loader image
Qwins Ltd Linked to Malware Surge via Cheap Hosting

A UK-registered company, Qwins Ltd, has emerged as a major enabler of cybercrime, according to cybersecurity researchers who linked its infrastructure to global malware campaigns. Operating under ASN 213702, Qwins Ltd has provided bulletproof hosting services that support malware families like Lumma Stealer, Amadey, and Mirai variants. Researchers observed its servers distributing over 120 malware […]

0bj3ctivityStealer Hides Payload in Images, Hits Firms

A newly uncovered information-stealing malware known as 0bj3ctivityStealer has drawn attention for its advanced exfiltration tactics and layered execution chain. First identified by HP Wolf Security researchers, the malware hides payload using obfuscated JavaScript and steganographic methods to bypass traditional detection systems. Its attack begins with phishing emails disguised as purchase order requests, luring users […]

Apple Releases Urgent MacOS, Safari Security Updates

Apple has rolled out security-focused updates for Mac users running macOS Sonoma and macOS Ventura, delivering macOS Sonoma 14.7.7 and macOS Ventura 13.7.7. The company labeled these releases as critical, addressing undisclosed security vulnerabilities. Apple releases urgent macOS patches periodically to maintain robust system protection and improve user safety. Alongside the macOS updates, Apple also […]

Dollar Tree Denies Hack, Blames Old Chain for Data Leak

Dollar Tree denied reports of a ransomware attack this week after a cybercriminal group claimed it had breached the discount retailer’s systems. Dollar Tree denies hack allegations, asserting that the data in question originated from a separate entity no longer in operation. The company clarified that the alleged stolen data came from a defunct discount […]

Hackers Lure Python Devs With Fake PyPI Login Site

Hackers lure Python devs into phishing traps by deploying a counterfeit version of the Python Package Index (PyPI) website, according to a warning issued this week by the Python Software Foundation. The attackers aim to steal user credentials by mimicking the official PyPI platform, a repository widely used by developers to share and install packages. […]

XWorm V6 Malware Evades Detection, Hits Windows Users

A newly discovered XWorm V6 malware variant has surfaced in active attacks against Windows users, showcasing advanced anti-analysis features and memory-only execution. Security researchers at Netskope uncovered the strain following a year-long investigation into XWorm’s development. The XWorm V6 malware evades detection through obfuscated VBScript droppers and runtime payload reconstruction via reversed character arrays. The […]

Ingram Micro Hit as Safepay Threatens Data Leak

The SafePay ransomware group has claimed responsibility for a cyberattack that compromised systems at global IT distributor Ingram Micro, threatening to leak 3.5 terabytes of stolen data. According to the threat actors, the breach occurred earlier this month, and the stolen files allegedly include internal documents, client records, and business communications. Ingram Micro hit SafePay’s […]

Hackers Exploit WordPress Alone Theme for Site Takeovers

Hackers exploit WordPress Alone theme vulnerabilities to launch remote code execution attacks, putting thousands of websites at risk of full compromise. The flaw, an unauthenticated arbitrary file upload vulnerability, allows attackers to bypass security measures and gain control over affected sites. Once inside, threat actors can execute malicious scripts, manipulate content, and take over administrative […]

SonicWall Warns Users to Patch 3 VPN Flaws Urgently

SonicWall warns users to patch immediately after uncovering three critical vulnerabilities in its VPN products. The security flaws, which affect several of the company’s firewall and remote access solutions, could allow attackers to bypass authentication or execute remote code. These risks pose a serious threat to organizations relying on SonicWall to secure remote connections. The […]

Russia Bans Speedtest Tool Citing Cybersecurity Risk

Russia has blocked access to Speedtest, a widely used internet performance tool developed by Seattle-based company Ookla, citing national security risks. The move, announced by Russia’s telecommunications regulator, comes as officials raise concerns that data collected through the tool could be leveraged in cyberattacks. Russia bans Speedtest tool as part of broader efforts to limit […]

FunkSec Ransomware Cracked as Hackers Vanish

Cybersecurity researchers have released a free public decryptor for the FunkSec ransomware strain, marking a significant win for victims who lost access to their data. The tool became available after the group behind the FunkSec ransomware was deemed inactive. Experts confirmed that the FunkSec ransomware cracked open following signs that its operators had ceased all […]

IBM Says U.S. Data Breach Costs Hit Record $10 Million

The average cost of a data breach in the U.S. surged to a record $10 million this year, IBM says US data breach costs continue to outpace global trends. While the global average dropped to $4.45 million—a 9% decline from 2024—U.S. organizations experienced the steepest financial impact among surveyed countries. IBM says US data breach […]