loader image
DDoSecrets Publishes 410GB From TeleMessage Breach

Distributed Denial of Secrets (DDoSecrets), a transparency-focused collective known for publishing leaked data, has added 410 gigabytes of breached data from TeleMessage to its indexing platform. The dataset reportedly includes sensitive communications and internal records, significantly expanding DDoSecrets’ repository of leaked information. TeleMessage, a secure messaging service marketed to enterprises and government agencies, has not […]

Konsola Proget Hit by Seven Security Flaws

CERT Polska has disclosed seven security vulnerabilities in Konsola Proget software, identified as CVE-2025-1415 through CVE-2025-1421. The flaws were reported to the organization and have since been documented on its official platform. Specific technical details surrounding the nature of the vulnerabilities were not provided in the summary, but the sequential CVE identifiers suggest a coordinated […]

Russian Hackers Target Firms Backing Ukraine’s Military

A Russian state-linked hacking group known as APT28 is intensifying cyber operations aimed at compromising the digital infrastructure of Western military organizations and private contractors supporting Ukraine. The group is reportedly targeting logistics networks and technology systems that play a critical role in sustaining Ukraine’s defense capabilities. Security analysts indicate that APT28’s campaign is designed […]

Fake Chrome Extensions Mimic Fortinet to Steal Data

A malicious campaign targeting Google Chrome users is leveraging more than 100 fake browser extensions to steal data and execute remote commands. The extensions, available through the Chrome Web Store, masquerade as legitimate services including Fortinet security tools, YouTube utilities, VPNs, AI assistants, and cryptocurrency platforms. Once installed, the extensions covertly exfiltrate browser cookies and […]

ChatGPT Flaw Exposes Users to Malicious Image Attacks

A newly disclosed vulnerability in OpenAI’s ChatGPT platform allows attackers to embed malicious SVG and image files into shared conversations, exposing users to cross-site scripting (XSS) attacks, phishing schemes and potentially harmful visual content. Tracked as CVE-2025-43714, the flaw affects the system through March 30, 2025. Security researchers found that ChatGPT improperly renders SVG files […]

3AM Ransomware Gang Launches Email Bombing Attacks

Threat actors affiliated with the 3AM ransomware group have deployed highly targeted intrusion techniques in early 2024, including email bombing and impersonation of IT support personnel, according to a report from BleepingComputer. The attackers used email bombing — a tactic involving a flood of irrelevant emails — to obscure critical security alerts and distract potential […]

Hackers Lure With Fake VPNs to Spread Winos Malware

Hackers are leveraging counterfeit software installers disguised as popular applications, including LetsVPN and QQ Browser, to distribute the Winos 4.0 malware framework, cybersecurity researchers revealed. The campaign, uncovered by Rapid7 in February 2025, employs a sophisticated multi-stage loader known as Catena to execute the attack. Catena functions as a memory-resident loader, embedding shellcode and configuration-switching […]

ConnectWise Tool Tops List of 2025 Cyber Weapons

ConnectWise ScreenConnect has emerged as the most exploited remote access tool (RAT) in cyberattacks throughout 2025, according to a report by Hackread. The remote desktop solution, commonly used for IT support and system administration, was frequently leveraged by threat actors to gain unauthorized access to networks and systems. Its widespread abuse underscores growing security concerns […]

Telefónica Update Triggers Telecom Outage Across Spain

Telecommunications services across Spain suffered a widespread outage on Tuesday, May 20, 2025, following a scheduled network update by Telefónica that triggered a cascading failure across multiple carriers. Fixed-line and mobile services were disrupted nationwide, with Madrid, Barcelona and other urban centers reporting significant connectivity issues. Major providers including Movistar, Orange, Vodafone, Digimobil and O2 […]

Fake Chrome Extensions Steal Logins, Inject Ads

More than 100 malicious Chrome browser extensions have been discovered hijacking user sessions, stealing credentials, and injecting unwanted ads, according to recent findings. The campaign, active since at least February 2024, involves an unidentified threat actor who has developed and distributed the rogue extensions under the guise of legitimate utilities and productivity tools. The extensions […]

Procolored Site Spread Malware-Loaded Software for Months

Procolored, a printer manufacturer, distributed malicious software through its official website for several months, exposing users to cybersecurity threats. Dozens of downloadable programs available on the site were found to contain information stealer malware and a backdoor, according to a report by *SecurityWeek*. The infected software potentially allowed attackers to harvest sensitive user data and […]

SIM Swapper Jailed for Hijacking SEC’s X Account

A cybercriminal involved in a SIM-swapping scheme that led to the hijacking of the U.S. Securities and Exchange Commission’s account on X (formerly Twitter) has been sentenced to prison. Authorities linked the scammer to the high-profile breach, which underscored persistent vulnerabilities in mobile-based authentication systems widely used across government and corporate platforms. The attacker exploited […]