loader image
Apache Parquet Java Flaw Opens Door to RCE Attacks

A critical vulnerability has been identified in Apache Parquet Java, an open-source columnar storage format, potentially exposing systems to remote code execution (RCE) attacks. The flaw, tracked as CVE-2025-46762, affects versions 1.15.1 and earlier, according to a disclosure. Attackers could exploit the vulnerability to execute arbitrary code on targeted systems, putting enterprise data and services […]

UK Legal Aid Agency Probes Breach, Data at Risk

The UK’s Legal Aid Agency is investigating a cybersecurity incident that may have exposed sensitive financial information, the agency warned law firms. The breach, which has not yet been publicly detailed, could impact the financial data handled by the agency, which operates under the Ministry of Justice and manages billions of pounds in legal funding. […]

Microsoft Bookings Flaw Let Hackers Hijack Meetings

A security flaw in Microsoft Bookings exposed users to significant risks by allowing attackers to alter meeting invitations and calendar details through HTML injection, researchers at ERNW reported. The vulnerability, rooted in inadequate input validation within the Bookings API, impacted fields such as `serviceNotes`, `additionalNotes`, and `body.content`. Exploitation was particularly effective via the “Reschedule” feature, […]

SonicWall Risks Rise as Flaws Exploited Again

SonicWall is facing renewed scrutiny after a resurgence of security flaws in its products landed the company on the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) catalog of known exploited vulnerabilities. The network security vendor has appeared on the list regularly, raising concerns among cybersecurity professionals and its customer base about the ongoing exploitation of […]

Apple macOS Sandbox Flaw Gets Public Exploit Release

A proof-of-concept exploit targeting a recently patched macOS flaw has been made public, raising concerns among cybersecurity experts. The vulnerability, tracked as CVE-2025-31258, affects the RemoteViewServices framework, which handles content rendering and preview features in macOS. The flaw allows malicious applications to partially escape Apple’s sandbox protections, potentially exposing sensitive system resources and user data. […]

Google Boosts Android 16 With New Security Tools

Google is introducing a range of new security enhancements in its upcoming Android 16 operating system update, aiming to bolster protection for mobile users. The upgrade, announced this week, includes a suite of advanced features designed to detect and prevent scams, secure personal data, and enhance user privacy. While specific tools were not detailed in […]

Europol Dismantles $3 Million Cyber Fraud Syndicate

Law enforcement agencies from five European nations, with coordination from Europol and Eurojust, have dismantled a cross-border cybercrime operation responsible for defrauding over 100 victims through fraudulent investment schemes, according to Infosecurity Magazine. The transnational syndicate is accused of orchestrating sophisticated scams that generated illicit profits exceeding 3 million euros. Authorities say the group lured […]

Meta Wins Irish Approval for EU AI Training Plans

Ireland’s Data Protection Commission (DPC) has approved Meta’s plans to use data from European Union users to train its artificial intelligence systems, clearing a regulatory hurdle for the tech giant. The decision marks a significant step forward in Meta’s ambitions to develop AI capabilities using data sourced from its platforms across the EU. However, the […]

EC-Council Wins UK Nod for 5 Cybersecurity Courses

EC-Council has secured reaccreditation from the United Kingdom’s National Cyber Security Centre (NCSC), reaffirming the credibility of five of its cybersecurity certification programs. The renewed endorsement strengthens EC-Council’s standing in the global cybersecurity training landscape, particularly within professional and government sectors that rely on recognized qualifications to meet industry standards. The reaccreditation ensures that EC-Council’s […]

Operation Endgame Seizes 300 Domains in Cyber Raid

An ongoing international crackdown on cybercrime has resulted in the takedown of 300 domains linked to ransomware activity, according to an announcement from authorities leading the effort. Dubbed Operation Endgame, the initiative targets key infrastructure used by cybercriminals to orchestrate and deploy ransomware campaigns across global networks. The seized domains were reportedly central to the […]

Lumma Malware Busted in Global Cybercrime Crackdown

Global law enforcement agencies and technology firms have coordinated an international operation to disrupt Lumma, a widely used infostealer favored by cybercriminal gangs. Authorities from the United States, Europe, and Japan executed the takedown with support from major tech companies, including Microsoft and Cloudflare. Lumma has been identified as a prevalent tool in the cybercrime […]

Hazy Hawk Hijacks DNS to Target CDC, Fortune 500 Firms

A newly identified threat actor known as “Hazy Hawk” is exploiting misconfigured Domain Name System (DNS) records to hijack subdomains tied to abandoned cloud services, according to researchers at Infoblox. Active since at least December 2023, Hazy Hawk targets high-profile organizations—including government agencies, Fortune 500 companies, and universities—by leveraging a technique called CNAME hijacking. The […]