loader image
ASUS Routers Hacked in Botnet Attack Using SSH Key

A newly discovered botnet campaign known as “AyySSHush” has compromised more than 9,000 ASUS routers globally, cybersecurity researchers said. The attackers gained persistent remote access by injecting an SSH public key, enabling control that survives reboots and firmware upgrades. Uncovered in March 2025, the campaign exploits two previously unknown authentication bypass flaws and CVE-2023-39780, a […]

Hackers Use Malicious Chargers to Breach Smartphones

Cybersecurity researchers have uncovered a new attack method known as “ChoiceJacking,” which enables malicious charging stations to compromise both Android and iOS devices. Discovered by researchers at Graz University of Technology, the technique bypasses long-standing USB security protections by exploiting flaws in user confirmation mechanisms. The attack combines elements of USB host and accessory protocols, […]

Victoria’s Secret Shuts Website After Cyber Incident

Victoria’s Secret has temporarily taken its website offline following what it described as a “security incident,” disrupting online shopping for customers. The lingerie retailer did not provide specific details about the nature of the breach or what data, if any, may have been affected. The outage, which began earlier this week, has left users unable […]

Microsoft Adds Share, Click to Do in Windows Update

Microsoft has begun rolling out the KB5058499 preview cumulative update for Windows 11 version 24H2, introducing 48 new features and improvements. Among the most notable additions are the enhanced Windows Share functionality and the new Click to Do Preview, both designed to streamline user productivity and interaction. The update is part of a gradual deployment […]

APT41 Hides Malware in Google Calendar Traffic

Chinese state-sponsored hacking group APT41 is deploying a new malware strain dubbed “ToughProgress” that exploits Google Calendar for covert command-and-control (C2) communication, according to cybersecurity analysts. The malicious software uses the popular cloud-based scheduling service to blend its traffic with legitimate operations, making detection significantly more challenging. By embedding commands within calendar event data, the […]

PumaBot Botnet Hacks IoT Devices via SSH Attacks

A newly identified Linux-based botnet known as PumaBot is targeting embedded Internet of Things (IoT) devices by brute-forcing SSH credentials, according to cybersecurity researchers. Written in the Go programming language, PumaBot is designed to infiltrate vulnerable systems and deploy malicious payloads after gaining unauthorized access. The malware specifically targets devices with weak or default SSH […]

Ivanti Blames Open-Source Code as Zero-Days Mount

Ivanti is facing growing scrutiny after disclosing another set of zero-day vulnerabilities affecting its products, raising fresh concerns about the security vendor’s ability to shield users from targeted cyberattacks. The company attributed the latest exploits to unresolved security flaws in unnamed open-source libraries, distancing its proprietary code from the breaches. However, some cybersecurity researchers are […]

Cisco Unveils Duo Tools to Fortify Access Security

Cisco has introduced a new suite of identity and access management (IAM) products and services under its Duo brand, aiming to bolster enterprise security frameworks. The offering, known as Duo Identity and Access Management, is designed to integrate seamlessly with existing cybersecurity infrastructures, enabling organizations to enhance user authentication and access controls without overhauling their […]

Iranian Hacker Guilty in $19 Million Baltimore Attack

An Iranian hacker has pleaded guilty in the U.S. to involvement in a wide-ranging ransomware and extortion operation that inflicted $19 million in damages on the city of Baltimore. The defendant, identified as Sina Gholinejad, also known as Sina Ghaaf, 37, admitted to participating in a scheme that used Robbinhood ransomware to infiltrate and encrypt […]

Dark Partners Gang Drives Global Crypto Thefts Spree

A cybercrime group known as “Dark Partner” is orchestrating widespread cryptocurrency thefts by leveraging a global network of fake software download sites, according to cybersecurity researchers. The fraud operation uses deceptive platforms that appear to offer artificial intelligence tools, virtual private networks (VPNs), and crypto-related applications to lure unsuspecting users. Once downloaded, the malicious software […]

Malware in AI Models on PyPI Hits Alibaba Users

Malicious actors have embedded malware within artificial intelligence models uploaded to the Python Package Index (PyPI), with a specific focus on compromising users affiliated with Alibaba’s AI Labs. The attack involves the distribution of seemingly legitimate AI models that, once downloaded, execute hidden malicious code on the target systems. The tactic exploits the growing reliance […]

Estonia Seeks Moroccan in Pharmacy Data Breach

Estonian authorities have issued an arrest warrant for a Moroccan national suspected of breaching a sensitive customer card database belonging to Allium UPI, the parent company of the Apotheka pharmacy chain. The intrusion, which occurred in February 2024, reportedly involved unauthorized access to confidential user data, prompting a criminal investigation into the breach. Details about […]