loader image
Google Calendar Abused to Hide Stealthy NPM Malware

A newly discovered malicious package in the NPM ecosystem is leveraging Google Calendar as a covert communication channel, allowing attackers to evade traditional detection mechanisms. The malware uses the calendar service as a “middleman” to receive commands and exfiltrate data, masking its activity behind legitimate infrastructure. In addition to this novel approach, the package employs […]

SAP Cyberattack Spreads, Echoes Typhoon APT Tactics

A wave of zero-day cyberattacks targeting SAP, Europe’s largest software maker, is expanding, with hundreds of victims identified globally. The scale and sophistication of the campaign have drawn comparisons to operations conducted by Salt Typhoon and Volt Typhoon—advanced threat groups linked to state-backed cyber activity. Although the full extent of the breach remains unclear, the […]

Zimbra Hack Hits 129,000 Servers; Sednit Suspected

A critical cross-site scripting (XSS) vulnerability tracked as CVE-2024-27443 has impacted more than 129,000 Zimbra Collaboration Suite servers worldwide, according to cybersecurity sources. The flaw has drawn scrutiny due to suspected exploitation by Sednit, a threat group believed to have ties with advanced persistent threat operations. The vulnerability allows attackers to inject malicious scripts into […]

Coinbase Fires Staff After Breach Hits 70,000 Users

Coinbase has confirmed that an internal breach compromised the personal data of approximately 70,000 users, following the discovery that support staff were bribed. The cryptocurrency exchange said the involved employees have been identified and terminated. The breach raises concerns about insider threats within digital asset platforms, particularly as Coinbase continues to expand its global operations. […]

Cybersecurity Pay 2025 Rises for Top Tech, Falls Elsewhere

Cybersecurity salaries are showing notable divergence heading into 2025, with specialized roles commanding higher pay while generalist and support positions see compensation stagnate, according to CyberSN’s 2025 Salary Data Report. The report highlights growing demand for advanced technical expertise and leadership capabilities, which are driving salary increases for professionals in those segments. In contrast, positions […]

O2 UK Fixes Flaw That Exposed Caller Location Data

O2 UK has addressed a security vulnerability in its implementation of Voice over LTE (VoLTE) and WiFi Calling technologies that exposed mobile users’ general location and unique identifiers. The flaw allowed anyone who placed a call to a target number to potentially extract sensitive metadata, including details that could reveal the recipient’s approximate whereabouts. The […]

UTC Joins ISASecure to Boost Utility Cyber Standards

The Utilities Technology Council (UTC) has joined ISASecure, a globally recognized cybersecurity certification program, in a move aimed at bolstering cybersecurity standards across utility infrastructure. The collaboration is expected to enhance the resilience of operational technology (OT) systems that underpin critical utility services. By aligning with ISASecure, UTC seeks to advance the development and implementation […]

Self-Spreading Malware Turns Docker into Dero Botnet

A newly discovered malware strain is targeting misconfigured Docker API endpoints, transforming exposed containers into nodes of a growing botnet used to mine Dero cryptocurrency. The campaign is distinguished by its self-propagating, worm-like behavior, allowing the malware to autonomously spread to other vulnerable Docker instances without requiring manual intervention. Security researchers at Kaspersky observed the […]

Microsoft Warns Hackers Exploit Apache Pinot Flaws

Microsoft is warning organizations that attackers are exploiting misconfigured Apache Pinot instances to access sensitive information. According to the company, improperly secured deployments of the open-source real-time analytics platform have created vulnerabilities that malicious actors are actively targeting. These misconfigurations can expose internal data, potentially leading to data breaches or further compromise of enterprise systems. […]

NETSCOUT Warns AI-Fueled DDoS Threatens Infrastructure

NETSCOUT issued a warning about a rising wave of distributed denial-of-service (DDoS) attacks powered by artificial intelligence, raising alarms over potential threats to critical infrastructure. The company highlighted that the use of AI is amplifying the scale and sophistication of these cyberattacks, making them harder to detect and mitigate. With more systems relying on automation […]

SonicWall VPN Flaw Exploited in Attacks Prompts Fix

SonicWall is urging administrators to immediately patch three security vulnerabilities found in its Secure Mobile Access (SMA) appliances, warning that one of the flaws is currently being exploited in active attacks. The company issued the alert to its customer base, emphasizing the critical nature of the vulnerabilities and the risk posed to networks using unpatched […]

MirrorFace Hits Japan, Taiwan With Spy Malware Duo

The cyber-espionage group known as MirrorFace has launched a targeted campaign against government agencies and public institutions in Japan and Taiwan, deploying advanced malware tools to infiltrate sensitive systems. According to findings from Trend Micro in March 2025, the group utilized spear-phishing tactics to deliver malicious payloads, including a custom malware strain dubbed ROAMINGMOUSE and […]