loader image
Hackers Earn $260,000 Breaking AI, Windows at Pwn2Own

Hackers earned a total of $260,000 in cash prizes on the first day of Pwn2Own Berlin 2025, a high-profile security competition that rewards researchers for identifying and exploiting software vulnerabilities. Participants demonstrated successful exploits targeting a range of platforms, including Red Hat, Microsoft Windows, Oracle VirtualBox, Docker Desktop, and artificial intelligence technologies. The competition, known […]

Eventin WordPress Bug Lets Hackers Control 10,000 Sites

More than 10,000 WordPress websites are at risk following the disclosure of a critical vulnerability in the Eventin plugin, a popular tool developed by Themewinter for event management. Tracked as CVE-2025-47539, the flaw enables unauthenticated attackers to create administrator accounts without user interaction, granting full control over affected sites. Security researchers from Patchstack identified the […]

Procolored Site Spread Malware-Loaded Software for Months

Procolored, a printer manufacturer, distributed malicious software through its official website for several months, exposing users to cybersecurity threats. Dozens of downloadable programs available on the site were found to contain information stealer malware and a backdoor, according to a report by *SecurityWeek*. The infected software potentially allowed attackers to harvest sensitive user data and […]

SIM Swapper Jailed for Hijacking SEC’s X Account

A cybercriminal involved in a SIM-swapping scheme that led to the hijacking of the U.S. Securities and Exchange Commission’s account on X (formerly Twitter) has been sentenced to prison. Authorities linked the scammer to the high-profile breach, which underscored persistent vulnerabilities in mobile-based authentication systems widely used across government and corporate platforms. The attacker exploited […]

Microsoft Patch Fixes Windows Server Hyper-V Freezes

Microsoft has issued an emergency update to resolve a critical issue affecting Windows Server 2022, where some Hyper-V virtual machines were freezing or restarting without warning. The problem, which impacted system stability and disrupted operations for affected users, prompted the company to act swiftly with a targeted fix. According to Microsoft, the update addresses a […]

DragonForce Hits MSP, Abuses SimpleHelp to Spread

The DragonForce ransomware group has compromised a managed service provider (MSP), leveraging its SimpleHelp remote monitoring and management (RMM) platform to infiltrate and encrypt systems across multiple customer networks. The attackers reportedly used the MSP’s access to execute data theft and encryption operations on downstream clients, highlighting the risks associated with centralized IT service platforms. […]

Atos Unveils Tool to Automate EU Cyber Compliance

Atos has rolled out its SecureHorizons NIS2 Compliance Manager on the ServiceNow platform, aiming to streamline and automate cybersecurity compliance for organizations across the European Union. The new solution is designed to help businesses meet the requirements of the EU’s Network and Information Security Directive (NIS2), which mandates stricter cybersecurity and risk management practices. By […]

Apache Parquet Exploit Tool Targets Critical Flaw

A proof-of-concept exploit has been made publicly available for a critical vulnerability in Apache Parquet, identified as CVE-2025-30065, potentially exposing servers to remote attacks. The flaw carries the highest severity rating, enabling threat actors to easily locate and target unpatched systems. Apache Parquet is a widely used open-source data storage format, and the release of […]

Ascension Health Breach Hit 437,000, U.S. Says

A data breach at Ascension Health in April 2025 affected 437,329 individuals, according to a report filed with the U.S. Department of Health and Human Services. The incident underscores the persistent vulnerabilities tied to third-party software flaws and inadequate identity management practices that continue to challenge healthcare organizations. While specific technical details of the breach […]

F5 Flaw Lets Admins Run Rogue Commands as Root

F5 Networks has disclosed a high-severity command injection vulnerability affecting its BIG-IP products operating in Appliance mode. Tracked as CVE-2025-31644, the flaw resides in an undisclosed iControl REST endpoint and a TMOS Shell (tmsh) command, allowing authenticated attackers to execute arbitrary system commands by bypassing security restrictions. The vulnerability is rated 8.7 on the CVSS […]

Kosovo Man Extradited to U.S. for Dark Web Market

A 33-year-old citizen of Kosovo has been extradited to the United States to face charges in connection with the operation of an illegal online marketplace, U.S. authorities said. The individual is accused of playing a significant role in managing the platform, which allegedly facilitated unlawful transactions over the internet. The extradition underscores ongoing efforts by […]

Windows 10 Update Triggers BitLocker Recovery Errors

A recent Windows 10 update, labeled KB5058379, is triggering unexpected BitLocker recovery prompts on some devices following installation and a system reboot. The cumulative update, pushed as part of Microsoft’s regular release cycle, appears to inadvertently activate the recovery process for BitLocker, the operating system’s built-in encryption feature. Users who applied the update have reported […]