loader image
Fortinet 0-Day Exploit Released as Attacks Surge

A publicly available proof-of-concept (PoC) exploit for a critical zero-day vulnerability in multiple Fortinet products has heightened concerns over enterprise network security. The flaw, identified as CVE-2025-32756 with a CVSS score of 9.8, enables unauthenticated remote code execution via a stack-based buffer overflow in the `/remote/hostcheck_validate` endpoint. It originates from improper bounds checking of the […]

DOJ Seizes $7.7M in Crypto Tied to North Korea Plot

The U.S. Department of Justice has seized approximately $7.7 million in cryptocurrency tied to an alleged scheme involving North Korean information technology workers, authorities said. The funds were frozen and confiscated after North Korean nationals reportedly attempted to launder the assets, which were linked to a long-running conspiracy. Officials stated the funds were illicitly obtained […]

Honeywell Finds 1,000 Threats in OT Log Review

Honeywell’s Advanced Monitoring and Incident Response (AMIR) service identified more than 1,000 cybersecurity incidents after analyzing 90 billion logs, reflecting a growing wave of threats targeting operational technology (OT) systems. The findings highlight the increasing complexity and frequency of cyber risks confronting industrial environments. The AMIR service, which specializes in monitoring and investigating cybersecurity events […]

Meta Challenges House Ban on WhatsApp for Staffers

Meta expressed confusion Monday after a directive from the House of Representatives ordered staffers to remove WhatsApp from official devices starting next week. The policy, delivered in a notice from the House’s chief administrative officer, bans the messaging app without offering a clear explanation, prompting Meta to challenge the decision. Meta challenges House ban by […]

Glasgow City Council Hit by Suspected Data Breach

Glasgow City Council reported a cyber incident that disrupted multiple online services and may have compromised customer data. The council confirmed the issue on its official channels, stating that the breach had affected operations and potentially led to unauthorized access to personal information. The Glasgow City Council data breach has raised concerns about the security […]

Ex-NATO Hacker Warns Cyber Wars Never Cease

Cyberattacks don’t pause for diplomacy, and digital warfare rarely recognizes traditional boundaries, an ex-NATO hacker warned during a recent interview focused on global cybersecurity threats. The former military cyber specialist emphasized that in the digital domain, there’s no such thing as a ceasefire—a reality that government agencies and private companies must urgently accept. He particularly […]

Atos Unveils Tool to Automate EU Cyber Compliance

Atos has rolled out its SecureHorizons NIS2 Compliance Manager on the ServiceNow platform, aiming to streamline and automate cybersecurity compliance for organizations across the European Union. The new solution is designed to help businesses meet the requirements of the EU’s Network and Information Security Directive (NIS2), which mandates stricter cybersecurity and risk management practices. By […]

Apache Parquet Exploit Tool Targets Critical Flaw

A proof-of-concept exploit has been made publicly available for a critical vulnerability in Apache Parquet, identified as CVE-2025-30065, potentially exposing servers to remote attacks. The flaw carries the highest severity rating, enabling threat actors to easily locate and target unpatched systems. Apache Parquet is a widely used open-source data storage format, and the release of […]

Ascension Health Breach Hit 437,000, U.S. Says

A data breach at Ascension Health in April 2025 affected 437,329 individuals, according to a report filed with the U.S. Department of Health and Human Services. The incident underscores the persistent vulnerabilities tied to third-party software flaws and inadequate identity management practices that continue to challenge healthcare organizations. While specific technical details of the breach […]

F5 Flaw Lets Admins Run Rogue Commands as Root

F5 Networks has disclosed a high-severity command injection vulnerability affecting its BIG-IP products operating in Appliance mode. Tracked as CVE-2025-31644, the flaw resides in an undisclosed iControl REST endpoint and a TMOS Shell (tmsh) command, allowing authenticated attackers to execute arbitrary system commands by bypassing security restrictions. The vulnerability is rated 8.7 on the CVSS […]

Kosovo Man Extradited to U.S. for Dark Web Market

A 33-year-old citizen of Kosovo has been extradited to the United States to face charges in connection with the operation of an illegal online marketplace, U.S. authorities said. The individual is accused of playing a significant role in managing the platform, which allegedly facilitated unlawful transactions over the internet. The extradition underscores ongoing efforts by […]

Windows 10 Update Triggers BitLocker Recovery Errors

A recent Windows 10 update, labeled KB5058379, is triggering unexpected BitLocker recovery prompts on some devices following installation and a system reboot. The cumulative update, pushed as part of Microsoft’s regular release cycle, appears to inadvertently activate the recovery process for BitLocker, the operating system’s built-in encryption feature. Users who applied the update have reported […]