loader image
APT28 Hacks Gov’t Email via MDaemon Zero-Day Bug

A Russian state-linked hacking group has exploited a zero-day vulnerability in MDaemon webmail software as part of a broader cyber espionage campaign targeting government email servers, according to new research from cybersecurity firm ESET. Dubbed Operation RoundPress, the activity began in 2023 and focused on exploiting cross-site scripting (XSS) flaws in multiple webmail platforms, including […]

Russia Disinformation Hits Poland, Romania Elections

Russian disinformation campaigns are intensifying in Poland and Romania as voters head to the polls for presidential elections, according to local authorities. Officials from both countries report a surge in activity linked to the Kremlin-backed influence network known as Doppelgänger. The disinformation effort appears designed to sway public opinion and disrupt the electoral process, with […]

vBulletin Flaws Let Hackers Seize Forums via API, RCE

Two critical vulnerabilities in the vBulletin forum software are under active exploitation, security researchers warned. Tracked as CVE-2025-48827 and CVE-2025-48828, the flaws affect vBulletin versions 5.0.0 to 5.7.5 and 6.0.0 to 6.0.3 when running on PHP 8.1 or newer. CVE-2025-48827, rated with a maximum CVSS score of 10, allows unauthenticated users to invoke protected API […]

TikTok Users Hit by AI Malware in Video Scam

Hackers are exploiting TikTok’s popularity to distribute information-stealing malware using AI-generated tutorial videos, according to researchers at Censys. The campaign targets users searching for pirated software by presenting convincing how-to videos that guide viewers through fake activation processes. Instead of legitimate instructions, the videos prompt users to run PowerShell commands that install malware such as […]

Coinbase Breach Tied to Bribed TaskUs Agents in India

Coinbase, one of the largest cryptocurrency exchanges in the U.S., has confirmed a data breach linked to bribed customer support agents at TaskUs, a third-party service provider based in India. Threat actors reportedly targeted support personnel employed by TaskUs, offering bribes in exchange for internal access that was then used to extract sensitive user data […]

Gluestack NPM Hack Hits 960,000 Weekly Downloads

A major supply chain attack has compromised 15 widely used Gluestack packages on the NPM registry, affecting libraries that collectively draw over 950,000 downloads each week. The affected packages were altered to include malicious code functioning as a remote access trojan (RAT), enabling attackers to potentially gain unauthorized control over systems running the compromised software. […]

ClickFix Hack Fakes Cloudflare to Spread Malware

Cybersecurity researchers have uncovered a ClickFix malware campaign that leverages a counterfeit Cloudflare Turnstile—a system typically used to verify human users—to trick victims into downloading malicious software. The attack mimics Cloudflare’s “humanness” verification process to deceive users into believing they are interacting with a legitimate security check. Once engaged, the fraudulent interface initiates the installation […]

Ukraine Hacks Tupolev in Escalating Cyber Strike

Ukraine has launched a second cyberattack targeting Russian military assets, this time focusing on Tupolev, a prominent aircraft manufacturer. The move signals an escalation in Ukraine’s digital offensive, suggesting that drones alone may no longer suffice in its strategic operations. The attack, described as a hack, is part of an ongoing campaign to disrupt Russia’s […]

Paragon Spyware Found on iPhones of EU Journalists

Researchers have confirmed that spyware developed by Paragon was found on an Apple device, marking a significant development in a growing surveillance controversy in Italy. The discovery, revealed Wednesday, adds to mounting concerns over the use of advanced surveillance tools targeting journalists across Europe. The spyware’s presence was detected during an investigation into potential abuses […]

OpenSSL Prague 2025 Speaker Deadline Nears

Organizers of the OpenSSL Prague 2025 speaker program are urging cybersecurity professionals to submit their proposals as the application deadline nears. The annual event, set to take place in the Czech capital, aims to spotlight advancements in encryption, secure communications, and open-source cryptographic tools. Organizers are looking for experienced voices to lead technical sessions, workshops, […]

Hackers Fake SonicWall VPN to Steal Corporate Logins

Hackers are distributing a fake SonicWall VPN application to steal corporate login credentials from remote users. The malicious software mimics SonicWall’s legitimate NetExtender SSL VPN app, which allows employees to securely connect to internal networks. Dubbed “SilentRoute” by Microsoft Threat Intelligence, the trojanized version tricks users into installing it, giving attackers access to sensitive data. […]

Windows 11 Update Adds 38 Fixes, Taskbar Tweaks

Microsoft on Thursday rolled out the KB5060829 preview cumulative update for Windows 11 version 24H2, delivering 38 changes and enhancements aimed at improving user experience. The Windows 11 Update Adds refinements to core features, including updates to the taskbar and the introduction of a streamlined PC-to-PC migration process. The update focuses on both functionality and […]