SECURITY 120
- US offers $10 million bounty for info on Russian FSB hackers
- Google fixes actively exploited Android flaws in September update
- Azure AD Credentials Exposed in Public App Settings File
- Supply-chain attack hits Zscaler via Salesloft Drift, leaking customer info
- Hidden Commands in Images Exploit AI Chatbots and Steal Data
- WhatsApp patches vulnerability exploited in zero-day attacks
- Velociraptor incident response tool abused for remote access
- Nissan confirms design studio data breach claimed by Qilin ransomware
- Hook Version 3 The Banking Trojan with The Most Advanced Capabilities
- Critical Docker Desktop flaw lets attackers hijack Windows hosts
- Anatsa Android Banking Trojan Now Targeting 830 Financial Apps
- APT36 hackers abuse Linux .desktop files to install malware in new attacks
- Hackers Weaponize QR Codes Embedded with Malicious Links to Steal Sensitive Information
- Major password managers can leak logins in clickjacking attacks
- New Research Links VPN Apps, Highlights Security Deficiencies
- Legitimate Chrome VPN Extension Turns to Browser Spyware
- Web Hosting Firms in Taiwan Attacked by Chinese APT for Access to High-Value Targets
- Researcher to release exploit for full auth bypass on FortiWeb
- Critical RCE Vulnerability in Cisco Firewall Management Software Under Active Exploitation
- PhantomCard New NFC-driven Android malware emerging in Brazil
- North Korean Kimsuky hackers exposed in alleged data breach
- Netherlands Citrix NetScaler Flaw CVE-2025-6543 Exploited to Breach Critical Organizations
- Cybersecurity Firm Profero Cracks DarkBit Ransomware Encryption
- New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP
- Google's August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild
- U.S. Judiciary confirms breach of court electronic records service
- Google suffers data breach in ongoing Salesforce data theft attacks
- SonicWall investigates possible zero-day amid Akira ransomware surge
- Cursor IDE Persistent Code Execution via MCP Trust Bypass
- Cisco Says User Data Stolen in CRM Hack
- Mozilla flags phishing wave aimed at hijacking trusted Firefox add-ons
- LegalPwn Attack Tricks GenAI Tools Into Misclassifying Malware as Safe Code
- Fake Telegram Premium Site Distributes New Lumma Stealer Variant
- Critical Vulnerability in NestJS Devtools Localhost RCE via Sandbox Escape
- AI-powered Cursor IDE vulnerable to prompt-injection attacks
- Dahua Camera flaws allow remote hacking. Update firmware now
- UNC2891 Bank Heist Physical ATM Backdoor & Linux Forensic Evasion Evasion
- ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH
- Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms
- Organizations Warned of Exploited PaperCut Flaw
- Attackers Actively Exploiting Critical Vulnerability in Alone Theme
- ToxicPanda The Android Banking Trojan Targeting Europe
- ToolShell An all-you-can-eat buffet for threat actors
- US nuclear weapons agency hacked in Microsoft SharePoint attacks
- How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance
- Microsoft Fix Targets Attacks on SharePoint Zero-Day
- Livewire Flaw Puts Millions of Laravel Apps at Risk of RCE Attacks
- Four new Android spyware samples linked to Iran's intel agency
- Dell confirms breach of test lab platform by World Leaks extortion group
- Follow-Up Cisco Updates Advisory with Additional Maximum Severity Unauthenticated RCE in ISE and ISE-PIC (CVE-2025-20337)
- The Linuxsys Cryptominer
- Mobile Forensics Tool Used by Chinese Law Enforcement Dissected
- Flaw in Signal App Clone Could Leak Passwords — GreyNoise Identifies Active Reconnaissance and Exploit Attempts
- Tracking Protestware Spread 28 npm Packages Affected by Payload Targeting Russian-Language Users
- Threat Actors Exploit SVG Files in Stealthy JavaScript Redirects
- The Good, the Bad, and the Encoding An SS7 Bypass Attack
- Google Gemini Tricked Into Showing Phishing Message Hidden in Email
- Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
- Nvidia warns its GPUs – even Blackwells – need protection against Rowhammer attacks
- Ransomware Delivered Through GitHub A PowerShell-Powered Attack
- Fix the Click Preventing the ClickFix Attack Vector
- AMD Warns of New Transient Scheduler Attacks Impacting a Wide Range of CPUs
- PerfektBlue 1-click RCE attack
- Critical RCE Vulnerability in mcp-remote CVE-2025-6514 Threatens LLM Clients
- Attackers Inject Code into WordPress Theme to Redirect Visitors
- Malicious pull request infects VS Code extension
- Animation-Driven Tapjacking on Android
- Hackers abuse leaked Shellter red team tool to deploy infostealers
- Ingram Micro outage caused by SafePay ransomware attack
- Critical Sudo bugs expose major Linux distros to local Root exploits
- Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
- Okta observes v0 AI tool used to build phishing sites
- Critical ICS vulnerabilities threaten Mitsubishi Electric and TrendMakers hardware across commercial facilities
- Zero-day Bluetooth gap turns millions of headphones into listening stations
- Taking the shine off BreachForums
- Supply Chain Incident Imperils Glasgow Council Services and Data
- Gogs Remote Command Execution Vulnerability (CVE-2024-56731)
- Decrement by one to rule them all AsIO3.sys driver exploitation
- Cisco ISE Vulnerability Allows Remote Attackers to Execute Malicious Commands
- Realtek Bluetooth Flaw Allows Attackers to Launch DoS Attacks During Pairing
- Don't panic, but it's only a matter of time before critical 'CitrixBleed 2' is under attack
- Cybercriminals Abuse Open-Source Tools To Target Africa’s Financial Sector
- SparkKitty, SparkCat’s little brother A new Trojan spy found in the App Store and Google Play
- Threat actor Banana Squad exploits GitHub repos in new campaign
- Famous Chollima deploying Python version of GolangGhost RAT
- Washington Post's email system hacked, journalists' accounts compromised
- VMOSX Data Leak Info of Thousands of Mac Cloud Users Potentially Exposed Online
- Tenable Fixes Three High-Severity Flaws in Vulnerability Scanner Nessus
- Kali Linux 2025.2 released with 13 new tools, car hacking updates
- Paraguay is Being Targeted by Cybercriminals - 7.4 Million Citizen Records for Sale
- Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction
- New ‘SmartAttack’ Steals Air-Gapped Data Using Smartwatches
- Inside FluxPanel How Phishing Enables Real-Time Ecommerce Checkout Hijacks
- Don't Get Caught in the Headlights - DeerStealer Analysis
- Over 80,000 servers hit as Roundcube RCE bug gets rapidly exploited
- NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073
- Attackers Unleash TeamFiltration Account Takeover Campaign (UNK_SneakyStrike) Leverages Popular Pentesting Tool
- The Evolution of Linux Binaries in Targeted Cloud Operations
- Security Flaws in eMagicOne Store Manager for WooCommerce in WordPress (CVE-2025-5058 and CVE-2025-4603)
- Flask Phishing Kit Targeted Credential Theft Using Open-Source Technology
- Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats
- iMessage Zero-Click Attacks Suspected in Targeting of High-Value Individuals
- Two Botnets, One Flaw Mirai Spreads Through Wazuh Vulnerability
- Sleep with one eye open how Librarian Ghouls steal data by night
- PayU Plugin Flaw Allows Account Takeover on 5000 WordPress Sites
- Grocery wholesale giant United Natural Foods hit by cyberattack
- Operation DRAGONCLONE Chinese Telecommunication industry targeted via VELETRIX & VShell malware
- Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721
- Unmasking Insecure HTTP Data Leaks in Popular Chrome Extensions
- ClickFix Attack Exploits Fake Cloudflare Turnstile to Deliver Malware
- Android Spyware Alert! Fake government app targeting Android users in India!
- Fake WordPress Caching Plugin Used to Steal Admin Credentials
- Criminals Bribed Outsourced Contractors to Steal Coinbase User Data
- Victims risk AsyncRAT infection after being redirected to fake Booking.com sites
- Qualcomm fixes three Adreno GPU zero-days exploited in attacks
- XSSing TypeErrors in Safari
- Zanubis in motion Tracing the active evolution of the Android banking malware
- MATLAB dev confirms ransomware attack behind service outage
- DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers
- Bypassing MTE with CVE-2025-0072