<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
    <title>Cybersecurity Tomorrow &amp; : Cybersecurity News &amp;amp; Updates</title>
    <link>https://cybersecuritytomorrow.com/rss/category/Cybersecurity_News_Updates</link>
    <description>Cybersecurity Tomorrow &amp; : Cybersecurity News &amp;amp; Updates</description>
    <dc:language>en</dc:language>
    <dc:creator></dc:creator>
    <dc:rights>Copyright 2025 Cybersecurity Tomorrow &amp; All Rights Reserved.</dc:rights>
    <item>
        <title>FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks</title>
        <link>https://cybersecuritytomorrow.com/fbi-warns-russian-hackers-target-signal-whatsapp-in-mass-phishing-attacks</link>
        <guid>https://cybersecuritytomorrow.com/fbi-warns-russian-hackers-target-signal-whatsapp-in-mass-phishing-attacks</guid>
        <description><![CDATA[ Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to seize control of accounts belonging to individuals with high intelligence value, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) said Friday.
&quot;The campaign ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiMsZnvgdoACYJn8WjDy_Lpvpy1iqvGpj-vb4hYfYTLujLp_5dm8WZKjl64LYwY4-MON0-1k8-F2K3KDu0QG7isYjhaMvre0E0vrqJCSP49r2j374JPbV6WvkTG8lwqwrxquX-3xrReaA3G-NQGvskSnlOtM1XRj1J3MdPuCK9lXC6vf8ZkrCizN6ohcLC/s1600/signal-whatsapp.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>FBI, Warns, Russian, Hackers, Target, Signal, WhatsApp, Mass, Phishing, Attacks</media:keywords>
    </item>
    <item>
        <title>Oracle Patches Critical CVE&amp;2026&amp;21992 Enabling Unauthenticated RCE in Identity Manager</title>
        <link>https://cybersecuritytomorrow.com/oracle-patches-critical-cve-2026-21992-enabling-unauthenticated-rce-in-identity-manager</link>
        <guid>https://cybersecuritytomorrow.com/oracle-patches-critical-cve-2026-21992-enabling-unauthenticated-rce-in-identity-manager</guid>
        <description><![CDATA[ Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.
The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0.
&quot;This vulnerability is remotely exploitable without authentication,&quot; Oracle said in an advisory. &quot;If successfully ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxIh9aqIMPc6elNLcqZwmxGq0BHfA3NS2kkxawAr-H7SzPJKmvc7tXrykcm664TGFkJUIb_BmGpJV0CkEjIxVoRfTCrc8br5bi_TL93Nv_g7J_c9ccucZL4e55lp_zyywwBeAzDIoA1bnI95ELRLCbOyVf0WX0CGgGHLun2uQFKhqeMKf16nBOeJTO7O77/s1600/oracle-flaw-hack.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Oracle, Patches, Critical, CVE-2026-21992, Enabling, Unauthenticated, RCE, Identity, Manager</media:keywords>
    </item>
    <item>
        <title>CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026</title>
        <link>https://cybersecuritytomorrow.com/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026</link>
        <guid>https://cybersecuritytomorrow.com/cisa-flags-apple-craft-cms-laravel-bugs-in-kev-orders-patching-by-april-3-2026</guid>
        <description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come under exploitation are listed below -

CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJQDea3eiUAONNSYkmQsjicwXBMSALOAUJi7yPHqOStd9N-KBADSGXjH5zJS66VPyzi7-w5ULK7Ax9qH66_Av9E3xIL8BB7sDKz9d-ZbmlyqeyfKyCUYBb15eOH5_keQQ-RUchVoh7NvguG3Ps8sau8Ik17QNOMVtmTkQEck9gao_1zcLPE8JE_qPvc4Q9/s1600/cisa-kev.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>CISA, Flags, Apple, Craft, CMS, Laravel, Bugs, KEV, Orders, Patching, April, 2026</media:keywords>
    </item>
    <item>
        <title>Trivy Supply Chain Attack Triggers Self&amp;Spreading CanisterWorm Across 47 npm Packages</title>
        <link>https://cybersecuritytomorrow.com/trivy-supply-chain-attack-triggers-self-spreading-canisterworm-across-47-npm-packages</link>
        <guid>https://cybersecuritytomorrow.com/trivy-supply-chain-attack-triggers-self-spreading-canisterworm-across-47-npm-packages</guid>
        <description><![CDATA[ The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm.
The name is a reference to the fact that the malware uses an ICP canister, which refers to tamperproof smart contracts on ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJqn31IC9aCQ9LMLCLRXgpwsa1gvtzXlYk20-1yRmCMYVM_MwGHedfSgbKl24yaeTx4fqRc4-vscge-d3P6sN8sErQBVGD0kgxMGzV-mDCI1wGFh87BB8me019zcennhvA6xyMHLnH9IKZ-txSWs9OwL5cGbg0X8sx_KZ2tj5A5awErRRRMbdSrw_cXs6a/s1600/npm-malware.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Trivy, Supply, Chain, Attack, Triggers, Self-Spreading, CanisterWorm, Across, npm, Packages</media:keywords>
    </item>
    <item>
        <title>Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets</title>
        <link>https://cybersecuritytomorrow.com/trivy-security-scanner-github-actions-breached-75-tags-hijacked-to-steal-cicd-secrets</link>
        <guid>https://cybersecuritytomorrow.com/trivy-security-scanner-github-actions-breached-75-tags-hijacked-to-steal-cicd-secrets</guid>
        <description><![CDATA[ Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets.
The latest incident impacted GitHub Actions &quot;aquasecurity/trivy-action&quot; and &quot;aquasecurity/setup-trivy,&quot; which are used to scan Docker container images for vulnerabilities and set up GitHub Actions workflow ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgNf7vYlImTCJ7BCjYYEhoFZXTawhHcJJad9cFjQn98oQjaPY9HY6Qgpp6pAyqkq7CNHyVXI9fR8hcyVNlW_knYia3f0BhAlK7fZb2gplznk9v9QCFGKtIbMLTSu-erTslOxZCHd8jkJKXIcCYhK8QkKLuWjG8yxjhPBaEWUDzwY0sUkX5JvhBtzFxyfp_q/s1600/scan.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:38:52 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Trivy, Security, Scanner, GitHub, Actions, Breached, Tags, Hijacked, Steal, CICD, Secrets</media:keywords>
    </item>
    <item>
        <title>Who is the Kimwolf Botmaster “Dort”?</title>
        <link>https://cybersecuritytomorrow.com/who-is-the-kimwolf-botmaster-dort</link>
        <guid>https://cybersecuritytomorrow.com/who-is-the-kimwolf-botmaster-dort</guid>
        <description><![CDATA[ In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to assemble Kimwolf, the world&#039;s largest and most disruptive botnet. Since then, the person in control of Kimwolf -- who goes by the handle &quot;Dort&quot; -- has coordinated a barrage of distributed denial-of-service (DDoS), doxing and email flooding attacks against the researcher and this author, and more recently caused a SWAT team to be sent to the researcher&#039;s home. This post examines what is knowable about Dort based on public information. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2026/02/ben-door.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:34:56 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Who, the, Kimwolf, Botmaster, “Dort”</media:keywords>
    </item>
    <item>
        <title>How AI Assistants are Moving the Security Goalposts</title>
        <link>https://cybersecuritytomorrow.com/how-ai-assistants-are-moving-the-security-goalposts</link>
        <guid>https://cybersecuritytomorrow.com/how-ai-assistants-are-moving-the-security-goalposts</guid>
        <description><![CDATA[ AI-based assistants or &quot;agents&quot; -- autonomous programs that have access to the user&#039;s computer, files, online services and can automate virtually any task -- are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines over the past few weeks have shown, these powerful and assertive new tools are rapidly shifting the security priorities for organizations, while blurring the lines between data and code, trusted co-worker and insider threat, ninja hacker and novice code jockey. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2026/03/lethaltrifecta.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:34:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>How, Assistants, are, Moving, the, Security, Goalposts</media:keywords>
    </item>
    <item>
        <title>Microsoft Patch Tuesday, March 2026 Edition</title>
        <link>https://cybersecuritytomorrow.com/microsoft-patch-tuesday-march-2026-edition</link>
        <guid>https://cybersecuritytomorrow.com/microsoft-patch-tuesday-march-2026-edition</guid>
        <description><![CDATA[ Microsoft Corp. today pushed security updates to fix at least 77 vulnerabilities in its Windows operating systems and other software. There are no pressing &quot;zero-day&quot; flaws this month (compared to February&#039;s five zero-day treat), but as usual some patches may deserve more rapid attention from organizations using Windows. Here are a few highlights from this month&#039;s Patch Tuesday. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2026/03/winupdatechecking.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:34:46 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Microsoft, Patch, Tuesday, March, 2026, Edition</media:keywords>
    </item>
    <item>
        <title>Iran&amp;Backed Hackers Claim Wiper Attack on Medtech Firm Stryker</title>
        <link>https://cybersecuritytomorrow.com/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker</link>
        <guid>https://cybersecuritytomorrow.com/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker</guid>
        <description><![CDATA[ A hacktivist group with links to Iran&#039;s intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker&#039;s largest hub outside of the United States, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at Stryker&#039;s main U.S. headquarters says the company is currently experiencing a building emergency. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2026/03/handala-stryker.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:34:41 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Iran-Backed, Hackers, Claim, Wiper, Attack, Medtech, Firm, Stryker</media:keywords>
    </item>
    <item>
        <title>Feds Disrupt IoT Botnets Behind Huge DDoS Attacks</title>
        <link>https://cybersecuritytomorrow.com/feds-disrupt-iot-botnets-behind-huge-ddos-attacks</link>
        <guid>https://cybersecuritytomorrow.com/feds-disrupt-iot-botnets-behind-huge-ddos-attacks</guid>
        <description><![CDATA[ The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million hacked Internet of Things (IoT) devices, such as routers and web cameras. The feds say the four botnets -- named Aisuru, Kimwolf, JackSkid and Mossad -- are responsible for a series of recent record-smashing distributed denial-of-service (DDoS) attacks capable of knocking nearly any target offline. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2026/01/ss-botnet.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:34:36 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Feds, Disrupt, IoT, Botnets, Behind, Huge, DDoS, Attacks</media:keywords>
    </item>
    <item>
        <title>Cyber Forensic Expert in 2,000+ Cases Faces FBI Probe</title>
        <link>https://cybersecuritytomorrow.com/cyber-forensic-expert-in-2000-cases-faces-fbi-probe</link>
        <guid>https://cybersecuritytomorrow.com/cyber-forensic-expert-in-2000-cases-faces-fbi-probe</guid>
        <description><![CDATA[ A Minnesota cybersecurity and computer forensics expert whose testimony has featured in thousands of courtroom trials over the past 30 years is facing questions about his credentials and an inquiry from the Federal Bureau of Investigation (FBI). Legal experts say the inquiry could be grounds to reopen a number of adjudicated cases in which the expert&#039;s testimony may have been pivotal. ]]></description>
        <enclosure url="http://www.dropbox.com/scl/fi/srxrxkwyf03inudrw9ymn/2023-Seminar-Recording-copy-copy-1.MP4" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:39 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Cyber, Forensic, Expert, 2, 000, Cases, Faces, FBI, Probe</media:keywords>
    </item>
    <item>
        <title>Patch Tuesday, April 2025 Edition</title>
        <link>https://cybersecuritytomorrow.com/patch-tuesday-april-2025-edition</link>
        <guid>https://cybersecuritytomorrow.com/patch-tuesday-april-2025-edition</guid>
        <description><![CDATA[ Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft&#039;s most-dire &quot;critical&quot; rating, meaning malware or malcontents could exploit them with little to no interaction from Windows users. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2021/07/windupate.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:35 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Patch, Tuesday, April, 2025, Edition</media:keywords>
    </item>
    <item>
        <title>China&amp;based SMS Phishing Triad Pivots to Banks</title>
        <link>https://cybersecuritytomorrow.com/china-based-sms-phishing-triad-pivots-to-banks</link>
        <guid>https://cybersecuritytomorrow.com/china-based-sms-phishing-triad-pivots-to-banks</guid>
        <description><![CDATA[ China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups are now directly targeting customers of international financial institutions, while dramatically expanding their cybercrime infrastructure and support staff. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2025/04/paypalsmish.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:31 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>China-based, SMS, Phishing, Triad, Pivots, Banks</media:keywords>
    </item>
    <item>
        <title>Trump Revenge Tour Targets Cyber Leaders, Elections</title>
        <link>https://cybersecuritytomorrow.com/trump-revenge-tour-targets-cyber-leaders-elections</link>
        <guid>https://cybersecuritytomorrow.com/trump-revenge-tour-targets-cyber-leaders-elections</guid>
        <description><![CDATA[ President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances for other security professionals at Krebs&#039;s employer SentinelOne, comes as CISA is facing huge funding and staffing cuts. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2025/04/chriskrebs-gi.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:27 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Trump, Revenge, Tour, Targets, Cyber, Leaders, Elections</media:keywords>
    </item>
    <item>
        <title>Funding Expires for Key Cyber Vulnerability Database</title>
        <link>https://cybersecuritytomorrow.com/funding-expires-for-key-cyber-vulnerability-database</link>
        <guid>https://cybersecuritytomorrow.com/funding-expires-for-key-cyber-vulnerability-database</guid>
        <description><![CDATA[ A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program -- which is traditionally funded each year by the Department of Homeland Security -- expires on April 16. ]]></description>
        <enclosure url="http://krebsonsecurity.com/wp-content/uploads/2025/04/mitreletter.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:22 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Funding, Expires, for, Key, Cyber, Vulnerability, Database</media:keywords>
    </item>
    <item>
        <title>Rogue npm Packages Mimic Telegram Bot API to Plant SSH Backdoors on Linux Systems</title>
        <link>https://cybersecuritytomorrow.com/rogue-npm-packages-mimic-telegram-bot-api-to-plant-ssh-backdoors-on-linux-systems</link>
        <guid>https://cybersecuritytomorrow.com/rogue-npm-packages-mimic-telegram-bot-api-to-plant-ssh-backdoors-on-linux-systems</guid>
        <description><![CDATA[ Cybersecurity researchers have uncovered three malicious packages in the npm registry that masquerade as a popular Telegram bot library but harbor SSH backdoors and data exfiltration capabilities.
The packages in question are listed below -

node-telegram-utils (132 downloads)
node-telegram-bots-api (82 downloads)
node-telegram-util (73 downloads)


According to supply chain ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTYaPrg3QcUDzJQw_6M2cQ8mylAmeTI7yDB2gTcrkFTeuN-nmzQGrSavv6DL8aU7gs55EFPkfLJM_rYvi1lm8wCbOK3OKftPnP9DR_HJbvbzvnvevxMUQRwOX0xd6qSZ0Is0f-eWZJFTknWvr4IoD2Qu4sZxmlmtn8nTW9yOOHbiFgeNyzc8cv5Wb9Z1X2/s1600/linux.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Rogue, npm, Packages, Mimic, Telegram, Bot, API, Plant, SSH, Backdoors, Linux, Systems</media:keywords>
    </item>
    <item>
        <title>ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware</title>
        <link>https://cybersecuritytomorrow.com/asus-confirms-critical-flaw-in-aicloud-routers-users-urged-to-update-firmware</link>
        <guid>https://cybersecuritytomorrow.com/asus-confirms-critical-flaw-in-aicloud-routers-users-urged-to-update-firmware</guid>
        <description><![CDATA[ ASUS has disclosed a critical security flaw impacting routers with AiCloud enabled that could permit remote attackers to perform unauthorized execution of functions on susceptible devices.
The vulnerability, tracked as CVE-2025-2492, has a CVSS score of 9.2 out of a maximum of 10.0.

&quot;An improper authentication control vulnerability exists in certain ASUS router firmware series,&quot; ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC2Znl4UHn2tC-NlTNtOaYJ7AhGRK7pH53LZWvxGtpnAr2WN-GQskGoscwZOOmp3j0TVSIRyeikiPUzIDN0MjkhWORr4owD4Tf7XhxzqtBGOlIEw36eGHe8fohgwJ8wtJakc7Uobm0uFShLjbiUrULgk9pNIJrLwOBBSmRH0RByY5885RDyvEqSXL8ytRB/s1600/asus-ai.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>ASUS, Confirms, Critical, Flaw, AiCloud, Routers, Users, Urged, Update, Firmware</media:keywords>
    </item>
    <item>
        <title>Chinese Smishing Kit Powers Widespread Toll Fraud Campaign Targeting U.S. Users in 8 States</title>
        <link>https://cybersecuritytomorrow.com/chinese-smishing-kit-powers-widespread-toll-fraud-campaign-targeting-us-users-in-8-states</link>
        <guid>https://cybersecuritytomorrow.com/chinese-smishing-kit-powers-widespread-toll-fraud-campaign-targeting-us-users-in-8-states</guid>
        <description><![CDATA[ Cybersecurity researchers are warning of a &quot;widespread and ongoing&quot; SMS phishing campaign that&#039;s been targeting toll road users in the United States for financial theft since mid-October 2024.
&quot;The toll road smishing attacks are being carried out by multiple financially motivated threat actors using the smishing kit developed by &#039;Wang Duo Yu,&#039;&quot; Cisco Talos researchers Azim Khodjibaev, Chetan ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTSFUr1LOmW273ZOVQRjrfUwSucPBc0LMRMS4l7mdYTxXLNPx-CbGJhJ_6FqNQamMtfdvDHg8jTDwC_2QBHVYZfU-5p_H9wxR5SQY4b2uBnhikXM6P9TsyzzI4SW3UU__EWK2MnGKeP9y-cdU1lku9l_zOjrGceurDqkr4Xb2BkKHbqcOGUGEgyBVScTFJ/s1600/phishing.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Chinese, Smishing, Kit, Powers, Widespread, Toll, Fraud, Campaign, Targeting, U.S., Users, States</media:keywords>
    </item>
    <item>
        <title>Multi&amp;Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoader</title>
        <link>https://cybersecuritytomorrow.com/multi-stage-malware-attack-uses-jse-and-powershell-to-deploy-agent-tesla-and-xloader</link>
        <guid>https://cybersecuritytomorrow.com/multi-stage-malware-attack-uses-jse-and-powershell-to-deploy-agent-tesla-and-xloader</guid>
        <description><![CDATA[ A new multi-stage attack has been observed delivering malware families like Agent Tesla variants, Remcos RAT, and XLoader.
&quot;Attackers increasingly rely on such complex delivery mechanisms to evade detection, bypass traditional sandboxes, and ensure successful payload delivery and execution,&quot; Palo Alto Networks Unit 42 researcher Saqib Khanzada said in a technical write-up of the campaign.
The ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKoTKuU3COGDSwy46uJfXpH99uyAvSuu8NEgeTJH6Co4hNRWbDcKB6EpP-bRz3ZDeNpv8N9v5RRjZHRrB5d657WYF4jjiQ7uzAEzDoevTU5HCSBe85S9PwvuJ9x9NYjYiPYE9HYTpry-dMYseQ4YNcE3jWJ28a6nZ9Wn5Q0xkFct_rKw3blJi2zzS7nBDd/s1600/malware-infection.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Multi-Stage, Malware, Attack, Uses, .JSE, and, PowerShell, Deploy, Agent, Tesla, and, XLoader</media:keywords>
    </item>
    <item>
        <title>[Webinar] AI Is Already Inside Your SaaS Stack — Learn How to Prevent the Next Silent Breach</title>
        <link>https://cybersecuritytomorrow.com/webinar-ai-is-already-inside-your-saas-stack-learn-how-to-prevent-the-next-silent-breach</link>
        <guid>https://cybersecuritytomorrow.com/webinar-ai-is-already-inside-your-saas-stack-learn-how-to-prevent-the-next-silent-breach</guid>
        <description><![CDATA[ Your employees didn’t mean to expose sensitive data. They just wanted to move faster. So they used ChatGPT to summarize a deal. Uploaded a spreadsheet to an AI-enhanced tool. Integrated a chatbot into Salesforce. No big deal—until it is.
If this sounds familiar, you&#039;re not alone. Most security teams are already behind in detecting how AI tools are quietly reshaping their SaaS environments. And ]]></description>
        <enclosure url="http://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOWn65wd33dg2uO99NrtKbpYLfcepwOLidQDMls0HXKlA91k6HURluRA4WXgJRAZldEe1VReMQZyyYt1PgnoAn5JPpILsWlXIzmrBSs_TBoyPwO7hZrWouBg2-O3mdeoeSGY-l9_bsZB7vbpKjTSvG93zNytjxgTaMPqo9iq9Z5pGa05CJOs9uXpwHFT4/s1600/ai-cyber.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Webinar, Already, Inside, Your, SaaS, Stack, —, Learn, How, Prevent, the, Next, Silent, Breach</media:keywords>
    </item>
    <item>
        <title>The Shadow AI Surge: Study Finds 50% of Workers Use Unapproved AI Tools</title>
        <link>https://cybersecuritytomorrow.com/the-shadow-ai-surge-study-finds-50-of-workers-use-unapproved-ai-tools</link>
        <guid>https://cybersecuritytomorrow.com/the-shadow-ai-surge-study-finds-50-of-workers-use-unapproved-ai-tools</guid>
        <description><![CDATA[ With unapproved AI tools entrenched in daily workflows, experts say it’s time to shift from monitoring to managing Shadow AI use across the enterprise.
The post The Shadow AI Surge: Study Finds 50% of Workers Use Unapproved AI Tools appeared first on SecurityWeek. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:12 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>The, Shadow, Surge:, Study, Finds, 50, Workers, Use, Unapproved, Tools</media:keywords>
    </item>
    <item>
        <title>In Other News: 4chan Hacked, Android Auto&amp;Reboot, Nemesis Admin Charged</title>
        <link>https://cybersecuritytomorrow.com/in-other-news-4chan-hacked-android-auto-reboot-nemesis-admin-charged</link>
        <guid>https://cybersecuritytomorrow.com/in-other-news-4chan-hacked-android-auto-reboot-nemesis-admin-charged</guid>
        <description><![CDATA[ Noteworthy stories that might have slipped under the radar: 4chan hacked, auto-reboot security feature coming to Android, Iranian administrator of Nemesis charged in US.
The post In Other News: 4chan Hacked, Android Auto-Reboot, Nemesis Admin Charged appeared first on SecurityWeek. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:12 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Other, News:, 4chan, Hacked, Android, Auto-Reboot, Nemesis, Admin, Charged</media:keywords>
    </item>
    <item>
        <title>Cy4Data Labs Raises $10 Million to Secure Data in Use</title>
        <link>https://cybersecuritytomorrow.com/cy4data-labs-raises-10-million-to-secure-data-in-use</link>
        <guid>https://cybersecuritytomorrow.com/cy4data-labs-raises-10-million-to-secure-data-in-use</guid>
        <description><![CDATA[ Data protection firm Cy4Data Labs has raised $10 million in a Series A funding round led by Pelion Venture Partners.
The post Cy4Data Labs Raises $10 Million to Secure Data in Use appeared first on SecurityWeek. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:12 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Cy4Data, Labs, Raises, 10, Million, Secure, Data, Use</media:keywords>
    </item>
    <item>
        <title>Events Giant Legends International Hacked</title>
        <link>https://cybersecuritytomorrow.com/events-giant-legends-international-hacked</link>
        <guid>https://cybersecuritytomorrow.com/events-giant-legends-international-hacked</guid>
        <description><![CDATA[ Legends International says the personal information of employees and customers was compromised as a result of a cyberattack.
The post Events Giant Legends International Hacked appeared first on SecurityWeek. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:12 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Events, Giant, Legends, International, Hacked</media:keywords>
    </item>
    <item>
        <title>Ahold Delhaize Confirms Data Stolen in Ransomware Attack</title>
        <link>https://cybersecuritytomorrow.com/ahold-delhaize-confirms-data-stolen-in-ransomware-attack</link>
        <guid>https://cybersecuritytomorrow.com/ahold-delhaize-confirms-data-stolen-in-ransomware-attack</guid>
        <description><![CDATA[ Ahold Delhaize has confirmed that data was stolen from its systems in November 2024 after a ransomware group claimed the attack.
The post Ahold Delhaize Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 15:06:12 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Ahold, Delhaize, Confirms, Data, Stolen, Ransomware, Attack</media:keywords>
    </item>
    </channel>
</rss>