loader image
EDRi Warns EU Against Reopening Landmark GDPR Law

European Digital Rights (EDRi), a civil society group focused on digital rights, has urged the European Commission to uphold the General Data Protection Regulation (GDPR) amid concerns it may be reopened for revision. In a public statement, the organization warned that altering the landmark privacy law could jeopardize fundamental rights and weaken accountability in the […]

FBI Warns AI Voice Scams Mimic U.S. Government

The FBI has issued a warning about a growing wave of scams using artificial intelligence to replicate the voices of U.S. government officials. According to the agency, cybercriminals are leveraging advanced AI tools to create convincing audio deepfakes, deceiving victims into believing they are speaking with federal authorities. These voice-cloning schemes are being used to […]

Hackers Win $1 Million Cracking AI, OS at Pwn2Own Berlin

Hackers earned over $1 million in cash prizes during the Pwn2Own Berlin 2025 competition, where cybersecurity researchers showcased high-impact vulnerabilities across a range of modern digital systems. Participants successfully demonstrated exploits targeting virtual machines, artificial intelligence platforms, web browsers, servers, containers, and operating systems. The event, designed to uncover critical security flaws before they can […]

Russia SpyPress Malware Hacks Webmail to Track Ukraine

A newly identified malware strain linked to Russian threat actors is exploiting webmail platforms to conduct surveillance operations targeting Ukraine, according to cybersecurity researchers. Dubbed “SpyPress,” the malware enables attackers to intercept communications, exfiltrate sensitive data, and monitor victims’ online activity through compromised email accounts. The campaign underscores the continued use of sophisticated cyber-espionage tactics […]

PupkinStealer Malware Hits Windows to Grab Logins, Files

A newly identified malware dubbed PupkinStealer is targeting Windows systems to harvest sensitive user data, cybersecurity researchers say. First detected in April 2025, the .NET-based malware, written in C#, focuses on stealing browser credentials, messaging app sessions, and desktop files. It exfiltrates data through Telegram’s Bot API, a tactic increasingly used by threat actors to […]

SEC X Account Hacker Gets 14-Month Prison Sentence

An Alabama man has been sentenced to 14 months in federal prison for hacking the U.S. Securities and Exchange Commission’s official social media account, an incident that briefly disrupted cryptocurrency markets. The breach occurred in January 2024, when unauthorized access to the SEC’s account was used to publish fraudulent posts. The misleading messages falsely suggested […]

Alabama Confirms Cyberattack, Offers Few Details

Alabama’s state government acknowledged it was the target of a cybersecurity breach but released minimal information about the incident. Officials confirmed the attack occurred but did not specify when it began, how it was carried out, or what systems were affected. The lack of detail leaves questions about the scope of the breach and whether […]

ENISA Unveils Guide to Test Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has published a new *Handbook for Cyber Stress Testing*, designed to assist national authorities in evaluating the cybersecurity posture and operational resilience of critical sector entities. The document outlines a structured approach for conducting cyber stress tests, offering guidance on planning, execution and evaluation of results. This initiative […]

Eventin WordPress Bug Lets Hackers Control 10,000 Sites

More than 10,000 WordPress websites are at risk following the disclosure of a critical vulnerability in the Eventin plugin, a popular tool developed by Themewinter for event management. Tracked as CVE-2025-47539, the flaw enables unauthenticated attackers to create administrator accounts without user interaction, granting full control over affected sites. Security researchers from Patchstack identified the […]

SAP Cyberattack Spreads, Echoes Typhoon APT Tactics

A wave of zero-day cyberattacks targeting SAP, Europe’s largest software maker, is expanding, with hundreds of victims identified globally. The scale and sophistication of the campaign have drawn comparisons to operations conducted by Salt Typhoon and Volt Typhoon—advanced threat groups linked to state-backed cyber activity. Although the full extent of the breach remains unclear, the […]

VMware, SharePoint Hacked in $435,000 Pwn2Own Blitz

Security researchers disclosed a series of critical zero-day vulnerabilities affecting major enterprise platforms during Day Two of the Pwn2Own Berlin 2025 contest, with total winnings reaching $435,000. Hosted at OffensiveCon, the event featured successful exploits targeting VMware ESXi, Microsoft SharePoint, Mozilla Firefox, and Red Hat Enterprise Linux. In a first for the contest, a researcher […]

EU Court Bans Tracking-Based Ads Over Consent Rules

A Brussels Court of Appeal ruled Wednesday that tracking-based online advertising practices violate European privacy laws, citing insufficient consent mechanisms. The decision targets the core of how digital advertisers operate across the EU, where user data is routinely collected and shared to serve personalized ads. The court found that current implementations of consent do not […]