loader image
Microsoft Issues Emergency Fix for Surface Hub Failure

Microsoft has issued an emergency fix to address a critical problem affecting some Surface Hub v1 devices running Windows 10. A known startup failure had left users unable to boot their systems, prompting the company to act swiftly. The Microsoft Issues Emergency Fix comes in response to reports of devices stuck during the startup process, […]

Microsoft Fixes Bug That Broke Windows 11 Updates

Microsoft has released a configuration update aimed at resolving a persistent issue that caused Windows Update to fail on certain Windows 11 devices. The rollout comes after users reported problems receiving essential system updates, which led to concerns over patch reliability and system security. The update, part of ongoing system maintenance efforts, ensures smoother delivery […]

Fred Hutch to Pay $50 Million in Data Breach Deal

Fred Hutchinson Cancer Center has agreed to pay over $50 million in the aftermath of a 2023 data breach, earmarking the funds for damages, infrastructure upgrades, and fraud monitoring services. The financial commitment follows a cyberattack that compromised sensitive information, prompting the organization to take corrective measures to mitigate fallout and prevent future incidents. According […]

**Splunk Windows Flaw Lets Users Bypass Admin Controls**

A high-severity vulnerability in Splunk’s Universal Forwarder for Windows is exposing enterprise systems to unauthorized access by non-administrator users. Tracked as CVE-2025-20298 with a CVSS v3.1 score of 8.0, the flaw stems from incorrect permission settings applied during installation or upgrade processes. Affected versions include branches 9.4 (below 9.4.2), 9.3 (below 9.3.4), 9.2 (below 9.2.6), […]

Victoria’s Secret Delays Results After Cyberattack

Victoria’s Secret & Co. has postponed the release of its first-quarter 2025 earnings after experiencing a security incident that disrupted its corporate systems. The fashion retailer is currently engaged in system restoration efforts following the breach, which occurred on May 24, according to a company statement. The decision to delay the earnings report highlights the […]

Lee Enterprises Says Hack Exposed Data of 40,000

Lee Enterprises said a ransomware attack led to a data breach affecting approximately 40,000 individuals, following the completion of its internal investigation. The media company confirmed that unauthorized access to its systems resulted in the exposure of sensitive personal information, though it did not specify the exact nature of the compromised data. The breach was […]

Meta Removes China, Iran Fake News Networks

Meta Platforms Inc. has dismantled three covert influence operations tied to China, Iran and Romania that were using fake accounts to manipulate political discourse across multiple regions, according to *The Record*. The campaigns operated on Meta-owned platforms, including Facebook and Instagram, and were designed to spread propaganda and shape public opinion through coordinated inauthentic behavior. […]

GitLab Flaws Expose Millions to Account Takeover Risk

GitLab has issued emergency patches to fix ten security vulnerabilities affecting its Community Edition (CE) and Enterprise Edition (EE) platforms, some of which could allow complete account takeover. The flaws span versions 17.9 through 18.0 and include high-severity vulnerabilities with CVSS scores exceeding 8.0. The most critical, CVE-2025-4278, is an HTML injection flaw that impacts […]

Paraguay Data of 7.4 Million Leaked via Infostealer

A massive cybersecurity breach has exposed sensitive information tied to the Paraguay data of 7.4 million individuals, according to researchers who traced the leak to malware infections. The stolen data, now circulating on dark web forums, reportedly includes details about nearly the entire population of the South American country. Experts believe the breach began when […]

SonicWall Warns NetExtender Tool Hijacked by Trojan

SonicWall warns NetExtender tool users to be on alert after discovering a tampered version of the application embedding data-theft capabilities. The company identified that attackers modified the legitimate NetExtender VPN client, inserting malicious code designed to capture user information. This development raises concerns for enterprises relying on the tool for secure remote access. According to […]

Dadsec Hackers Exploit Tycoon2FA to Breach Office365

A coordinated phishing campaign exploiting shared cybercriminal infrastructure has emerged as a growing threat to enterprise Microsoft 365 users, according to researchers at Trustwave. The operation connects the Tycoon2FA Phishing-as-a-Service (PhaaS) platform—active since August 2023—with the threat group Storm-1575, also known as Dadsec. Attackers employ adversary-in-the-middle (AiTM) techniques to bypass multi-factor authentication, distributing phishing emails […]

PyPI Malware Mimics Popular Tools to Backdoor Systems

Two malicious Python packages uploaded to the Python Package Index (PyPI) are targeting Windows and Linux systems, according to Hackread. The attack involves backdoored libraries designed to infiltrate developer environments. One of the packages mimics “colorama,” a legitimate and widely used Python tool for color formatting in terminal output. The second imitates “colorizr,” a similarly […]