loader image
U.S. Disrupts Botnet, Charges Russians in Crackdown

U.S. authorities have disrupted a major cybercrime operation involving two proxy services—Anyproxy and 5socks—that leveraged infected devices to form a botnet, according to a law enforcement announcement. The takedown targeted infrastructure used to mask malicious online activity by routing traffic through compromised systems without the owners’ knowledge. The operation, which disabled both platforms, marks a […]

EU Cybersecurity Agency Launches Vulnerability Database

The European Union Agency for Cybersecurity (ENISA) has launched the European Vulnerability Database, a centralized resource aimed at enhancing cybersecurity resilience across the region. The platform aggregates reliable and actionable data on security vulnerabilities affecting Information and Communication Technology (ICT) products and services. Designed to support risk mitigation efforts, the database includes critical information such […]

Ivanti Patches Zero-Days Used in Code Execution Attacks

Ivanti urged customers on Thursday to apply security patches for its Endpoint Manager Mobile (EPMM) software to address two critical zero-day vulnerabilities. The flaws, which have been actively exploited in the wild, can be chained together by attackers to achieve remote code execution on targeted systems. The company issued the warning after identifying that threat […]

Hackers Earn $260,000 Breaking AI, Windows at Pwn2Own

Hackers earned a total of $260,000 in cash prizes on the first day of Pwn2Own Berlin 2025, a high-profile security competition that rewards researchers for identifying and exploiting software vulnerabilities. Participants demonstrated successful exploits targeting a range of platforms, including Red Hat, Microsoft Windows, Oracle VirtualBox, Docker Desktop, and artificial intelligence technologies. The competition, known […]

Eventin WordPress Bug Lets Hackers Control 10,000 Sites

More than 10,000 WordPress websites are at risk following the disclosure of a critical vulnerability in the Eventin plugin, a popular tool developed by Themewinter for event management. Tracked as CVE-2025-47539, the flaw enables unauthenticated attackers to create administrator accounts without user interaction, granting full control over affected sites. Security researchers from Patchstack identified the […]

SIM Swapper Jailed for Hijacking SEC’s X Account

A cybercriminal involved in a SIM-swapping scheme that led to the hijacking of the U.S. Securities and Exchange Commission’s account on X (formerly Twitter) has been sentenced to prison. Authorities linked the scammer to the high-profile breach, which underscored persistent vulnerabilities in mobile-based authentication systems widely used across government and corporate platforms. The attacker exploited […]

Procolored Site Spread Malware-Loaded Software for Months

Procolored, a printer manufacturer, distributed malicious software through its official website for several months, exposing users to cybersecurity threats. Dozens of downloadable programs available on the site were found to contain information stealer malware and a backdoor, according to a report by *SecurityWeek*. The infected software potentially allowed attackers to harvest sensitive user data and […]

Microsoft Patch Fixes Windows Server Hyper-V Freezes

Microsoft has issued an emergency update to resolve a critical issue affecting Windows Server 2022, where some Hyper-V virtual machines were freezing or restarting without warning. The problem, which impacted system stability and disrupted operations for affected users, prompted the company to act swiftly with a targeted fix. According to Microsoft, the update addresses a […]

DragonForce Hits MSP, Abuses SimpleHelp to Spread

The DragonForce ransomware group has compromised a managed service provider (MSP), leveraging its SimpleHelp remote monitoring and management (RMM) platform to infiltrate and encrypt systems across multiple customer networks. The attackers reportedly used the MSP’s access to execute data theft and encryption operations on downstream clients, highlighting the risks associated with centralized IT service platforms. […]

NetBird Malware Hits CFOs in Global Phishing Blitz

Chief financial officers and senior finance executives across global investment, banking, energy, and insurance sectors are being targeted in a sophisticated spear-phishing campaign deploying the NetBird malware, according to a report from GBHackers News. The operation appears designed to infiltrate high-value corporate environments by compromising executive-level email accounts through deceptive, tailored phishing messages. Once delivered […]

Microsoft Edge Adds Bio Lock for Android Private Tabs

Microsoft has introduced a new privacy feature in its Edge browser for Android that allows users to lock InPrivate browsing tabs using a PIN or biometric authentication. The update, currently available in the Canary version, enhances session security by requiring user authentication when returning to private tabs after leaving the app. The feature mirrors similar […]

China Data Leak Exposes 4 Billion User Records

Cybersecurity researchers have uncovered what may be the largest known leak of Chinese personal data from a single source, exposing more than 4 billion records online. The 631-gigabyte trove was found on an unsecured server and included sensitive details such as WeChat and Alipay activity, residential addresses, financial data, and national identification information. The leak, […]