Leverage ASCII characters to exploit VS Code | PortSwigger Research

https://portswigger.net/research/drag-and-pwnd-leverage-ascii-characters-to-exploit-vs-code
Drag and Pwnd: Leverage ASCII characters to exploit VS Code | PortSwigger Research

DarkWatchman, Sheriff Malware Hit Russia and Ukraine with Stealth and Nation-Grade Tactics

https://thehackernews.com/2025/05/darkwatchman-sheriff-malware-hit-russia.html
DarkWatchman, Sheriff Malware Hit Russia and Ukraine with Stealth and Nation-Grade Tactics