loader image
Akira Hackers Exploit SonicWall Flaws for Ransom

Affiliates of the Akira ransomware gang have resumed attacks by exploiting a trio of known vulnerabilities in SonicWall security appliances. The latest wave of activity reveals how Akira hackers exploit SonicWall flaws to breach networks and demand ransom payments, revisiting a critical bug that was first abused in the summer of 2024. Security researchers initially […]

Cursor AI Bug Lets Hackers Auto-Run Malicious Code

A critical remote code execution flaw in the Cursor AI code editor exposes users to silent attacks triggered simply by opening a project folder. The Cursor AI bug lets hackers execute commands automatically when developers access malicious repositories, without requiring user interaction or consent. Security researchers at Oasis Security uncovered the issue, which takes advantage […]

NPM Hack Hits 10% of Clouds, Yields No Profit for Thieves

A widespread breach in the NPM ecosystem has disrupted around 10% of all cloud environments, marking it as the most significant supply-chain compromise in the platform’s history. Despite the scale and sophistication of the attack, hackers failed to extract meaningful financial gain. The incident, now widely referred to as the NPM Hack Hits 10%, has […]

Logins Get Smarter as Firms Balance Safety, Ease

As organizations work to protect digital assets, balancing security and usability in login systems has become critical. Adding more authentication steps can strengthen defenses, but excessive friction may drive users away. The latest trend—Logins Get Smarter—focuses on enhancing security without compromising user experience. Security experts emphasize that too few safeguards expose systems to breach risks, […]

States Target Firms Dodging Data Opt-Out Laws

California, Colorado and Connecticut have launched a joint investigative effort to enforce compliance with data privacy laws. The coordinated action comes as states target firms dodging requirements to honor consumers’ rights to opt out of data sales and tracking. Regulators are reaching out to businesses that fail to implement technology mandated by law, specifically tools […]

Google Pixel 10 Adds C2PA to Fight Deepfake Images

Google Pixel 10 adds C2PA integration to its camera and Photos app, enabling users to verify whether images are AI-generated or altered. Announced at the Made by Google 2025 event, this move strengthens image authenticity by embedding Content Credentials into JPEG captures and edits. These credentials use secure digital signatures to provide verifiable proof of […]

CyberVolk Hits Critical Systems With Flawed Ransomware

A newly discovered ransomware strain known as CyberVolk has begun targeting Windows systems within critical infrastructure and scientific institutions, aiming at countries viewed as adversarial to Russian interests. Since its emergence in May 2024, the malware has caused widespread disruption in public services and research facilities across Japan, France and the United Kingdom. CyberVolk hits […]

Nucleus Launches AI Tool to Prioritize Cyber Threats

Nucleus Security has introduced Nucleus Insights, an artificial intelligence-based threat intelligence platform aimed at helping cybersecurity teams prioritize vulnerabilities more effectively. As Nucleus launches AI tool capabilities through this new platform, organizations can now better determine which Common Vulnerabilities and Exposures (CVEs) require immediate focus and understand the reasoning behind each recommendation. The platform uses […]

NSC Cyber Chief Backs More Aggressive U.S. Hacking

The NSC cyber chief backs a shift toward more assertive U.S. cyber operations, signaling a strategic pivot in the government’s approach to digital threats. Speaking to Nextgov/FCW, the National Security Council’s senior cybersecurity director emphasized the need to intensify offensive cyber tactics while maintaining a strong focus on defensive capabilities to protect national infrastructure. The […]

AsyncRAT Evades Detection With Stealthy Fileless Attack

A surge in fileless malware campaigns has brought renewed attention to AsyncRAT, a remote access trojan that exploits trusted system tools to launch in-memory attacks. By avoiding traditional disk writes, AsyncRAT evades detection and enables threat actors to maintain control over compromised enterprise systems with minimal forensic trace. Attackers gain initial access by abusing unauthorized […]