loader image
Lenovo Fixes BIOS Flaws That Bypass Secure Boot

Lenovo has released new UEFI firmware updates to address high-severity BIOS vulnerabilities that could allow attackers to bypass Secure Boot protections. The flaws affect specific all-in-one desktop models that use customized Insyde UEFI firmware. As part of this security response, Lenovo fixes BIOS flaws that posed a risk to device integrity and system trust. The […]

TraderTraitor Hacks Cloud to Steal Billions in Crypto

A North Korean hacking unit known as TraderTraitor has intensified its focus on cryptocurrency firms by breaching cloud platforms and poisoning supply chains, according to new findings. The TraderTraitor hacks cloud environments by leveraging trojanized applications and social engineering, often targeting developers with fake job offers on LinkedIn or Telegram. Since 2020, the group has […]

Orange Hit by Cyberattack Disrupting IT Systems

Orange, the French multinational telecommunications and digital services provider, faced a cybersecurity breach on Friday that targeted one of its information systems, according to a report by BleepingComputer. The incident left operations disrupted, raising concerns about the resilience of its digital infrastructure. Orange hit by cyberattack, has yet to disclose full details about the breach […]

Microsoft Uncovers macOS Flaw That Bypasses Privacy

Microsoft has identified a vulnerability in macOS, dubbed “Sploitlight,” that could allow attackers to bypass Transparency, Consent, and Control (TCC) protections. Microsoft uncovers macOS flaw in the system’s logging framework, which could expose sensitive user data by exploiting how the operating system grants app permissions. According to Microsoft, the flaw resided in how macOS logged […]

Base44 AI Platform Hit by Critical Auth Flaw

A critical flaw in the Base44 AI Platform Auth flow has exposed users to significant security risks, according to a report from Infosecurity Magazine. The vulnerability allows threat actors to bypass Single Sign-On protocols, potentially registering and accessing private applications without proper authentication. Security researchers identified the issue within the platform’s authentication mechanism, which is […]

Ingram Micro Hackers Threaten 3.5TB Data Dump

Ingram Micro is facing a renewed cybersecurity crisis this week as hackers threaten to leak 3.5 terabytes of stolen data. Despite the looming threat, the global IT distributor claims to have fully restored its worldwide operations, although certain regional websites are only now returning online. The company has not disclosed specific details about the compromised […]

Avast Unleashes FunkSec Ransomware Decryptor

Cybersecurity firm Avast has unveiled a new tool to help victims recover from FunkSec ransomware attacks. In a targeted effort, Avast unleashes FunkSec ransomware decryption support through a publicly available tool and is actively assisting dozens of affected organizations. The ransomware strain, described as short-lived, had impacted multiple victims before being disrupted. Avast collaborated closely […]

Google Project Zero to Reveal Bugs After One Week

Google Project Zero plans to publicly disclose security vulnerabilities within seven days of reporting them to vendors, aiming to reduce delays in patch adoption. The policy shift targets what researchers describe as the “upstream patch gap,” where fixes exist but downstream vendors have yet to incorporate them into widely used products. By accelerating transparency, Google […]

IBM Says Data Breach Costs Hit Record $10 Million

U.S. organizations are paying more than ever to recover from data breaches, according to IBM’s latest annual report. IBM says data breach costs now exceed $10 million on average, marking a new record high for the country. The report highlights growing financial pressure on businesses as cyberattacks become more frequent and complex. The findings underscore […]

HOOK Android Trojan Adds Ransomware Extortion Tool

A new variant of the HOOK Android Trojan adds ransomware-like overlay screens to its capabilities, cybersecurity researchers revealed. The malware now deploys full-screen ransom messages that aim to pressure victims into making payments. This marks a significant evolution in the trojan’s tactics, blending traditional banking fraud with extortion. According to researchers from Zimperium zLabs, the […]

CISA Flags Citrix, Git Flaws as Active Threats

The U.S. Cybersecurity and Infrastructure Security Agency on Aug. 25 added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, escalating concerns across enterprise IT teams. CISA flags Citrix Git flaws as active threats, highlighting their potential to compromise infrastructure if left unpatched. The vulnerabilities include CVE-2025-48384, a high-severity issue linked to Git, and […]

Google Play Store Hit as Malware Apps Slip Through

Several malicious applications managed to bypass Google’s security checks and land in the Google Play Store, raising concerns over the platform’s ability to screen threats effectively. Security researchers flagged the suspicious apps after users reported abnormal device behavior, including unexpected pop-ups and performance issues. Despite these findings, Google claims its advertising mechanisms remain secure and […]