loader image
PowerSchool Paid Ransom, Hackers Target Teachers

PowerSchool, a widely used educational technology platform in North America, reportedly paid a ransom following a cyberattack. Despite the payment, hackers have shifted tactics and are now targeting individual teachers, according to cybersecurity sources. The attackers are leveraging stolen data to intimidate educators, threatening to expose sensitive information unless additional demands are met. The incident […]

20-Year Proxy Botnet Using IoT Devices Dismantled

A decades-old proxy botnet that hijacked thousands of vulnerable internet-connected devices has been dismantled in a coordinated operation involving Lumen Technologies’ Black Lotus Labs, the FBI, the U.S. Department of Justice and the Dutch National Police. Active since 2004, the botnet exploited unpatched Internet of Things (IoT) and end-of-life (EoL) devices, primarily in residential networks, […]

Google Warns ColdRiver Wields New LostKeys Malware

Google has identified a new cyber threat linked to the Russian-backed hacking group ColdRiver, which is deploying an undisclosed malware strain named “LostKeys.” The malware, previously unreported, marks an evolution in the group’s offensive toolkit, signaling heightened capabilities and potential new targets. ColdRiver, known for its persistent cyber-espionage campaigns, appears to be expanding its methods […]

South African Accounts Target Zelensky in Campaign

A coordinated influence campaign targeting Ukraine’s president has been traced to a network of South African influencers-for-hire, according to new findings from the Atlantic Council’s Digital Forensic Research Lab (DFRLab). The analysis identified more than 40 social media accounts involved in the effort, which aimed to manipulate online discourse through traffic amplification tactics. The campaign […]

North Korea Hackers Target South Korea in Spy Campaign

A North Korean-linked hacking group known as APT37, also referred to as ScarCruft, has launched a fresh cyber-espionage campaign targeting South Korean entities with ties to national security, analysts at cybersecurity firm Genians said. The group is reportedly using phishing tactics to infiltrate organizations and extract sensitive information. The campaign highlights ongoing cyber threats from […]

VMware, SharePoint Hacked in $435,000 Pwn2Own Blitz

Security researchers disclosed a series of critical zero-day vulnerabilities affecting major enterprise platforms during Day Two of the Pwn2Own Berlin 2025 contest, with total winnings reaching $435,000. Hosted at OffensiveCon, the event featured successful exploits targeting VMware ESXi, Microsoft SharePoint, Mozilla Firefox, and Red Hat Enterprise Linux. In a first for the contest, a researcher […]

Akamai, Microsoft Clash Over ‘BadSuccessor’ Flaw Patch

Akamai has identified a privilege escalation vulnerability in Windows Server 2025, which it is calling ‘BadSuccessor’, raising concerns over Microsoft’s decision not to release an immediate fix. The flaw, according to Akamai, could allow attackers to escalate privileges on affected systems, posing a potential risk to enterprise environments relying on the upcoming server version. Despite […]

UK Says Legal Aid Hack Exposed Sensitive Applicant Data

The U.K. government has confirmed a significant data breach involving the Legal Aid Agency, resulting in the potential exposure of a large volume of sensitive personal information. According to officials, the compromised data pertains to individuals who applied for legal aid, raising concerns that the information may now be in the hands of cybercriminals. The […]

CompTIA Launches SecOT+ to Bridge OT Cyber Gap

CompTIA has introduced a new cybersecurity certification, SecOT+, designed to bridge the skills gap between information technology (IT) and operational technology (OT) professionals. The initiative targets a growing need for cybersecurity expertise in industrial environments, where the convergence of IT and OT systems has introduced new vulnerabilities. The SecOT+ certification aims to equip workers with […]

Claude 4 Cuts Vibe Coding Errors by 25%, Boosts Speed

Lovable, a company specializing in Vibe coding, reported a 25% reduction in syntax errors after adopting Claude 4, the latest iteration of the large language model developed by Anthropic. In addition to improved coding accuracy, the company said its development process became 40% faster with the tool’s integration. The update reflects the growing trend of […]

Langflow RCE Flaw Rated 9.8 Joins CISA Risk List

A critical vulnerability affecting Langflow, a popular low-code platform for developing agentic AI workflows, has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) Catalog. The flaw, identified as a remote code execution (RCE) bug with a CVSS severity score of 9.8, poses a significant threat to systems utilizing […]

Microsoft Unveils AI Agents to Control Windows Settings

Microsoft on Thursday introduced new artificial intelligence agents designed to streamline user interaction with Windows settings, as part of its latest Copilot+ PC experience rollout. The tools aim to simplify the process of configuring and customizing Windows devices by allowing AI to make system adjustments on behalf of users. The announcement highlights Microsoft’s continued investment […]