loader image
Russian Hackers Target Firms Backing Ukraine’s Military

A Russian state-linked hacking group known as APT28 is intensifying cyber operations aimed at compromising the digital infrastructure of Western military organizations and private contractors supporting Ukraine. The group is reportedly targeting logistics networks and technology systems that play a critical role in sustaining Ukraine’s defense capabilities. Security analysts indicate that APT28’s campaign is designed […]

ChatGPT Flaw Exposes Users to Malicious Image Attacks

A newly disclosed vulnerability in OpenAI’s ChatGPT platform allows attackers to embed malicious SVG and image files into shared conversations, exposing users to cross-site scripting (XSS) attacks, phishing schemes and potentially harmful visual content. Tracked as CVE-2025-43714, the flaw affects the system through March 30, 2025. Security researchers found that ChatGPT improperly renders SVG files […]

iHeartRadio Stations Breached, Data Exposed in Hack

Several radio stations operated by iHeartMedia suffered a data breach in December, exposing sensitive personal information including Social Security numbers and financial data. The breach affected multiple stations under the iHeartRadio brand, one of the largest radio networks in the United States. Details regarding the specific number of individuals impacted or the method by which […]

Cisco Flaw Lets Hackers Seize Wireless Controllers

Cisco Systems Inc. has disclosed a critical vulnerability in its IOS XE Wireless LAN Controllers that could let remote attackers take full control of affected devices without authentication. Tracked as CVE-2025-20188, the flaw carries a maximum CVSS severity score of 10.0 and stems from a hard-coded JSON Web Token in the Out-of-Band Access Point Image […]

IXON VPN Flaws Let Hackers Gain Root on All Systems

IXON, a Dutch provider of industrial remote access solutions, has patched two high-severity vulnerabilities in its VPN Client software that could allow local attackers to escalate privileges to system level on Windows, Linux, and macOS platforms. Tracked as CVE-2025-26168 and CVE-2025-26169, the flaws affect all versions prior to 1.4.4 and were assigned a CVSS score […]

Fake Crypto Ads on Facebook Spread Malware Attack

Malicious advertisements posing as cryptocurrency exchange platforms are circulating on Facebook, distributing malware to unsuspecting users. The ads, designed to mimic legitimate crypto services, lure victims by promising investment opportunities or exclusive trading tools. Once clicked, users are redirected to compromised websites where malware is covertly installed on their devices. This campaign underscores growing concerns […]

Microsoft Extends M365 App Fixes on Windows 10 to 2028

Microsoft will continue delivering security updates for Microsoft 365 (M365) applications running on Windows 10 through 2028, extending support for its productivity suite even as the underlying operating system nears end-of-life. The announcement offers clarity for enterprise users relying on Windows 10 systems, though it highlights a growing divide between application and OS support. While […]

Twilio Denies Breach After Steam 2FA Leak Claim

Twilio Inc. denied reports of a security breach after a threat actor claimed to possess over 89 million Steam user records, including one-time access codes. In a statement to BleepingComputer, the communications platform said it had not been compromised, countering allegations that its systems were the source of the data leak. The claims emerged online, […]

ENISA Unveils Guide to Test Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has published a new *Handbook for Cyber Stress Testing*, designed to assist national authorities in evaluating the cybersecurity posture and operational resilience of critical sector entities. The document outlines a structured approach for conducting cyber stress tests, offering guidance on planning, execution and evaluation of results. This initiative […]

3AM Ransomware Gang Launches Email Bombing Attacks

Threat actors affiliated with the 3AM ransomware group have deployed highly targeted intrusion techniques in early 2024, including email bombing and impersonation of IT support personnel, according to a report from BleepingComputer. The attackers used email bombing — a tactic involving a flood of irrelevant emails — to obscure critical security alerts and distract potential […]

Hackers Lure With Fake VPNs to Spread Winos Malware

Hackers are leveraging counterfeit software installers disguised as popular applications, including LetsVPN and QQ Browser, to distribute the Winos 4.0 malware framework, cybersecurity researchers revealed. The campaign, uncovered by Rapid7 in February 2025, employs a sophisticated multi-stage loader known as Catena to execute the attack. Catena functions as a memory-resident loader, embedding shellcode and configuration-switching […]

ConnectWise Tool Tops List of 2025 Cyber Weapons

ConnectWise ScreenConnect has emerged as the most exploited remote access tool (RAT) in cyberattacks throughout 2025, according to a report by Hackread. The remote desktop solution, commonly used for IT support and system administration, was frequently leveraged by threat actors to gain unauthorized access to networks and systems. Its widespread abuse underscores growing security concerns […]