Dashcams have become an essential accessory in vehicles across many countries, serving as impartial witnesses in the event of accidents and roadside disputes. Yet, new research presented at Security Analyst Summit 2025 by a team of Singaporean cybersecurity researchers has uncovered a disturbing reality: dashcams, even offline ones, are increasingly being exploited as convenient surveillance […]
Microsoft is currently investigating a service disruption affecting the Microsoft Defender portal, which has blocked numerous security professionals from accessing critical threat management tools.
The issue, tracked under the identifier DZ1191468 in the Microsoft 365 admin center, sparked concerns early Tuesday as administrators reported timeouts and login failures when attempting to load the security dashboard.
The disruption began earlier today, with users across multiple regions experiencing difficulties reaching the Defender portal (security.microsoft.com). According to Microsoft’s status updates, the root cause has been linked to an unexpected “spike in traffic” that overwhelmed the service’s access capabilities.
We're investigating an issue where users may experience issues when trying to access the Microsoft Defender portal. Additional information will be provided in the admin center under DZ1191468.
While the portal is essential for Security Operations Center (SOC) teams to monitor alerts, investigate incidents, and manage endpoint security, the outage effectively left some organizations temporarily blind to real-time threat data.
Microsoft’s Official Response
Microsoft acknowledged the problem quickly, assigning it the case ID DZ1191468. In a statement provided to administrators, the company confirmed the nature of the anomaly:
We've identified a spike in traffic and applied a mitigation. Availability has recovered, however, we're reviewing isolated error reports. Additional details are available in the admin center under DZ1191468.
Following the implementation of traffic management mitigations, service availability has largely recovered. However, Microsoft notes that while the core issue is resolved, they are still “reviewing isolated error reports” to ensure complete stability for all tenants.
For enterprise security teams, access to the Microsoft Defender portal is non-negotiable. It serves as the central hub for Extended Detection and Response (XDR), allowing analysts to triage malware alerts and isolate compromised devices.
Even brief access interruptions can impede a SOC’s ability to respond to active threats or verify automated remediations. During the downtime, automated background protection services (like Defender Antivirus on endpoints) likely remained operational, but the administrative visibility required for human oversight was temporarily severed.
Administrators experiencing lingering connection issues are advised to monitor the Service Health Dashboard in the Microsoft 365 admin center under DZ1191468 for the latest recovery confirmation.
Israeli entities spanning academia, engineering, local government, manufacturing, technology, transportation, and utilities sectors have emerged as the target of a new set of attacks undertaken by Iranian nation-state actors that have delivered a previously undocumented backdoor called MuddyViper.
The activity has been attributed by ESET to a hacking group known as MuddyWater (aka Mango
Security researchers at Nisos have identified a critical gap in insider threat detection: organizations often fail to correlate early behavioral anomalies with external intelligence sources, leaving meaningful warning signs buried beneath operational noise until incidents escalate into confirmed breaches. Most insider threats do not announce themselves with apparent malicious activity. Instead, security teams encounter subtle […]
Security researchers have uncovered a serious vulnerability in nopCommerce, a popular open-source ecommerce platform used by major companies, including Microsoft, Volvo, and BMW. The flaw allows attackers to hijack user accounts by exploiting captured session cookies, even after legitimate users have logged out. Field Details CVE ID CVE-2025-11699 Vulnerability Title Insufficient Session Cookie Invalidation Platform […]
The Raspberry Pi Foundation has announced immediate availability of a new 1GB version of the Raspberry Pi 5, marking a significant expansion of its affordable computing platform.
The new entry-level model arrives at $45, making high-performance computing more accessible to budget-conscious consumers and developers worldwide.
The 1GB Raspberry Pi 5 retains all the flagship capabilities that have made the platform popular among hobbyists, educators, and professionals.
It features a powerful quad-core 2.4GHz Arm Cortex-A76 processor, dual-band Wi-Fi connectivity, and a PCI Express port for expandable storage and peripherals.
These specifications ensure users get enterprise-grade computing power at a fraction of the cost of traditional computers.
The launch comes as the Raspberry Pi Foundation addresses the unprecedented rise in LPDDR4 memory costs, mainly driven by competition from artificial intelligence infrastructure projects.
To maintain memory supplies and navigate an increasingly constrained market anticipated for 2026. The organization has announced strategic price increases across select Raspberry Pi 4 and Raspberry Pi 5 products.
These adjustments mirror previous increases announced in October for Compute Module products. The pricing structure reflects the foundation’s commitment to affordability while maintaining operational sustainability.
Higher-capacity models experience more significant increases: Lower-capacity variants of Raspberry Pi 4, older Raspberry Pi 3+ models, and Raspberry Pi Zero products maintain their existing prices, providing continued options for cost-sensitive users.
Raspberry Pi 5 Pricing Changes
Memory Capacity
Old Price
New Price
Price Increase
Percentage Increase
2GB
$50
$55
$5
10%
4GB
$60
$70
$10
16.7%
8GB
$80
$95
$15
18.75%
16GB
$120
$145
$25
20.8%
Raspberry Pi 4 Pricing Change
Memory Capacity
Old Price
New Price
Price Increase
Percentage Increase
4GB
$55
$60
$5
9.1%
8GB
$75
$85
$10
13.3%
The 16GB Compute Module 5, which remained unchanged during October’s price adjustment, now sees a $20 increase.
The Raspberry Pi Foundation believes the current memory shortages are temporary and continues its mission to provide affordable, high-performance computers worldwide.
Leadership emphasizes its commitment to unwinding these price increases once memory market conditions stabilize and competitive pressures from AI infrastructure projects ease.
The new 1GB Raspberry Pi 5 offers developers and makers a powerful, affordable entry into the ecosystem, combining modern processors with essential connectivity at a low price.
Multiple Ukrainian hacktivist groups have launched an extensive spearphishing campaign targeting Russia’s critical aerospace and defence industries, according to a new threat intelligence report by Intrinsec. The coordinated attacks between June and September 2025 represent an escalating cyber warfare strategy aimed at disrupting Russian military capabilities and civilian aviation operations. The campaign involves several prominent […]
A sophisticated threat actor has been conducting a persistent phishing campaign against United States educational institutions since April 2025, leveraging the open-source Evilginx framework to bypass multi-factor authentication (MFA). The campaign, which has targeted at least 18 universities to date, utilizes adversary-in-the-middle (AiTM) techniques to intercept login credentials and session cookies by mimicking legitimate single […]
The Glassworm malware campaign has resurfaced with unprecedented scale, deploying 24 malicious extensions across Microsoft Visual Studio Marketplace and OpenVSX over the past week.
This latest wave of attacks demonstrates the persistent threat posed by supply chain compromises targeting developer tools.
The malware specifically clones legitimate extensions for popular frameworks, including Flutter, Tailwind, Vim, Yaml, Svelte, React Native, and Vue, making it difficult for developers to distinguish between authentic and fraudulent packages.
The attack mechanism exploits the trust developers place in extension marketplaces by initially publishing seemingly legitimate packages that pass security reviews.
Popular extension clone (Source – Secure Annex)
Once approved, the extensions receive updates containing hidden malicious code, allowing the attackers to bypass existing security filters.
Secure Annex security researchers identified that these malicious extensions employ sophisticated techniques to manipulate download counts and artificially inflate installation statistics, positioning the fake extensions directly alongside legitimate ones within the IDE interface.
This social engineering tactic makes it challenging for users to identify the correct extension during installation.
Infection Mechanism and Evolution
The infection process begins when developers install what appears to be a legitimate extension from the marketplace.
The malicious payload activates immediately after the extension loads into the development environment. Once activated, the code executes embedded implants that were previously hidden within the extension package.
The attackers have evolved their evasion tactics significantly, transitioning from invisible Unicode characters in earlier iterations to Rust-based implants embedded directly inside the extensions.
When the extension activates, it runs the malicious code within the developer’s system context, giving attackers access to sensitive information such as environment variables, authentication tokens, and project source code.
Malicious extensions (Source – Secure Annex)
The sophisticated obfuscation techniques make detection difficult without specialized security analysis tools. Secure Annex analysts noted the consistent attack signatures and patterns across the campaigns, linking various techniques together despite their evolution.
The researchers discovered that many extensions continue staging operations while manipulating download statistics to build credibility before final deployment.
The identified compromised packages span both marketplaces, with notable examples including prisma-inc.prisma-studio-assistance, prettier-vsc.vsce-prettier, and flutter-extension across both platforms.
Organizations using these extensions face significant risk from unauthorized system access and data exfiltration.
Security professionals recommend immediately auditing installed extensions and implementing marketplace scanning solutions to detect and prevent future compromises.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
A new malware campaign has emerged that exploits the trust users place in popular applications.
Threat actors are distributing trojanized installers for Telegram, WinSCP, Google Chrome, and Microsoft Teams to deploy ValleyRat, a remote access trojan designed for long-term system compromise.
The campaign has been attributed to the China-aligned APT group known as Silver Fox, which has remained active since at least 2022.
The infection begins when victims download what appears to be a legitimate application installer through spear-phishing emails or malicious advertisements.
On the surface, users see a normal installation interface, but hidden processes run silently in the background.
The malware stages files, deploys kernel-level drivers, tampers with endpoint security, and ultimately launches a ValleyRat beacon that maintains persistent access to the compromised system.
Nextron Systems security researchers identified this campaign through their detailed analysis of the entire infection chain.
Their investigation revealed that the attackers combine multiple layers of obfuscation, endpoint security tampering, and kernel-level techniques to evade detection while establishing command-and-control communications with remote servers.
Silver Fox Telegram installer infection chain (Source – Nextron Systems)
The distribution primarily occurs through trojanized Telegram installers. One analyzed sample, named tg.exe, carries the SHA-256 hash 9ede6da5986d8c0df3367c395b0b3924ffb12206939f33b01610c1ae955630d1.
Telegram UI showing Version 6.0.2 (Source – Nextron Systems)
The PE header timestamp dates to 2019, while its first VirusTotal submission occurred in August 2025, representing an unusual six-year gap for a frequently updated application.
Infection Mechanism and Defense Evasion
Once executed, the installer creates the directory C:\ProgramData\WindowsData\ and drops essential files, including a renamed 7-Zip binary (funzip.exe) and an encrypted archive disguised as main.xml.
The malware then uses PowerShell to add a Microsoft Defender exclusion for the entire C:\ drive, effectively silencing antivirus protection.
The archive extraction command reveals the embedded password:-
"C:\ProgramData\WindowsData\funzip.exe" x -y -phtLcENyRFYwXsHFnUnqK -o"C:\ProgramData\WindowsData" "C:\ProgramData\WindowsData\main.xml"
This extraction deploys men.exe, the main orchestrator that performs environmental reconnaissance by scanning for security processes, including Microsoft Defender’s MsMpEng.exe and Chinese security products like ZhuDongFangYu.exe and 360tray.exe.
Created scheduled task WindowsPowerShell.WbemScripting.SWbemLocator executing X.vbe (Source – Nextron Systems)
The campaign establishes persistence through a scheduled task named WindowsPowerShell.WbemScripting.SWbemLocator, designed to mimic legitimate Windows components, which executes an encoded VBScript launching the ValleyRat beacon for continued system access.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.