Deep dive into CVE‑2025‑29824 in Windows

On April 8, 2025, Microsoft patched 121 vulnerabilities across its products, including CVE-2025-29824—the only one known to be exploited in the wild. This particular flaw enabled adversaries to escalate Windows privileges by leveraging a bug in the clfs.sys driver. Microsoft Read More …

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824

In April 2025, Microsoft patched 121 vulnerabilities in its products. According to the company, only one of them was being used in real-world attacks at the time the patch was released: CVE-2025-29824. The exploit for this vulnerability was executed by Read More …

Eight things we learned from WhatsApp vs. NSO Group spyware lawsuit

On May 6, WhatsApp scored a major victory against NSO Group when a jury ordered the infamous spyware maker to pay more than $167 million in damages to the Meta-owned company. The ruling concluded a legal battle spanning more than Read More …

Pakistan among least affected by web threats

At its annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, the Kaspersky Global Research and Analysis Team presented cybersecurity trends, including ransomware, advanced persistent threats (APTs), supply chain attacks, mobile threats, artificial intelligence and IoT Read More …

Kaspersky reveals three-year long suspected supply chain attack targeting Linux

UPDATE 13.09.2023. Free Download Manager team issued an official statement regarding this incident. Kaspersky unveiled a malicious campaign in which an installer of the Free Download Manager software was employed to disseminate a Linux backdoor for a minimum of three Read More …

Riyadh gears up for the ultimate hack fest as infosec heavyweights head to Black Hat MEA this November

Registrations now open for most awaited cybersecurity event in the region, taking place in Riyadh from 15 – 17 November 2022 Visitors to expect an action-packed agenda with 23 bespoke certified world-class cybersecurity trainings, exhilarating hacking competitions, and captivating sessions Read More …

Former Twitter employees charged with spying for Saudi Arabia by digging into the accounts of kingdom critics

The Justice Department has charged two former Twitter employees with spying for Saudi Arabia by accessing the company’s information on dissidents who use the platform, marking the first time federal prosecutors have publicly accused the kingdom of running agents in Read More …