loader image
SonicWall Risks Rise as Flaws Exploited Again

SonicWall is facing renewed scrutiny after a resurgence of security flaws in its products landed the company on the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) catalog of known exploited vulnerabilities. The network security vendor has appeared on the list regularly, raising concerns among cybersecurity professionals and its customer base about the ongoing exploitation of […]

Fake AI Tools Spread Noodlophile Malware via Facebook

Cybercriminals are using fake artificial intelligence tools to distribute a new strain of malware known as Noodlophile, targeting more than 62,000 individuals through deceptive social media campaigns, according to cybersecurity researchers. Rather than using conventional phishing tactics or cracked software websites, attackers create highly convincing AI-themed platforms to lure victims. These fraudulent tools are promoted […]

Blob URL Phishing Bypasses Email Filters, Hides in Browser

A newly identified phishing technique is exploiting blob URLs to bypass Secure Email Gateways (SEGs) and evade traditional security analysis tools, according to researchers at Cofense. The method leverages blob URIs—browser-generated, temporary data URLs—to create credential harvesting pages that reside solely in the victim’s browser memory. The attack begins with emails linking to allowlisted services […]

Insight Partners Fears Hack Exposed Financial Secrets

Private equity firm Insight Partners suspects that highly sensitive financial data may have been compromised in a recent cyber intrusion, raising concerns over potential fraud risks. The breach, described as involving “weapons-grade” information, could include confidential financial records, placing investors and partners at heightened exposure to identity theft and financial manipulation. While the extent and […]

Germany Seizes eXch Crypto Site in $1.9 Billion Probe

German authorities dismantled the eXch crypto exchange on April 30, 2025, in a coordinated international operation targeting money laundering and illegal trading activities. The Federal Criminal Police Office (BKA), in collaboration with the Central Office for Combating Cybercrime (ZIT) and Dutch financial intelligence agency FIOD, seized the platform’s infrastructure, €34 million in cryptocurrency, and 8 […]

ChatGPT Adds PDF Option for Deep Research Reports

OpenAI’s ChatGPT is rolling out a new feature for its Deep Research tool, allowing users to download research outputs as PDF files. The capability addresses a longstanding user demand for easier sharing and archiving of complex, multi-step research conducted within the platform. Deep Research is designed to assist users with in-depth analysis across layered queries, […]

Linux Kernel Exploit Published for Critical nftables Bug

A proof-of-concept (PoC) exploit has been released for CVE-2024-26809, a critical vulnerability affecting the Linux kernel’s nftables subsystem. The flaw, which allows local privilege escalation, stems from a double-free bug in the nft_pipapo_destroy() function of the netfilter module. Exploiting this involves manipulating overlapping elements in the nft_set_pipapo structure, corrupting the kernel heap and enabling attackers […]

Microsoft Teams to Block Screenshots in Meetings

Microsoft is introducing a new privacy feature for its Teams platform that will block screen captures during meetings, aiming to safeguard sensitive information shared in virtual environments. The “Prevent Screen Capture” capability, slated for global release in July 2025, ensures that any unauthorized attempt to take screenshots results in a blacked-out meeting window, making captured […]

PupkinStealer Malware Loots Logins, Sends Data via Telegram

A new information-stealing malware written in .NET, dubbed PupkinStealer, has emerged, targeting browser credentials and user data with exfiltration conducted via Telegram, cybersecurity firm CYFIRMA said. Detected in April 2025, the malware is attributed to a developer using the alias “Ardent” and reflects a growing trend of threat actors abusing legitimate platforms for command-and-control operations. […]

U.S. Disrupts Botnet, Charges Russians in Crackdown

U.S. authorities have disrupted a major cybercrime operation involving two proxy services—Anyproxy and 5socks—that leveraged infected devices to form a botnet, according to a law enforcement announcement. The takedown targeted infrastructure used to mask malicious online activity by routing traffic through compromised systems without the owners’ knowledge. The operation, which disabled both platforms, marks a […]

20-Year Proxy Botnet Using IoT Devices Dismantled

A decades-old proxy botnet that hijacked thousands of vulnerable internet-connected devices has been dismantled in a coordinated operation involving Lumen Technologies’ Black Lotus Labs, the FBI, the U.S. Department of Justice and the Dutch National Police. Active since 2004, the botnet exploited unpatched Internet of Things (IoT) and end-of-life (EoL) devices, primarily in residential networks, […]

Google Warns ColdRiver Wields New LostKeys Malware

Google has identified a new cyber threat linked to the Russian-backed hacking group ColdRiver, which is deploying an undisclosed malware strain named “LostKeys.” The malware, previously unreported, marks an evolution in the group’s offensive toolkit, signaling heightened capabilities and potential new targets. ColdRiver, known for its persistent cyber-espionage campaigns, appears to be expanding its methods […]