loader image
Clearview AI Sued in Europe Over Privacy Breaches

Clearview AI sued in Europe as the facial recognition firm faces renewed legal pressure over alleged violations of data privacy laws. The complaint, filed by the advocacy group noyb, accuses Clearview of ignoring previous bans and enforcement actions issued by European data protection authorities. These regulators had previously ruled that the company’s data collection practices […]

Hackers Combine Cache, FileFix in Stealthy Malware Push

Hackers combine cache FileFix techniques in a new phishing campaign that uses deceptive FortiClient pages and browser caching to bypass detection. Cybersecurity analysts found that attackers trick users into pasting commands into Windows Explorer’s address bar, exploiting a 2048-character entry limit to deliver larger payloads than possible in traditional ClickFix attacks. The campaign hides PowerShell […]

Dentsu Discloses Data Breach at Merkle Unit

Japanese advertising conglomerate Dentsu has confirmed a cybersecurity breach at its U.S.-based subsidiary Merkle, exposing sensitive information belonging to employees and clients. Dentsu discloses data breach details following an internal investigation that identified unauthorized access to company systems. The company has not confirmed the number of affected individuals or the nature of the compromised data. […]

HSBC USA Customer Data Leaked in Reported Hack

Cybercriminals have reportedly exposed a database containing sensitive HSBC USA customer data, according to a report by Cybernews. The leaked information allegedly includes full names, Social Security numbers, bank account details, and transaction histories. The breach raises concerns about the scope of data compromised and the potential for identity theft or financial fraud. The report […]

Everest Hackers Claim Breach at Sweden’s Power Grid

The Everest ransomware group has claimed responsibility for a cyberattack on Svenska kraftnät, Sweden’s state-owned power grid operator. In a statement posted to a leak site, Everest hackers claim breach of the utility’s internal systems and say they have exfiltrated approximately 280 gigabytes of sensitive corporate data. The alleged breach has triggered an investigation, according […]

Anivia Stealer Malware Bypasses UAC in Dark Web Sale

A new strain of credential-stealing malware named Anivia Stealer is being marketed across underground forums, according to researchers at KrakenLabs. Developed in C++17, the Anivia Stealer malware bypasses User Account Control (UAC) protections on Windows systems ranging from XP to Windows 11, allowing cybercriminals to execute privileged operations without alerting users. Threat actor ZeroTrace is […]

Python Turns Down $1.5 Million U.S. Grant Over Ethics

The Python Software Foundation has withdrawn a $1.5 million grant proposal to the U.S. National Science Foundation, citing ethical concerns over the funding terms. The decision, in which Python turns down 15 million in government support, centers on conditions that the foundation believes would compromise its principles on diversity, equity and inclusion. According to the […]

Windows 11 Update Adds Admin Cybersecurity Shield

Microsoft has started rolling out the KB5067036 preview cumulative update for Windows 11 versions 24H2 and 25H2, introducing new cybersecurity improvements. The Windows 11 Update Adds the Administrator Protection feature, which enhances system security by restricting access to high-risk administrative tools unless explicitly authorized. This release also includes a refreshed Start Menu design, aiming to […]

MikroTik Flaw Exposes Admin Logins Over Plain HTTP

A critical security vulnerability in MikroTik’s RouterOS and SwitchOS platforms, tracked as CVE-2025-61481, has been assigned a maximum CVSS score of 10.0. The MikroTik flaw exposes admin logins through the unencrypted HTTP version of the WebFig interface, enabling unauthenticated attackers to steal credentials and execute arbitrary code remotely. Devices running RouterOS version 7.14.2 and SwitchOS […]

Magento Flaw Lets Hackers Hijack Sessions, Run Code

Security researchers at Akamai have issued an urgent alert following the discovery of active attacks targeting a critical Magento flaw that lets hackers take over user sessions and execute remote code without authentication. Tracked as CVE-2025-54236 and dubbed “SessionReaper,” the vulnerability allows attackers to hijack sessions and gain high-level access to Magento-based online stores. Akamai’s […]

Wear OS Bug Lets Apps Send Texts Without Permission

A newly disclosed vulnerability in Google Messages for Wear OS allows unprivileged apps to send SMS and RCS messages without user permission, raising concerns over unauthorized communications. The flaw, tracked as CVE-2025-12080 and rated 6.9 under CVSS v4, was discovered by security researcher Gabriele Digregorio. A proof-of-concept exploit is already available, highlighting the ease with […]

Docker Compose Bug Lets Hackers Overwrite Any File

A newly disclosed Docker Compose bug lets hackers overwrite arbitrary files on affected systems by exploiting a high-severity path traversal flaw tracked as CVE-2025-62725. The vulnerability, which carries a CVSS v4 score of 8.9, impacts users of Docker Desktop, standalone Compose binaries, and Compose V2 integrations within the Docker CLI. Attackers can abuse the way […]