Please turn JavaScript on

Security Risk Advisors

follow.it gives you an easy way to subscribe to Security Risk Advisors's news feed! Click on Follow below and we deliver the updates you want via email, phone or you can read them here on the website on your own news page.

You can also unsubscribe anytime painlessly. You can even combine feeds from Security Risk Advisors with other site's feeds!

Title: A Leader in Cybersecurity Services - Security Risk Advisors

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  9 / week

Message History

Socket’s Threat Research Team identified five malicious Chrome extensions targeting enterprise HR and ERP platforms including Workday, NetSuite, and SuccessFactors. Disclosed on January 15, 2026, the coordinated campaign deployed extensions under publisher names databycloud1104 and softwareaccess, reaching over 2,300 combined users. The exte...


Read full story

Security researchers have identified an active campaign targeting U.S. government and policy organizations with a backdoor known as LOTUSLITE. Acronis attributes this operation with moderate confidence to Mustang Panda, a Chinese state-sponsored advanced persistent threat group also tracked as Earth Pret, HoneyMyte, and Twill Typhoon. Attack...


Read full story

A critical flaw in the WordPress plugin Modular DS allows remote attackers to gain admin-level access to vulnerable websites while bypassing authentication measures. Modular DS is a plugin that can allow hosting providers, developers, and site owners remotely monitor websites with the plugin, manage users, log in, run tasks, perform updates,...


Read full story

Wiz Research disclosed CodeBreach, a supply chain vulnerability in AWS CodeBuild CI pipelines that allowed complete takeover of key AWS GitHub repositories, including the AWS JavaScript SDK repository aws-sdk-js-v3. Reported to AWS on August 25, 2025 and publicly disclosed on January 15, 2026, the vulnerability stemmed from unanchored regex ...


Read full story

deVixor, an Android banking malware distributed through phishing websites impersonating automotive businesses in Iran. Active since October 2025, the malware targets Iranian users with fake vehicle discount offers that trick victims into downloading malicious APK files. Analysis of over 700 samples reveals deVixor evolved from basic SMS harv...


Read full story