loader image
Laravel Flaw Exposes 600 Apps to Remote Code Attacks

A critical Laravel flaw exposes 600 apps to remote code execution by leaking APP_KEY values, according to recent research by GitGuardian and Synacktiv. Since 2018, attackers have accessed over 260,000 APP_KEYs from public GitHub repositories, enabling exploitation across multiple Laravel versions. The flaw stems from Laravel’s decrypt() function, which automatically deserializes data without validation. Malicious […]

SureForms Flaw Exposes 200,000 WordPress Sites to Hackers

A critical flaw in the SureForms WordPress plugin has exposed over 200,000 websites to potential full-site takeover attacks. The vulnerability, identified as CVE-2025-6691 with a CVSS score of 8.8, allows unauthenticated users to delete arbitrary files—including wp-config.php—directly from servers. This SureForms flaw exposes WordPress installations to a risk where attackers can trigger setup mode and […]

Europol, Jordan Join Forces to Fight Cross-Border Crime

Europol and Jordan’s Public Security Directorate signed a Working Arrangement on July 10 to intensify their joint efforts against serious and organized crime. As Europol and Jordan join forces, the agreement creates a formal framework for structured cooperation aimed at countering cross-border threats, including terrorism, impacting the EU, the Middle East and beyond. The arrangement […]

ZuRu Malware Hijacks Termius App to Target macOS Users

A newly discovered variant of the ZuRu malware hijacks Termius, a popular SSH client, to target macOS users with advanced infection tactics. Security researchers uncovered the campaign in late May 2025, marking a significant shift in the malware’s delivery method. Instead of poisoning search results, attackers now bundle malicious code within legitimate applications used by […]

Hackers Steal $500,000 in Crypto via AI Dev Tool Trap

Hackers exploited a malicious extension in the Cursor AI development environment to steal $500,000 in cryptocurrency from a Russian blockchain developer. The attack, which Securelist analysts linked to a fake “Solidity Language” extension, marks a new phase in supply chain intrusions using AI-assisted platforms. Hackers steal 500000 crypto assets by manipulating search algorithms to elevate […]

**US Sanctions North Korea Hackers in IT Jobs Scheme**

The U.S. Treasury on July 8 imposed sanctions on Song Kum Hyok and four entities based in Russia, exposing a covert cyber campaign that has helped fund North Korea’s weapons development. The move, part of a broader push as US sanctions North Korea hackers, highlights the use of remote IT workers embedded in legitimate projects […]

Schneider Electric Flaws Expose Data Centers to Attacks

Schneider Electric has confirmed six critical security weaknesses in its EcoStruxure IT Data Center Expert software, exposing data centers to potential remote code execution. The Schneider Electric flaws expose systems running versions 8.3 and earlier to attacks that could allow unauthorized access and OS-level command injection. The most serious issue, tracked as CVE-2025-50121, received a […]

SafePay Ransomware Hits 200 Firms Using RDP, VPN Hack

SafePay ransomware has rapidly emerged as a major cyber threat, targeting managed service providers and small-to-midsize enterprises across industries. SafePay ransomware hits 200 victims globally in Q1 2025 alone, marking a sharp rise in its activity since its 2024 debut. The group infiltrates networks using compromised Remote Desktop Protocol and Virtual Private Network credentials. Unlike […]

Rockerbox Breach Exposes SSNs, Licenses of 245,949 Users

A misconfigured cloud storage bucket at Dallas-based tax consultancy Rockerbox exposed 245,949 sensitive user records, including Social Security numbers and driver’s licenses. The Rockerbox breach exposes SSNs through an unencrypted 286.9 GB repository that was openly accessible via a simple HTTP GET request and indexed online by early July 2025. The exposed data included tax […]

Meta Loses German Court Fight Over Tracking Tech

A German court has ruled that Meta violated European privacy laws by embedding tracking technologies in third-party websites, in a case that could set a precedent for future legal actions. In the decision issued in Leipzig, the court ordered Meta to pay €5,000 ($5,900) to a Facebook user who brought the lawsuit, marking a key […]

Bitcoin Depot Breach Exposes Data of 26,000 Customers

Bitcoin Depot, a major operator of cryptocurrency ATMs across North America, confirmed that a cyberattack last year exposed personal data belonging to over 26,000 individuals. The Bitcoin Depot breach exposes data including names, addresses and driver’s license numbers. The company disclosed the incident after determining hackers gained unauthorized access to internal systems. The breach affected […]

GMX Crypto Platform Hit as Hacker Steals $40 Million

Decentralized exchange GMX halted trading operations after suffering an exploit that led to the loss of more than $40 million in user funds. The GMX Crypto Platform Hack forced the exchange to take immediate action to prevent further damage and protect remaining assets. Officials confirmed the incident but have not disclosed specific technical details regarding […]