Sourabh Verma

All posts by Sourabh Verma

Sourabh is a Cybersecurity Analyst at Barracuda. He's a security expert. Sourabh supports our XDR service delivery and is highly skilled at analyzing security events to detect cyber threats, helping keep our partners and their customers protected.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: PromptSpy Android malware abusing Google Gemini AI

Cybersecurity Threat Advisory: PromptSpy Android malware abusing Google Gemini AI

Reported by SecurityWeek on February 20, 2026, PromptSpy is a newly identified Android malware family developed by threat actors. Its standout capability is using Google Gemini at runtime to analyze on‑screen content and help the malware remain installed and active...

/ March 2, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: ZeroDayRAT enables takeover on Android & iOS

Cybersecurity Threat Advisory: ZeroDayRAT enables takeover on Android & iOS

A new commercial mobile spyware platform, ZeroDayRAT, is being promoted to cybercriminals on Telegram as a tool that provides full remote control of compromised Android and iOS devices. Researchers at mobile threat hunting company iVerify describe it as a “complete...

/ February 13, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Tsundere Bot malware loader

Cybersecurity Threat Advisory: Tsundere Bot malware loader

A new malware loader, Tsundere Bot, is increasingly used by criminal Initial Access Brokers (IABs) to compromise corporate environments and pave the way for ransomware attacks. Recent public reporting links Tsundere Bot to ClickFix‑style phishing, malicious loaders delivered through user...

/ February 3, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical FortiCloud bypass remains unpatched

Cybersecurity Threat Advisory: Critical FortiCloud bypass remains unpatched

Fortinet has confirmed that critical authentication bypass vulnerabilities affecting FortiCloud Single Sign-On (SSO) remain exploitable, even in environments that have already applied recent patches. Attackers are actively abusing these flaws, and Fortinet expects to issue additional fixes within the next...

/ January 26, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apache Tika vulnerability

Cybersecurity Threat Advisory: Apache Tika vulnerability

A maximum-severity Extensible Markup Language (XML) External Entity (XXE) injection vulnerability has been disclosed in Apache Tika, tracked as CVE-2025-66516 with a CVSS score of 10.0. Review this Cybersecurity Threat Advisory now to mitigate your risk and potential impact. What...

/ December 10, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: 7-Zip symbolic link vulnerability

Cybersecurity Threat Advisory: 7-Zip symbolic link vulnerability

Attackers are actively exploiting a high-severity 7-Zip vulnerability, CVE-2025-11001. Attackers use malicious archives to abuse symbolic links, forcing writes outside the intended extraction directory and enabling remote code execution (RCE) when users interact. Review this Cybersecurity Threat Advisory for remediation...

/ November 25, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall VPNs targeted by Akira ransomware

Cybersecurity Threat Advisory: SonicWall VPNs targeted by Akira ransomware

Akira ransomware operators have launched an aggressive campaign targeting SonicWall VPN appliances. Attackers have already breached accounts protected by multi-factor authentication (MFA) successfully, leveraging vulnerabilities in SonicWall Secure Mobile Access (SMA) and SSL-VPN portals. The campaign is characterized by rapid...

/ September 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Microsoft has disclosed a serious zero-day vulnerability in the Web Distributed Authoring and Versioning (WebDAV) protocol, identified as CVE-2025-33053, with a CVSS score of 8.8. Actively exploited by the Stealth Falcon APT group, this vulnerability enables remote code execution (RCE)...

/ June 30, 2025