Wednesday , April 2 2025

infosecbulletin

.Gov Domains Weaponized in Phishing Surge

.gov

A recent report from Cofense Intelligence highlights a concerning trend: threat actors are increasingly misusing .gov top-level domains (TLDs) to execute phishing campaigns. Between November 2022 and November 2024, attackers have leveraged vulnerabilities in government websites from various countries to host malicious content, act as command-and-control (C2) servers, and funnel …

Read More »

RedSentry presents
Hacked 101 Seminar Successfully Ended at UITS

Hacked 101

The cybersecurity seminar “RedSentry presents: Hacked 101,” organized by RedSentry with the University of Information Technology and Sciences (UITS) as the venue partner, concluded successfully, leaving a significant impact on students and aspiring cybersecurity professionals. The event attracted a large audience eager to learn about the dynamic and ever-evolving world …

Read More »

US scientists claim to replicate DeepSeek for $30 dubbed “TinyZero,”

$30

Researchers at the University of California, Berkeley, claims they’ve managed to reproduce the core technology behind DeepSeek’s at a total cost of roughly $30. The news raises questions about whether developing advanced AI requires huge budgets or if cheaper alternatives have been ignored by major tech companies. DeepSeek recently launched …

Read More »

ChatGPT, DeepSeek, Qwen 2.5-VL Vulnerable to AI Jailbreaks

Qwen

This week, multiple research teams showcased jailbreaks for popular AI models, including OpenAI’s ChatGPT, DeepSeek, and Alibaba’s Qwen. After its launch, the open-source R1 model by Chinese company DeepSeek caught the attention of the cybersecurity industry. Experts found that jailbreak methods, previously patched in other AI models, still function against …

Read More »

Paragon Attack WhatsApp With New Zero-Click Spyware

paragon

WhatsApp reveiled on Friday that a “zero-click” spyware attack, linked to the Israeli company Paragon, has targeted many users globally, including journalists and civil society members. The spyware targeted almost 100 WhatsApp users, including journalists, and operated without user interaction, links, or attachments, making it particularly dangerous. Reuters reported that …

Read More »

Vulnarabilitties found in Cisco webex and VMware Aria operation

Cisco webex

A serious cybersecurity flaw in Cisco Webex Chat has been discovered, allowing unauthorized attackers to access the chat histories of organizations using the platform. Identified in July 2024, the flaw exposed sensitive communications from potentially thousands of organizations, including IT help desks and customer service operations. Proof-of-Concept and Real-World Impact: …

Read More »