loader image
Google Warns Hackers Target Salesforce With Vishing Ploy

Google has issued a warning about a financially motivated cybercriminal group targeting Salesforce customers through a vishing and extortion campaign. The attackers are using voice phishing tactics to deceive victims into revealing sensitive information, which is then leveraged to gain unauthorized access to Salesforce accounts. Once inside, the threat actors reportedly extort the victims, demanding […]

Microsoft Patches 66 Flaws, One Bug Actively Exploited

Microsoft addressed 66 vulnerabilities in its latest Patch Tuesday release, with 10 of the flaws classified as “critical,” the company disclosed. Among the patched issues, two carry a Common Vulnerability Scoring System (CVSS) rating of 8.8, signaling high severity. Notably, one of these high-rated vulnerabilities is currently under active exploitation, heightening the urgency for users […]

Chrome, Firefox Fix High-Risk Memory Flaws

Google and Mozilla have issued security updates addressing four high-severity memory-related vulnerabilities in their respective web browsers, Chrome and Firefox. The patches, released separately by the two companies, are designed to mitigate risks stemming from memory bugs that could be exploited to compromise user systems or cause application instability. The updates reflect ongoing efforts by […]

Trump Extends TikTok Reprieve Despite Ban Law

The Trump administration plans to again delay enforcement of its TikTok ban, offering the popular video-sharing platform a temporary reprieve. Trump extends TikTok reprieve under the same legislation that initially sought to block the app — the Protecting Americans from Foreign Adversary Controlled Applications Act. This law targets platforms perceived to be under the influence […]

Jira Tickets Turn Attack Vectors in AI Exploit PoC

A proof-of-concept exploit developed by Cato Networks has demonstrated how Jira tickets turn attack vectors when manipulated through prompt injection techniques. The exploit reveals how attackers can leverage seemingly routine external inputs to compromise internal artificial intelligence tools integrated within enterprise systems. By embedding malicious prompts in Jira tickets, attackers can manipulate AI-driven services that […]

Androxgh0st Botnet Hits US University Servers

The Androxgh0st Botnet hits again, this time targeting servers at U.S. universities as it broadens its digital footprint. Security researchers have observed increased activity from the botnet, which is now exploiting vulnerable infrastructure within academic institutions. These attacks raise concerns over the growing sophistication and persistence of threat actors operating this malware. The botnet reportedly […]

Germany Names TrickBot, Conti Ringleader as Russian

Germany’s Federal Criminal Police Office (Bundeskriminalamt, or BKA) has identified the alleged leader of the notorious Conti ransomware and TrickBot cybercrime operations as Vitaly Nikolaevich Kovalev, a 36-year-old Russian national. The announcement marks a significant move by German authorities in their ongoing efforts to dismantle international ransomware networks. The BKA publicly named Kovalev, who is […]

Russian Spy Hacking Ops Exposed by Server Breach

A covert cyber unit within the Russian military has been exposed after an unsecured server linked to its operations was accessed by investigative journalists, according to a report from Cybernews. The server belonged to Unit 29155, a division of the Main Directorate of the General Staff of the Armed Forces, and reportedly contained sensitive information […]

Kettering Health Hit by Interlock Ransomware Attack

Kettering Health, a major healthcare provider operating 14 medical centers across Ohio, has confirmed that the Interlock ransomware group was responsible for a cyberattack that compromised its network in May. The organization reported that threat actors gained unauthorized access and exfiltrated data during the breach. The incident underscores ongoing cybersecurity challenges facing the healthcare sector, […]

2ClickPortal Software Hit by SQL Injection Flaw

A critical SQL injection vulnerability has been identified in the 2ClickPortal software, according to an advisory published by CERT Poland. The flaw, tracked as CVE-2025-4568, could allow attackers to manipulate backend databases by injecting malicious SQL code through user-facing input fields. Such vulnerabilities may be exploited to access, modify, or delete sensitive data without proper […]

Apple iMessage Flaw Let Hackers Spy With No Clicks

A previously undisclosed zero-click vulnerability in Apple’s iMessage platform has come to light, involving the misuse of its nickname feature, researchers revealed. The flaw, which has since been patched, may have been exploited to target high-profile individuals without requiring any user interaction, according to cybersecurity analysts. Zero-click exploits are particularly concerning due to their stealthy […]

Gargle Leak Exposes 2.7 Million U.S. Patient Records

Nearly 2.7 million patient profiles and 8.8 million appointment records in the United States were left exposed due to a misconfigured MongoDB database, according to a report by Cybernews. The unsecured database is believed to have been operated by Gargle, a U.S.-based dental marketing firm. The exposed data included sensitive health-related information, raising concerns about […]