A Russian-speaking cybercriminal group known as 'Crazy Evil' has reportedly stolen over $5 million through targeted social media scams, utilizing malware such as StealC, AMOS, and Angel Drainer. These scams specifically target cryptocurrency holders, employing tailored phishing tactics to drain digital wallets. In addition to this, Google has addressed 47 security vulnerabilities in Android, including a critical flaw (CVE-2024-53104) that allows attackers to escalate privileges through the USB Video Class driver. Microsoft has also issued critical patches for vulnerabilities in its Azure AI Face Service and Microsoft Account, with one flaw (CVE-2025-21415) having a public exploit. Furthermore, North Korean hackers are deploying FERRET malware via fake job interviews on macOS, posing as recruiters to lure victims into compromising their systems. These developments highlight ongoing cybersecurity threats affecting both individual users and major tech platforms.
By me @Forbes: Why you really shouldn't change your X password. Great bit of analysis from @LabsSentinel. #infosec https://t.co/iuZfy4Sewk
By me @Forbes: Oh great, Microsoft Accounts have been vulnerable to a CWE-862 authentication attack. What you need to know about CVE-2025-21396. #infosec https://t.co/hJxdsKLq0Z
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections: https://t.co/jD9iav4eTn by The Hacker News #infosec #cybersecurity #technology #news