Tag: cyber-security-news

  • Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution

    Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution A critical security flaw in Forcepoint One DLP Client has been disclosed, allowing attackers to bypass vendor-implemented Python restrictions and execute arbitrary code on enterprise endpoints. The vulnerability, tracked as CVE-2025-14026, undermines the data loss prevention security controls designed to protect sensitive organizational data. The…

  • 10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026

    10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026 Vulnerability Assessment and Penetration Testing (VAPT) tools form the cornerstone of any cybersecurity toolkit, enabling organizations to identify, analyze, and remediate vulnerabilities across systems, networks, applications, and IT infrastructure. These tools empower proactive security by exposing weaknesses and attack vectors before threat actors can…

  • Top 10 Best Open Source Firewall in 2026

    Top 10 Best Open Source Firewall in 2026 An open-source firewall provides network security by monitoring and controlling traffic based on predefined rules, offering transparency, flexibility, and cost savings through accessible source code that users can modify to suit specific needs. These firewalls function through essential mechanisms like traffic monitoring to analyze incoming and outgoing…

  • New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code

    New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed…

  • New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins

    New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications. The attack combines vishing (voice phishing), spoofed domains, and Google’s own trusted infrastructure to achieve exceptional success rates against organizations worldwide.…

  • Threat Actors Allegedly Promoting New ‘Brutus’ Brute-Force Tool Targeting Fortinet Services

    Threat Actors Allegedly Promoting New ‘Brutus’ Brute-Force Tool Targeting Fortinet Services A threat actor operating under the moniker “RedTeam” has begun advertising a new brute-force attack tool, “Brutus,” designed to target Fortinet services, according to recent dark web intelligence. The tool is priced at $1,500, signaling growing interest in automated credential-stuffing attacks against enterprise infrastructure.…

  • Top 20 Best Endpoint Management Tools – 2026

    Top 20 Best Endpoint Management Tools – 2026 Endpoint management has become essential for modern IT, securing and optimizing devices across hybrid and remote environments. With distributed workforces expanding, demand for robust endpoint management tools reaches new heights in 2026. This guide ranks the top 20 endpoint management tools for 2026, detailing specs, standout features,…

  • Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections

    Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. A threat actor operating under the nickname “Zestix” and his alias “Sentap” has been systematically accessing corporate cloud storage platforms, including…

  • Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System

    Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices. The advisory, identified as ETN-VA-2025-1026, highlights…

  • Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes

    Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes A threat actor operating under the identifier 1011 has publicly claimed to have obtained and leaked sensitive data from NordVPN’s development infrastructure on a dark web forum. The breach reportedly exposes over ten database source codes, along with critical authentication credentials that could…

  • GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

    GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW,…

  • Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data

    Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data QNAP has patched multiple security vulnerabilities in its License Center application that could allow attackers to access sensitive information or disrupt services on affected NAS devices. The issues, tracked as CVE-2025-52871 and CVE-2025-53597, were disclosed on January 3, 2026. QNAP rated the flaws as Moderate severity and confirmed that the issues have been resolved in the latest…

  • Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network

    Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Resecurity deploys synthetic data honeypots to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into false breach claims.​ Resecurity has refined deception technologies for counterintelligence, mimicking enterprise environments to…

  • Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting

    Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting…

  • Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage

    Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage Finnish authorities have detained all 14 crew members of a cargo vessel suspected of deliberately damaging an undersea telecommunications cable connecting Helsinki to Estonia. The ship, named Fitburg, was sailing from St. Petersburg, Russia, to Haifa, Israel, under a St. Vincent and the Grenadines…

  • VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection

    VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection The cybersecurity landscape is witnessing a rise in sophisticated malware that leverages legitimate tools to mask malicious intent. A prime example is VVS Stealer (also styled VVS $tealer). This Python-based malware family has been actively marketed on Telegram since April 2025. This threat…

  • 10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability

    10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability Over 10,000 Fortinet firewalls worldwide remain vulnerable to CVE-2020-12812, a multi-factor authentication (MFA) bypass flaw disclosed over five and a half years ago. Shadowserver recently added the issue to its daily Vulnerable HTTP Report, highlighting persistent exposure amid active exploitation confirmed by Fortinet in…

  • Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts

    Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope—the breaches targeted Telegram accounts specifically, not complete device access. The group…

  • Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack

    Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector. The December 2025 attacks signal a dangerous shift in email-based threats, in which attackers abuse legitimate Google infrastructure rather than spoofing domains or forging…

  • RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware

    RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware A sophisticated threat group has intensified its campaign against organizations by leveraging the latest vulnerabilities in web applications and Internet of Things (IoT) devices. The RondoDoX botnet, tracked through exposed command-and-control logs spanning nine months from March to December 2025, demonstrates a relentless approach to…

  • Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement

    Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application. The attack leverages a professionally crafted email claiming to promote a legitimate wallet solution designed for secure Cardano token…

  • Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

    Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from server memory. With a CVSS score of 8.7 and over 87,000 potentially vulnerable MongoDB…

  • Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics

    Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics After a decade of disappearing from the cybersecurity landscape, the Careto threat group, also known as “The Mask,” has resurfaced with sophisticated new attack methods targeting high-profile organizations. Security researchers have identified fresh evidence of Careto’s activity, revealing how the group…

  • Apache NuttX Vulnerability Let Attackers to Crash Systems

    Apache NuttX Vulnerability Let Attackers to Crash Systems A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The flaw, tracked as CVE-2025-48769 and rated moderate in severity, affects a wide range of NuttX versions and…

  • Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild

    Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild The cybersecurity landscape in 2025 has been marked by an unprecedented surge in critical vulnerabilities, with over 21,500 CVEs disclosed in the first half of the year alone, representing a 16-18% increase compared to 2024. Among these, a select group of vulnerabilities stands out…

  • WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups

    WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups An open-source solution for handling encrypted WhatsApp backups. The wa-crypt-tools suite, hosted on GitHub, decrypts and encrypts .crypt12, .crypt14, and .crypt15 files from WhatsApp and WhatsApp Business, provided users supply the required key file or 64-character key.​ wa-crypt-tools simplifies access to WhatsApp’s end-to-end encrypted backups, which…

  • Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users

    Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users A new wave of GlassWorm malware has emerged, marking a significant shift in targeting strategy from Windows to macOS systems. This self-propagating worm, distributed through malicious VS Code extensions on the Open VSX marketplace, has already accumulated over 50,000 downloads. The fourth wave introduces several…

  • New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks

    New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users into running harmful software on their devices. The tool automates what security experts call ClickFix attacks, where fake error messages push people to manually execute malicious…

  • DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware

    DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. The discovery reveals a level of operational sophistication rarely seen…

  • Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

    Critical IBM API Connect Vulnerability Let Attackers Bypass Logins A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for API management. It grants unauthorized actors…

  • Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation

    Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe security crisis. Advanced AI tools, designed to assist developers, are now being weaponized to automate the creation of sophisticated exploits against enterprise software. This shift fundamentally challenges…

  • Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass

    Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass Dark web forums have become a marketplace for sophisticated malware tools, with threat actors continuously refining their capabilities to stay ahead of security solutions. The latest concerning development involves an emerging AI-powered crypter service that promises unprecedented evasion abilities, putting enterprise environments at…

  • Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

    Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, affects Apache StreamPipes versions 0.69.0 through 0.97.0. The vulnerability stems from a flawed user ID creation…

  • Open-Source C2 Platform AdaptixC2 Released With Enhanced Stability, Performance, and Speed

    Open-Source C2 Platform AdaptixC2 Released With Enhanced Stability, Performance, and Speed The Adaptix Framework team has announced a significant update to AdaptixC2, an open-source post-exploitation and adversarial emulation platform designed for penetration testers. The latest version introduces significant improvements to network tunneling, the user interface, and overall system performance. One of the most notable upgrades focuses…

  • Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

    Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack demonstrates a significant…

  • Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims

    Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER. This malicious software operates as a kernel-level antivirus and endpoint detection response (EDR) process killer, designed to evade and neutralize security defenses.…

  • EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack

    EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised installer files to…

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures

    Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate income tax documents. The attack campaign uses authentic-looking Income Tax Department emails to trick users into downloading a malicious executable disguised as a tax-related…

  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

    New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows clear indicators of AI-assisted development. The campaign, tracked through a unique signature of four mushroom emojis embedded in the string “OUTL,” has been…

  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks

    Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly executed. This perception leads many to believe that modern attackers operate with machine-like precision, seamlessly moving from one objective to another without facing obstacles. However,…

  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

    2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers A coordinated exploitation campaign that generated more than 2.5 million malicious requests against Adobe ColdFusion servers and 47+ other technology platforms during the Christmas 2025 holiday period. The operation was attributed to a single threat actor operating from Japan-based infrastructure. This indicates an advanced scanning…

  • MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

    MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including credentials, session tokens, and personally identifiable information, directly from server memory without requiring authentication. The flaw exists…

  • OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks

    OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks OpenAI has rolled out a critical security update to ChatGPT Atlas, its browser-based AI agent, introducing advanced defenses against prompt injection attacks. The update marks a significant step in protecting users from emerging adversarial threats targeting agentic AI systems. What Are Prompt Injection Attacks? Prompt injection attacks…

  • Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records

    Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Condé Nast, the parent company. The threat actor “Lovely” claims this is just the start, promising to release up to 40 million more records from brands like…

  • MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk

    MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw affecting multiple supported and legacy server versions that allows unauthenticated remote attackers to…

  • Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability

    Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability The chaos surrounding Ubisoft escalated significantly today as the first group of hackers, previously known for silent exploits, initiated a highly visible and disruptive takeover of Rainbow Six Siege servers. Players worldwide are reporting a massive influx of in-game currency, unwarranted bans, and taunting messages…

  • 87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released

    87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score of 7.5.…

  • Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data

    Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data A proof-of-concept (PoC) exploit dubbed “mongobleed” for CVE-2025-14847, a critical unauthenticated memory leak vulnerability in MongoDB’s zlib decompression handling. Dubbed by its creator Joe Desimone as a way to bleed sensitive server memory, the flaw lets attackers remotely extract uninitialized data without credentials,…

  • TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data

    TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data Multiple critical vulnerabilities in TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), formerly part of 1E Client. Affecting Windows versions before 25.11 and select older branches, the flaws stem from improper input validation (CWE-20), potentially enabling attackers on the local network to execute code,…

  • M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users

    M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse session tokens from active users. Potentially gaining unauthorized access to sensitive document management systems. The flaw, tracked as CVE-2025-13008, affects multiple versions across different release branches and carries a high-severity…

  • TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses

    TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses Many Trust Wallet users saw their wallets drained of over $7 million after a security breach in the Chrome browser extension version 2.68.0, released on December 24, 2025. Blockchain investigator ZachXBT first flagged the incident on X, noting a surge in unauthorized outflows from affected…

  • Parrot 7.0 Released with New Penetration Testing and AI Tools

    Parrot 7.0 Released with New Penetration Testing and AI Tools Parrot OS 7.0, codenamed Echo, launches as a complete system rewrite based on Debian 13, bringing KDE Plasma 6, Wayland by default, and fresh penetration testing tools, including a dedicated AI category. This release emphasizes lightweight theming and community-driven spins, marking a pivotal update for…

  • Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems

    Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems A critical vulnerability in LangChain’s core library (CVE-2025-68664) allows attackers to exfiltrate sensitive environment variables and potentially execute code through deserialization flaws. Discovered by a Cyata researcher and patched just before Christmas 2025, the issue affects one of the most popular AI frameworks with…

  • Google Now Allows Users to Change Their @gmail.com Email Address

    Google Now Allows Users to Change Their @gmail.com Email Address For years, one of the most persistent frustrations for Google users has been the inability to alter their primary email address without creating an entirely new account. Whether you are stuck with an unprofessional handle created in high school or simply want a rebrand, Google…

  • 100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild

    100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild As artificial intelligence becomes deeply embedded in enterprise operations and cybercriminal arsenals alike, the Cybersecurity Predictions 2026 landscape reveals an unprecedented convergence of autonomous threats, identity-centric attacks, and accelerated digital transformation risks. Industry experts across leading security firms, government agencies, and research institutions…

  • Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash

    Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as CVE-2025-68615, this security flaw allows remote attackers to trigger a buffer overflow, leading to a service crash or potentially a more severe system compromise.…

  • Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls

    Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and potentially granting unauthorized access to VPNs and admin consoles. Fortinet’s PSIRT team detailed the in-the-wild attacks in a recent blog post, urging admins to audit…

  • Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security

    Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security Microsoft has announced hardware-accelerated BitLocker, a significant security enhancement designed to eliminate performance bottlenecks caused by encryption on modern high-speed NVMe drives. The new technology addresses growing concerns about CPU overhead as storage devices become faster, particularly for users running intensive workloads such as gaming and…

  • Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware

    Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November 2022, using advanced techniques to deliver the MgBot malware. The group employs adversary-in-the-middle attacks combined with DNS poisoning to compromise specific victims across…

  • Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations

    Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to look like legitimate security tools. The attacks began in November 2025 and have compromised multiple companies across information technology, staffing services, and…

  • Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass

    Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software and endpoint detection tools. The tool was posted on an underground forum where criminals gather to buy and sell hacking services.…

  • Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression

    Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication. The flaw resides in MongoDB’s zlib compression implementation and affects multiple versions of the database platform.​ The vulnerability enables client-side exploitation of the MongoDB Server’s zlib…

  • One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware

    One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges our understanding of digital security. Unlike traditional attacks that require user interaction, such on clicking a malicious link or downloading an infected file,…

  • WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users

    WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept exploits and gaming utilities. The malware targets users searching for game cheats, pirated software, and application patches, particularly for popular titles like Rust,…

  • Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised

    Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000 IT systems across the agency and 10 of its 11 regional water basin administrations. The incident affected critical infrastructure responsible for managing the country’s…

  • Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects

    Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects Law enforcement agencies across 19 African nations have achieved a landmark victory against cybercrime. Arresting 574 suspects and dismantling six ransomware variants during Operation Sentinel, a month-long coordinated crackdown that concluded on November 27. The operation, which ran from October 27 to November 27, targeted…

  • Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials

    Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These malicious extensions, active since 2017, have been distributed to over 2,180 users through the…

  • Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan

    Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat actors repurpose benign software to gain complete control over compromised systems while evading traditional security…

  • CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation

    CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the wild. CVE-2023-52163 is a missing authorization vulnerability in Digiever DS-2105 Pro devices. That enables…

  • Hackers Using ClickFix Technique to Hide Images within the Image Files

    Hackers Using ClickFix Technique to Hide Images within the Image Files Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, discovered by Huntress analysts, represents a significant shift in how cybercriminals deliver information-stealing malware…

  • Spotify Music Library With 86M Music Files Scraped by Hacktivist Group

    Spotify Music Library With 86M Music Files Scraped by Hacktivist Group The shadow library known as Anna’s Archive has executed a massive scrape of Spotify, releasing a torrent collection containing approximately 86 million audio tracks and metadata for 256 million songs. The group, which typically focuses on archiving academic papers and books, claims this unauthorized…

  • Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data

    Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data Cyber criminals are changing their tactics by recruiting insiders within organizations instead of relying on traditional attack methods like brute force or social engineering. Recent findings show that employees in banks, telecom companies, and technology firms are…

  • DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks

    DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks A new and ominous player has emerged in the rapidly expanding landscape of “Shadow AI.” Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the darknet that is empowering threat actors to automate cyberattacks, generate illicit content,…

  • U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware

    U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware The U.S. Department of Justice (DOJ) has charged 54 individuals in a sweeping crackdown on a transnational cyber-physical attack network. The indictments, announced by U.S. Attorney Lesley A. Woods, allege a massive conspiracy involving “ATM jackpotting” to fund Tren de Aragua…

  • Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more

    Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, and encrypted passwords from over 1.2 million accounts, underscoring the…

  • 100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild

    100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild Security researchers have identified at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that attackers are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-20393, currently has no available patch,…

  • Claude Opus 4.5 Now Integrated with GitHub Copilot

    Claude Opus 4.5 Now Integrated with GitHub Copilot GitHub has announced the general availability of Claude Opus 4.5, Anthropic’s advanced AI model, across its Copilot platform. This integration enhances AI capabilities for developers using GitHub’s code assistance tools. The Claude Opus 4.5 model is now accessible to users with Copilot Enterprise, Copilot Business, Copilot Pro,…

  • Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra

    Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra Microsoft has begun deploying Baseline Security Mode across Microsoft 365 tenants, a new dashboard in the M365 Admin Center that centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and Entra. Announced at Ignite 2025, this opt-in feature helps administrators quickly assess…

  • Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks

    Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks In a shocking betrayal of industry trust, two former cybersecurity professionals have pleaded guilty to federal charges for launching ransomware attacks against U.S. businesses. The pair, whose day jobs involved helping companies respond to hacks and negotiate ransoms, admitted to moonlighting as cybercriminals in a plot to…

  • CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware

    CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware The Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA) and Canadian Centre for Cyber Security (Cyber Centre), has released updated indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware. The latest update, published on December 19, 2025, includes an…

  • Hackers Weaponize SVG Files and Office Documents to Target Windows Users

    Hackers Weaponize SVG Files and Office Documents to Target Windows Users Cybersecurity researchers have uncovered a sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers. The operation primarily targets manufacturing and government organizations across Italy, Finland, and Saudi Arabia, using highly evasive techniques. Infection chain Multi-Vector Attack Strategy The…

  • Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide

    Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide In a major disruption to remote work and collaboration, Microsoft Teams experienced a significant outage on Friday, affecting thousands of users across multiple regions. Reports of messaging delays, failed message deliveries, and issues with other service functions began surging around 2:30 PM ET…

  • 25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks

    25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks Over 25,000 Fortinet devices worldwide with FortiCloud Single Sign-On (SSO) enabled, leaving them potentially exposed to remote attacks. The finding stems from enhanced device fingerprinting in a new Device Identification report, which scanned global IP addresses and flagged these systems as openly advertising their SSO configuration. FortiCloud…

  • Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response

    Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response Torrance, United States / California, December 19th, 2025, CyberNewsWire Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into Palo Alto Networks’ Cortex XSOAR. The integration embeds…

  • BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service

    BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service A new credential-harvesting campaign has been discovered targeting users of UKR.NET, a popular Ukrainian webmail and news platform. The attacks are linked to BlueDelta, a Russian state-sponsored hacker group also known as APT28, Fancy Bear, and Forest Blizzard. This group has been running…

  • WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls

    WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices. The vulnerability, tracked as CVE-2025-14733, carries a critical severity score…

  • Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data

    Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor’s pattern of exploiting file transfer solutions. The campaign appears to leverage multiple security weaknesses in CentreStack and its sister product Triofox,…

  • University of Sydney Hacked – Students and Staff Data Exposed

    University of Sydney Hacked – Students and Staff Data Exposed The University of Sydney has confirmed a significant data breach affecting thousands of current and former staff members, as well as students and alums. In a message to the university community, Vice-President (Operations) Nicole Gower revealed that suspicious activity was detected in an online IT…

  • China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware

    China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has unveiled a new China-aligned threat actor dubbed LongNosedGoblin. Active since at least September 2023, this advanced persistent threat (APT) group distinguishes itself by leveraging a diverse toolset of custom C#/.NET malware families.…

  • Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays

    Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays A slight delay in keystrokes from a supposed U.S.-based IT worker alerted Amazon to a North Korean infiltrator accessing a corporate laptop. The commands should have zipped from the worker’s machine to Amazon’s Seattle headquarters in under 100 milliseconds. Instead, they trickled in…

  • Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates

    Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates Let’s Encrypt, the nonprofit certificate authority powering free TLS/SSL certificates for millions of websites, announced sweeping updates to its issuance policies. The changes introduce a new “Generation Y” root hierarchy, deprecate TLS client authentication, and progressively shorten certificate lifetimes to align with CA/Browser Forum requirements.…

  • Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide

    Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide A massive botnet targeting Android devices has emerged as one of the most significant threats in the cybersecurity landscape today. Named Kimwolf, this sophisticated malware has compromised approximately 1.8 million Android devices worldwide, including smart TVs, set-top boxes, tablets, and other Android-based systems. Security researchers discovered…

  • Security Measures at NOWPayments: What Businesses Need to Know

    Security Measures at NOWPayments: What Businesses Need to Know When businesses start accepting crypto payments, security is often one of the first concerns. This is completely understandable. Crypto works differently from traditional payments, and many people want to know how their funds and transactions are protected. NOWPayments approaches security in a practical and transparent way.…

  • NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments 

    NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments  Enterprise-Grade Disaster Recovery and MSP Capabilities Now Available  NAKIVO, a leading provider of data protection solutions, has released NAKIVO Backup & Replication v11.1, marking a significant leap forward in protecting virtual environments and empowering managed service providers (MSPs).  After completing the closed beta testing phase, v11.1 has been…

  • Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands

    Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting Secure Email Gateway (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). The attack, spotted since late November 2025 and publicly disclosed on…

  • New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users

    New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, such as “Free VPN Forever,” which conceal malicious payloads within their own interface icons.…

  • Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution

    Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution Google has released Chrome version 143.0.7499.146/.147 to address critical security vulnerabilities that could enable remote code execution on affected systems. The update is now rolling out to Windows and Mac users, with Linux receiving version 143.0.7499.146. Full deployment is expected over the…

  • BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls

    BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls In a sophisticated cyberespionage campaign, the BlindEagle threat actor has once again targeted Colombian government institutions. This latest operation specifically zeroed in on an agency under the Ministry of Commerce, Industry, and Tourism, leveraging a highly effective strategy to bypass standard email security…

  • APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators

    APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators A significant discovery in threat intelligence reveals that APT-C-35, commonly known as DoNot, continues to maintain an active infrastructure footprint across the internet. Security researchers have identified new infrastructure clusters linked to this India-based threat group, which has long been recognized as a state-sponsored actor with…

  • Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure

    Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia’s Main Intelligence Directorate (GRU) and the notorious Sandworm group, represents a major shift in tactics. Instead of focusing…