loader image
Ukraine Nabs Spies Using Dashcams for Missile Strikes

Ukrainian authorities have detained individuals accused of spying for Russia by using vehicle dash cameras to support missile targeting efforts. The suspects allegedly parked cars outfitted with activated dash cams near military installations and left them in place for up to 12 hours to capture detailed surveillance footage. According to officials, the recorded video was […]

Fake Recruiters Use NetBird to Target CFOs Globally

A new spear-phishing campaign is targeting Chief Financial Officers and financial executives across six global regions, cybersecurity researchers have warned. The operation, which spans Europe, Africa, Canada, the Middle East, and South Asia, leverages fake recruiter emails to lure victims into downloading a legitimate remote access tool called NetBird. The attackers appear to be executing […]

Linux Flaws Let Hackers Steal Password Hashes at Scale

Two critical vulnerabilities in widely used Linux distributions could allow local attackers to extract password hashes by manipulating core dump files, according to researchers at Qualys Threat Research Unit. The flaws—CVE-2025-5054 and CVE-2025-4598—affect Ubuntu’s Apport and systemd-coredump used in Red Hat Enterprise Linux 9/10 and Fedora 40/41. Both bugs exploit race conditions that let users […]

Lumma Infostealer Takedown May Have Fallen Short

Efforts to dismantle the Lumma infostealer operation may not have fully succeeded, according to security industry updates. Despite previous actions targeted at disrupting the malware’s infrastructure, new activity suggests that Lumma remains operational. The infostealer, known for harvesting sensitive user data including credentials and financial information, continues to pose a threat to organizations and individuals. […]

Microsoft Unveils New Tactics to Thwart AiTM Attacks

Microsoft has published new research outlining advanced defensive strategies to counter the growing threat of Adversary-in-the-Middle (AiTM) attacks, which are becoming increasingly prevalent in cloud-based enterprise environments. These attacks exploit proxy servers to intercept authentication flows, effectively bypassing multifactor authentication (MFA) through phishing-as-a-service platforms such as Evilginx. High-profile threat groups, including Storm-0485 and Star Blizzard, […]

Phishing Kits Go Retail as Cybercrime Turns Subscription

Cybercriminals are increasingly adopting a subscription-based model known as Phishing-as-a-Service (PhaaS), lowering the barrier to entry for launching sophisticated phishing attacks. Mirroring legitimate SaaS platforms, PhaaS kits—often sold on the dark web—offer pre-built templates, spoofed email tools, credential-harvesting sites, and real-time dashboards for tracking campaign success. These services enable even novice attackers to mimic trusted […]

TikTok Users Hit by AI Malware in Video Scam

Hackers are exploiting TikTok’s popularity to distribute information-stealing malware using AI-generated tutorial videos, according to researchers at Censys. The campaign targets users searching for pirated software by presenting convincing how-to videos that guide viewers through fake activation processes. Instead of legitimate instructions, the videos prompt users to run PowerShell commands that install malware such as […]

vBulletin Flaws Let Hackers Seize Forums via API, RCE

Two critical vulnerabilities in the vBulletin forum software are under active exploitation, security researchers warned. Tracked as CVE-2025-48827 and CVE-2025-48828, the flaws affect vBulletin versions 5.0.0 to 5.7.5 and 6.0.0 to 6.0.3 when running on PHP 8.1 or newer. CVE-2025-48827, rated with a maximum CVSS score of 10, allows unauthenticated users to invoke protected API […]

Fake Job Offers Spread PureHVNC Malware in Phishing Scam

Cybercriminals last year leveraged fake job offers from well-known fashion and beauty brands—including Bershka, John Hardy, Fragrance Du Bois, and Dear Klairs—to distribute the PureHVNC remote access trojan, according to a report from GBHackers News. The phishing campaign used these fraudulent employment lures as part of a multi-stage strategy to gain unauthorized access to victims’ […]

Cybersecurity ROI Climbs as Budgets Shrink: Report

Cybersecurity budgets have declined significantly over the past two years, despite evidence that security teams are generating measurable business value, according to a report cited by *Infosecurity Magazine*. The share of annual organizational spending allocated to cybersecurity has dropped from 1.1% to 0.6%, highlighting a growing disconnect between investment levels and cybersecurity’s contribution to enterprise-wide […]

Linux Bugs Expose Password Hashes in Core Dumps

Two newly discovered vulnerabilities in popular Linux distributions could allow local attackers to access sensitive data, including password hashes, security researchers have found. The flaws, tracked as CVE-2025-5054 and CVE-2025-4598, affect apport and systemd-coredump—core dump handling utilities used in Ubuntu, Red Hat Enterprise Linux (RHEL), and Fedora. According to the Qualys Threat Research Unit, both […]

Unimed Data Leak Exposes 14 Million Patient Chats

Unimed, the world’s largest healthcare cooperative based in Brazil, exposed at least 14 million patient-doctor communications due to a misconfiguration in its data infrastructure, Cybernews reported. The breach occurred through an unsecured deployment of Apache Kafka, an open-source platform used for real-time data transmission. The leaked data included conversations between patients and healthcare professionals, as […]