cyber attacks

AppWizard
November 3, 2025
A new wave of cyber attacks targeting Android users has been identified, involving 224 compromised applications that have collectively amassed over 38 million downloads from the Google Play Store. This threat, named SlopAds by the Satori Threat Intelligence and Research Team, involves sophisticated advertising fraud techniques, including steganography, to generate illicit revenue through harmful ads embedded in apps. Google has removed all compromised applications from the Play Store and will notify users to uninstall them. Users are advised to enable Google’s Play Protect feature to safeguard against malicious applications. Ad fraud not only affects individual users but also undermines trust in the advertising ecosystem.
Winsage
October 31, 2025
A China-affiliated threat actor, UNC6384, has been conducting cyber attacks targeting diplomatic and governmental entities in Europe, including Hungary, Belgium, Italy, the Netherlands, and Serbia. These attacks exploit an unpatched Windows shortcut vulnerability (CVE-2025-9491) through spear-phishing emails that appear relevant to diplomatic events. The emails deliver malicious LNK files that deploy PlugX malware via DLL side-loading. PlugX is a remote access trojan that allows extensive control over compromised systems and has been linked to another hacking group, Mustang Panda. Microsoft Defender can detect these attacks, and Smart App Control provides additional protection. The LNK file executes a PowerShell command to extract a TAR archive containing a legitimate utility, a malicious DLL, and an encrypted PlugX payload. The size of the malicious artifacts has decreased significantly, indicating ongoing evolution. UNC6384 has also begun using HTML Application files to load external JavaScript for retrieving malicious payloads, aligning with Chinese intelligence objectives regarding European defense policies.
Winsage
October 8, 2025
Microsoft will cease updates for Windows 10 on October 14, leaving users vulnerable to cyber threats. Over 40 percent of Windows users still use Windows 10, with around 5 million in the UK alone. A survey indicates that about one-quarter of these users plan to continue using Windows 10 after the support deadline. Users may face increased risks from malware, performance issues, and compatibility challenges with applications. Upgrading to Windows 11 is free if the hardware requirements are met. For those unable to upgrade, Microsoft offers the Windows 10 Consumer Extended Security Updates (ESU) program, which concludes on October 13 of the following year.
Winsage
September 28, 2025
Unsupported operating systems and device software lack regular updates, making them vulnerable to cyber attacks. Devices running on unsupported platforms can become gateways for attackers, as they are susceptible to known exploits that can be easily weaponized. According to Microsoft’s 2024 Digital Defense Report, over 90% of successful ransomware attacks target unmanaged endpoints. Unsupported versions can bypass standard security solutions and often fail compatibility checks with modern security tools, leading to significant protection gaps. Additionally, these vulnerabilities can be exploited to steal credentials and gain unauthorized access, posing risks to overall network security.
Tech Optimizer
July 22, 2025
Remote access trojans (RATs) are malware that allow hackers to control devices remotely, enabling them to steal passwords, monitor screens, log keystrokes, activate webcams or microphones, install additional malware, and use the computer for further cyber attacks. RATs typically enter systems through phishing, malicious downloads, fake updates, or compromised websites. Signs of a RAT infection include sluggish performance, unusual network activity, mysterious programs, unexpected pop-ups, and unexpected activation of camera or microphone lights. Preventive measures include being cautious with communications, downloading from reputable sources, using antivirus software, keeping software updated, and implementing a firewall. If a RAT is suspected, it is advised to disconnect from the internet, run a full antivirus scan, check installed programs, change passwords, and consider a factory reset. Smartphones can also be vulnerable to RATs, which may manifest as rapid battery drain, overheating, strange pop-ups, excessive data usage, and unfamiliar apps. Immediate actions for compromised phones include enabling airplane mode, deleting suspicious apps, and updating the operating system.
Winsage
July 9, 2025
Calne-based Black Nova Designs has warned that Microsoft will cease support for Windows 10 in three months, which will leave millions of users without security updates or technical assistance, increasing their vulnerability to cyber threats. Managing director Kyle Holmes noted the lack of awareness about this change and emphasized the risks involved. The company recommends six IT tips for businesses: 1. Upgrade from Windows 10 promptly, especially for machines older than 2018. 2. Regularly back up data and maintain robust antivirus protection, with services starting at £60+VAT per month. 3. Strengthen passwords to mitigate vulnerabilities. 4. Verify that correct Microsoft licenses are being used to avoid potential fines. 5. Ensure proper ownership and access to website domains. 6. Seek Cyber Essentials certification to demonstrate adherence to cybersecurity best practices. Black Nova Designs supports over 1,000 clients across the UK, focusing on cybersecurity and proactive IT management.
Winsage
April 29, 2025
Microsoft has introduced a no-reboot patching feature for Windows 11 and announced hotpatching costs for Windows Server 2025. Windows 7 and Windows Server 2008 R2 have reached their end-of-support status and lack official security patches. However, users of these legacy systems can utilize a micro patching service called 0patch, which delivers micro patches to address specific vulnerabilities without requiring system reboots. On April 29, 2023, Mitja Kolsek, CEO of ACROS Security, announced that support for Windows 7 and Windows Server 2008 R2 would be extended until January 2027 due to high demand. These micro patches are currently the only available security updates for these legacy versions.
BetaBeacon
April 3, 2025
Google's decision to introduce gaming capabilities in cars through Android Auto has faced criticism from experts who fear it may lead to distractions on the road and make vehicles vulnerable to cyber attacks. Akash Mahajan, CEO of Kloudle, highlighted the increased security risks associated with adding gaming features to cars.
Search