loader image
Meta Targets Scammers With WhatsApp, Messenger Tools

Meta introduced a suite of security enhancements Tuesday aimed at protecting users of Messenger and WhatsApp from online scammers. The company launched the new tools during Cybersecurity Awareness Month, reinforcing its broader initiative as Meta targets scammers with smarter, real-time detection and user empowerment features. On WhatsApp, users will now see alerts when they share […]

Microsoft Updates Break Logins in Windows, Server 2025

Microsoft confirmed that recent security updates are disrupting login processes on Windows 11 versions 24H2, 25H2, and Windows Server 2025. The problem, which surfaced after updates like KB5064081 and KB5065426, highlights how Microsoft updates break logins on systems with duplicated Security Identifiers (SIDs), especially in enterprise environments using cloned virtual machines. Users report recurring credential […]

Pakistani Hackers Mimic NIC Email to Target India Govt

A cyber-espionage group linked to Pakistan has launched a phishing campaign against Indian government agencies, posing as the National Informatics Centre’s email services. Cybersecurity analysts have attributed the operation to APT36, also known as TransparentTribe. These Pakistani hackers mimic NIC email headers and formats to deceive officials into sharing credentials or downloading malicious files. The […]

Cursor, Windsurf IDEs Expose 94 Chromium Flaws

Developers using the latest versions of Cursor and Windsurf IDEs face heightened risks, as both platforms expose users to over 94 known security flaws tied to outdated Chromium and V8 JavaScript components. These vulnerabilities, previously patched in their original frameworks, remain unaddressed in the IDEs, leaving systems open to possible exploitation. Security researchers identified the […]

AWS Outage Hits 1,000 Firms, DNS Failure Blamed

A widespread disruption on Oct. 20 took more than 1,000 organizations offline, highlighting the internet’s reliance on Amazon Web Services. The AWS outage hits 1,000 firms across sectors, cutting access to websites, applications and digital services as engineers traced the root of the issue to a Domain Name System (DNS) malfunction. The interruption, which lasted […]

AI Agent Hijack Flaw Found in Anthropic’s MCP Protocol

A newly disclosed vulnerability in the Oat++ implementation of Anthropic’s Model Context Protocol (MCP) exposes AI agents to session hijacking, security researchers revealed. The flaw allows attackers to exploit predictable session IDs, enabling unauthorized access to ongoing conversations and effectively executing an AI Agent Hijack Flaw. The issue has been assigned CVE-2025-6515. By capturing or […]

Hackers Sneak AdaptixC2 Into npm to Breach Dev Systems

Hackers sneak AdaptixC2 into the npm ecosystem by disguising it as a legitimate package, targeting developers who rely on Node.js modules. Researchers in October discovered that a malicious library named “https-proxy-utils” mimicked popular proxy tools such as “http-proxy-agent.” Once installed, it executed a post-installation script that deployed the AdaptixC2 agent, giving attackers covert access to […]

Microsoft Patches 172 Flaws Including 3 Zero-Days

Microsoft patched 172 security flaws in its October 2025 Patch Tuesday update, the highest monthly total so far this year. The rollout includes fixes for eight critical vulnerabilities, two publicly disclosed issues, and three zero-day exploits. Microsoft patches 172 flaws across its product suite, underscoring the growing complexity of enterprise security risks. Among the addressed […]

CrowdStrike Uncovers Oracle EBS Zero-Day Attack

CrowdStrike Uncovers Oracle EBS attack campaign exploiting a newly identified zero-day vulnerability, now tracked as CVE-2025-61882. This vulnerability impacts Oracle E-Business Suite (EBS) applications, widely used by enterprises for resource planning and operations. According to CrowdStrike, the campaign involves mass exploitation attempts against exposed EBS systems, suggesting an organized and likely sophisticated effort. The cybersecurity […]

CrowdStrike Falcon Blocks Git Exploit in Active Attack

CrowdStrike has detected active exploitation of the Git vulnerability identified as CVE-2025-48384. The company reported that its security platform, CrowdStrike Falcon, blocks Git-based attacks by stopping threat actors who use deceptive social engineering techniques alongside compromised repositories. This campaign targets developers by luring them into cloning malicious Git projects, which then trigger the exploit. According […]

Cavalry Werewolf Hackers Target Energy, Mining Sectors

A newly uncovered cyber-espionage campaign tied to the Cavalry Werewolf hackers targets Russia’s public sector and critical industries, exploiting trusted government communications. Active from May through August 2025, the group—also known as YoroTrooper and Silent Lynx—used spear-phishing emails posing as Kyrgyz government agencies to deliver malware. These phishing messages distribute FoalShell and StallionRAT through RAR […]

TP-Link Patches Critical Flaw in Omada Gateways

TP-Link has issued firmware updates to fix four security vulnerabilities affecting its Omada gateway devices, including a critical pre-authentication operating system command injection flaw. The company acted swiftly as the TP-Link patches critical flaw aim to prevent attackers from executing arbitrary commands on impacted devices without user authentication. The vulnerabilities affect a wide range of […]