Alerts List
AL2025_51 Malicious VSCode Extensions Resurface on OpenVSX, Target Developers with Crypto-Stealers and Backdo
Description Researchers have observed a coordinated campaign (tracked as TigerJack) that publishes malicious Visual Studio Code (VSCode) extensions to . . . Read more

Date Publish: Oct 16th 25
AL2025_50 Oracle E-Business Suite Zero-Day (CVE-2025-61882) Exploited in Clop Data-Theft Campaign (October 7t
Description Oracle has released an emergency security update to address a critical, unauthenticated remote-code-execution vulnerability in Oracle E-Bu . . . Read more

Date Publish: Oct 7th 25
AL2025_49 Discord Support-Ticket Breach Exposes User Data (October 7th, 2025)
Description Discord disclosed that an unauthorized party gained limited access to a third-party customer service/ticketing system used by Discord, exp . . . Read more

Date Publish: Oct 7th 25
AL2025_48 Microsoft Outlook Stops Displaying Inline SVG Images Exploited in Phishing Attacks (October 07th, 2
Description Microsoft has implemented a security change in Outlook to block the display of inline SVG (Scalable Vector Graphics) images, following rec . . . Read more

Date Publish: Oct 7th 25
AL2025_47 New MatrixPDF toolkit turns PDFs into phishing and malware lures (October 02nd , 2025) 
Description  A new phishing and malware distribution toolkit called MatrixPDF has been discovered on cybercrime forums, enabling threat actors to tran . . . Read more

Date Publish: Oct 2nd 25
AL2025_46 Cisco ASA and FTD Zero-Day Vulnerabilities Actively Exploited in State-Sponsored Attacks (October 0
Description  Cisco has released emergency security patches for three critical zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and . . . Read more

Date Publish: Oct 2nd 25
AL2025_45 LockBit 5.0 Emerges- Cross Platform Ransomware Targets Windows, Linux and ESXi (September 30th, 202
Description A new iteration of the LockBit ransomware marketed as LockBit 5.0 has been observed in the wild. This variant includes cross-platform bina . . . Read more

Date Publish: Sep 30th 25
AL2025_44 AI-Driven Phishing Campaign Using LLM-Crafted SVG Files (September 30th, 2025)
Description Microsoft has identified a new phishing campaign targeting organizations that leverages large language models (LLMs) to create obfuscated . . . Read more

Date Publish: Sep 30th 25
AL2025_43 Akira Ransomware Exploits SonicWall VPNs to Bypass Multi-Factor Authentication (September 29th , 20
Description Security researchers have observed the Akira ransomware group bypassing multi-factor authentication (MFA) protections on SonicWall SSL VPN . . . Read more

Date Publish: Sep 29th 25
AL2025_42 Fake Microsoft Teams Installers Distribute Oyster Malware (September 29th, 2025)
Description Cybercriminals are tricking users into downloading fake Microsoft Teams installers from malicious websites promoted through search engine . . . Read more

Date Publish: Sep 29th 25
AL2025_41 Google Patches Actively Exploited Chrome Zero-Day Vulnerability (September 27th , 2025)
Description Google has released an emergency update to fix a zero-day vulnerability in the Chrome browser, tracked as CVE-2025-10585. This flaw is alr . . . Read more

Date Publish: Sep 27th 25
AL2025_40 New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus (September 24th, 2025
Description  In June 2025, Zscaler ThreatLabz discovered a new malware family named YiBackdoor, which shows significant source code overlap with IcedI . . . Read more

Date Publish: Sep 24th 25