loader image
Instantel Devices Exposed to Hack Risk, Researcher Says

More than 1,000 industrial monitoring devices manufactured by Instantel may be vulnerable to cyberattacks following the discovery of a critical command execution flaw in the company’s Micromate units. The flaw, identified by a researcher, could allow an attacker to gain unauthorized control of the devices, potentially disrupting their operation or accessing sensitive environmental data. The […]

Google Says Hackers Pose as IT to Breach Firms

Hackers are increasingly using fake IT support calls as a tactic to infiltrate corporate systems, according to a warning from Google. The attackers impersonate legitimate helpdesk personnel, contacting employees to manipulate them into granting access to sensitive internal resources. These social engineering schemes are designed to bypass security measures by exploiting human trust rather than […]

Infoblox NetMRI Bugs Expose Systems to Remote Attacks

Infoblox NetMRI, a network automation and management platform, has been found to contain multiple critical security vulnerabilities, according to a post shared on the r/netsec forum. The flaws include remote code execution (RCE), authentication bypass, SQL injection (SQLi), and arbitrary file read vulnerabilities. These issues are identified by several CVEs, though specific identifiers were not […]

SinoTrack GPS Flaws Let Hackers Control Vehicles Remotely

SinoTrack GPS tracking devices contain two security vulnerabilities that could allow unauthorized remote access to vehicles, according to a recent disclosure. The flaws affect the web management interface used to control the devices, exposing them to potential exploitation via default or weak passwords. If successfully exploited, the vulnerabilities could grant attackers access to device profiles, […]

Windows 10 Update Fixes Start Menu, Printer Bugs

Microsoft rolled out the June 2025 non-security preview update for Windows 10 version 22H2, introducing 13 fixes and improvements. This Windows 10 update fixes several issues, including a Start Menu bug that blocked users from launching the interface. The update, labeled KB5061087, also addresses problems affecting USB multi-function printers, where scanning features failed to operate […]

OneClik Malware Hits Energy Sector, Trellix Says

Cybersecurity firm Trellix has uncovered a sophisticated campaign using the OneClik malware, which targets organizations in the energy, oil and gas sectors. The campaign exploits Microsoft’s ClickOnce deployment technology to deliver malicious payloads and evade traditional detection methods. OneClik malware hits energy firms by embedding itself in cloud-hosted environments, enabling attackers to bypass endpoint defenses […]

Pure Crypter Malware Outsmarts Windows 11 24H2 Defenses

A sophisticated malware crypter known as Pure Crypter has been observed bypassing new security features introduced in Windows 11 version 24H2, according to researchers at eSentire. Designed as a modular malware delivery platform, Pure Crypter deploys multiple evasion techniques, including AMSI bypassing, DLL unhooking, and execution delays, to avoid detection by modern security tools. The […]

MainStreet Bank Data Breach Hits 5% of Customers

MainStreet Bancshares, a Virginia-based community bank, disclosed that nearly 5% of its customer data was compromised following a cybersecurity breach involving a third-party vendor. The incident occurred in March and was reported by The Record, a cybersecurity news outlet operated by Recorded Future. The breach did not originate within MainStreet Bank’s internal systems but stemmed […]

Apple Denies China Tied to Mysterious iPhone Crashes

A wave of unexplained iPhone crashes has raised alarms in the cybersecurity community, with some observers suspecting links to Chinese hacking operations—allegations Apple firmly denies. The crashes have prompted scrutiny amid rising geopolitical tensions and increasing cyberespionage activity. Though no official attribution has been made, the incidents coincide with broader concerns about state-backed cyber intrusions […]

Google Uncovers Vishing Ring Targeting Salesforce Data

Google has revealed a financially motivated threat group, dubbed UNC6040, that is targeting organizations using Salesforce through voice phishing, or “vishing,” schemes. According to the company’s threat intelligence team, the group employs deceptive techniques to trick victims into downloading a counterfeit version of a legitimate Salesforce tool called Data Loader. The fraudulent application is designed […]

Cilium Taps eBPF to Boost Container Security Insights

Cilium taps eBPF to deliver deeper visibility into container environments by monitoring activities directly at the Linux kernel level. This approach enables enhanced security by capturing detailed system behavior, including system calls, network traffic, and process execution. Tools such as Tetragon leverage this capability to provide real-time insights into container operations without disrupting performance. By […]

Scattered Spider Hacks M&S, Co-op in $592M Cyber Hit

U.K. retailers Marks & Spencer and Co-op suffered coordinated cyberattacks in April 2025, resulting in damages estimated up to $592 million. The Cyber Monitoring Centre (CMC), an independent body backed by the insurance industry, confirmed that the incidents are now classified as a “single combined cyber event.” Investigators linked the breaches to the Scattered Spider […]