loader image
**Microsoft Patches Critical Remote Desktop Flaws**

Microsoft has patched two critical vulnerabilities in its Remote Desktop services that could allow attackers to execute malicious code remotely, the company said in its May 2025 Patch Tuesday release. The flaws—tracked as CVE-2025-29966 and CVE-2025-29967—affect the Remote Desktop Client and Gateway Service. Both are heap-based buffer overflow vulnerabilities with high CVSS scores, enabling remote […]

Microsoft Fixes 75 Flaws, 11 Critical in May Patch

Microsoft released security updates addressing 75 vulnerabilities as part of its May Patch Tuesday rollout, with 11 of those flaws rated as critical in severity. The update includes fixes for five vulnerabilities that are currently being exploited in the wild, posing heightened risk to users and organizations. Additionally, two other vulnerabilities patched in this cycle […]

Google Boosts Android 16 With New Security Tools

Google is introducing a range of new security enhancements in its upcoming Android 16 operating system update, aiming to bolster protection for mobile users. The upgrade, announced this week, includes a suite of advanced features designed to detect and prevent scams, secure personal data, and enhance user privacy. While specific tools were not detailed in […]

Chinese Hackers Hit Taiwan Drone, Military Supply Chains

A Chinese-speaking hacking group known as Earth Ammit has disrupted supply chains tied to Taiwan’s drone industry, cybersecurity researchers said. The group reportedly carried out two waves of cyber-espionage campaigns between 2023 and 2024, targeting a wide spectrum of sectors. The affected industries include military, satellite communications, heavy industry, media, technology, software services and healthcare. […]

SAP Fixes Second Zero-Day Used in Server Attacks

SAP has issued security patches to fix a second zero-day vulnerability that was actively exploited in recent cyberattacks targeting its NetWeaver application servers. The flaw, which had not been previously disclosed, allowed attackers to compromise systems before a fix was made available, highlighting the urgency of the update. This marks the second such vulnerability in […]

Andy Frain Breach Exposes Data of 100,000 People

Andy Frain Services, an Illinois-based provider of physical security services, suffered a data breach in October that exposed personal information of more than 100,000 individuals, according to a report by *SecurityWeek*. The cyberattack was allegedly carried out by the Black Basta ransomware group, which claimed responsibility for compromising approximately 750 gigabytes of the company’s files. […]

Tycoon Phishing Kit Adds Encryption, Fingerprint Evasion

A recent update to the Tycoon 2FA phishing kit reveals the deployment of new evasion techniques, including browser fingerprinting and enhanced payload encryption, signaling a continued evolution in cybercriminal tactics. The kit, designed to bypass two-factor authentication (2FA), now incorporates methods that make detection and mitigation increasingly difficult for security systems. Browser fingerprinting allows attackers […]

Google Uses AI on Android to Flag Scam Texts, Fraud

Google is enhancing its Android security capabilities by expanding the reach of its “Scam Detection” tool in Google Messages. The feature, which operates using on-device artificial intelligence, will now identify a broader set of digital fraud attempts, including scam texts and investment-related fraud. By analyzing message content locally on the device, the system flags suspicious […]

Intel Hit by New Spectre Flaw With Data Leak Risk

Researchers at ETH Zurich have uncovered a new method to exploit Intel processors using a variation of the notorious Spectre vulnerability, according to findings published Tuesday. The technique leverages a branch prediction race condition to leak sensitive information from memory, reigniting concerns over speculative execution flaws in modern CPUs. The exploit, which targets Intel’s processor […]

CISA Adds TeleMessage Flaw to Exploited Bugs List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified vulnerability affecting TeleMessage to its Known Exploited Vulnerabilities (KEV) catalog, following a confirmed security breach. The addition signals that threat actors have actively exploited the flaw, prompting federal agencies and organizations to take immediate remediation steps. TeleMessage, a provider of secure messaging […]

Twilio Denies Breach After Steam 2FA Leak Claim

Twilio Inc. denied reports of a security breach after a threat actor claimed to possess over 89 million Steam user records, including one-time access codes. In a statement to BleepingComputer, the communications platform said it had not been compromised, countering allegations that its systems were the source of the data leak. The claims emerged online, […]

Ivanti Patches Zero-Days Used in Code Execution Attacks

Ivanti urged customers on Thursday to apply security patches for its Endpoint Manager Mobile (EPMM) software to address two critical zero-day vulnerabilities. The flaws, which have been actively exploited in the wild, can be chained together by attackers to achieve remote code execution on targeted systems. The company issued the warning after identifying that threat […]