loader image
Zimbra Hack Hits 129,000 Servers; Sednit Suspected

A critical cross-site scripting (XSS) vulnerability tracked as CVE-2024-27443 has impacted more than 129,000 Zimbra Collaboration Suite servers worldwide, according to cybersecurity sources. The flaw has drawn scrutiny due to suspected exploitation by Sednit, a threat group believed to have ties with advanced persistent threat operations. The vulnerability allows attackers to inject malicious scripts into […]

Coinbase Fires Staff After Breach Hits 70,000 Users

Coinbase has confirmed that an internal breach compromised the personal data of approximately 70,000 users, following the discovery that support staff were bribed. The cryptocurrency exchange said the involved employees have been identified and terminated. The breach raises concerns about insider threats within digital asset platforms, particularly as Coinbase continues to expand its global operations. […]

Cybersecurity Pay 2025 Rises for Top Tech, Falls Elsewhere

Cybersecurity salaries are showing notable divergence heading into 2025, with specialized roles commanding higher pay while generalist and support positions see compensation stagnate, according to CyberSN’s 2025 Salary Data Report. The report highlights growing demand for advanced technical expertise and leadership capabilities, which are driving salary increases for professionals in those segments. In contrast, positions […]

O2 UK Fixes Flaw That Exposed Caller Location Data

O2 UK has addressed a security vulnerability in its implementation of Voice over LTE (VoLTE) and WiFi Calling technologies that exposed mobile users’ general location and unique identifiers. The flaw allowed anyone who placed a call to a target number to potentially extract sensitive metadata, including details that could reveal the recipient’s approximate whereabouts. The […]

Akamai, Microsoft Clash Over ‘BadSuccessor’ Flaw Patch

Akamai has identified a privilege escalation vulnerability in Windows Server 2025, which it is calling ‘BadSuccessor’, raising concerns over Microsoft’s decision not to release an immediate fix. The flaw, according to Akamai, could allow attackers to escalate privileges on affected systems, posing a potential risk to enterprise environments relying on the upcoming server version. Despite […]

CompTIA Launches SecOT+ to Bridge OT Cyber Gap

CompTIA has introduced a new cybersecurity certification, SecOT+, designed to bridge the skills gap between information technology (IT) and operational technology (OT) professionals. The initiative targets a growing need for cybersecurity expertise in industrial environments, where the convergence of IT and OT systems has introduced new vulnerabilities. The SecOT+ certification aims to equip workers with […]

UK Says Legal Aid Hack Exposed Sensitive Applicant Data

The U.K. government has confirmed a significant data breach involving the Legal Aid Agency, resulting in the potential exposure of a large volume of sensitive personal information. According to officials, the compromised data pertains to individuals who applied for legal aid, raising concerns that the information may now be in the hands of cybercriminals. The […]

Lumma Infostealer Hit 10 Million Devices: FBI Says

A widespread malware campaign using the Lumma infostealer compromised approximately 10 million systems globally before being disrupted, according to the FBI. The malicious software targeted a broad range of victims, including individuals, businesses, and major corporations such as those in the Fortune 500. Cybercriminals deployed the malware to extract sensitive data from infected machines, enabling […]

Hackers Hijack Paychecks via Fake Payroll Portals

Hackers are leveraging search engine optimization (SEO) poisoning to launch a new wave of payroll fraud attacks, security researchers at ReliaQuest report. By targeting employees on mobile devices, attackers create fake login pages that closely mimic legitimate corporate payroll portals. These spoofed sites appear prominently in search results when users look for company payroll platforms, […]

VMware Fixes NATO-Flagged Flaw Exposing User Data

VMware has released a new batch of security patches addressing multiple software vulnerabilities that could expose users to serious cyber threats, including data leakage, unauthorized command execution, and denial-of-service (DoS) attacks. The most critical flaw among them has been flagged by NATO, underscoring its potential impact on security-sensitive environments. The company did not provide any […]

Russia Orders Tracking App for All Foreigners in Moscow

Russia has enacted a new law mandating that all foreign nationals in the Moscow region install a location-tracking application on their mobile devices, according to a government announcement. The measure is part of a broader strategy aimed at monitoring the movements of non-citizens within the capital and its surrounding areas. The tracking app will reportedly […]

Samlify Flaw Lets Hackers Bypass SSO as Admin Users

A critical vulnerability has been identified in Samlify, a SAML-based Single Sign-On (SSO) library, that enables attackers to bypass authentication and gain administrative access. The flaw allows malicious actors to inject unsigned assertions into otherwise valid SAML responses, effectively tricking the system into granting elevated privileges without proper verification. The vulnerability stems from improper validation […]