loader image
**EDR-Redir Tool Outsmarts Defenses Using Windows Driver**

A newly released exploit tool called EDR-Redir allows attackers to reroute or isolate the executable folders of leading endpoint detection and response solutions. The EDR Redir Tool Outsmarts traditional protections by exploiting Windows’ Bind Filter and Cloud Filter drivers, enabling advanced redirection tactics without needing kernel-level access. The technique uses Windows 11’s Bind Link feature, […]

EU Charges Meta, TikTok With Major DSA Breaches

The European Commission has formally accused Meta and TikTok of breaching the Digital Services Act, marking a significant regulatory move as the EU charges Meta TikTok over systemic failures in platform governance. Investigators allege that both companies failed to mitigate the spread of harmful content and did not provide sufficient transparency in their content moderation […]

OpenAI Atlas Jailbroken by Malicious Prompt URLs

OpenAI’s new AI-powered browser, ChatGPT Atlas, has been compromised by a vulnerability that allows attackers to disguise malicious prompts as URLs. The exploit, revealed by security firm NeuralTrust, enables threat actors to jailbreak the system by embedding harmful instructions in malformed web addresses, a flaw now referred to as OpenAI Atlas Jailbroken. These deceptive strings […]

Phishing Attack Uses UUID Trick to Evade Email Security

A new phishing attack uses UUID-based techniques to bypass Secure Email Gateways, exploiting dynamically generated identifiers and randomized domains to evade detection. Security researchers at Cofense identified the campaign in early February 2025, highlighting its use of JavaScript scripts embedded in HTML attachments or spoofed services like SharePoint, OneDrive, and Adobe Acrobat Sign. Unlike conventional […]

Cyber Decoys Trap Hackers as Detection Tech Advances

As cyber threats grow more advanced, traditional defenses like firewalls struggle to keep pace. Cyber decoys trap hackers by luring them into fake environments, allowing defenders to detect and respond to threats before real systems are compromised. Deception technology now plays a pivotal role in proactive cybersecurity strategies, offering early detection, low false positives, and […]

North Korea Hacks EU Drone Firms in Data Theft Blitz

State-sponsored hackers from North Korea’s Lazarus group have launched a cyberespionage campaign targeting European firms in the unmanned aerial vehicle sector. The operation, which began in March 2025, compromised three defense-related organizations in Central and Southeastern Europe. This marks another development in the series of North Korea hacks targeting EU drone technology. The attackers used […]

China-Backed Hackers Share Logins in Spyware Alliance

China-backed hackers share logins through a newly uncovered program dubbed “Premier Pass-as-a-Service,” according to a report from Trend Research. The report highlights a surge in coordination among China-aligned advanced persistent threat (APT) groups, marking a significant evolution in global cyberespionage tactics. These groups are now exchanging credentials and network access, enabling wider infiltration across targeted […]

AI Agents Flawed, Let Hackers Run Code via Prompts

A critical argument injection flaw in several widely used AI agent platforms allows attackers to bypass human approval and execute remote code using crafted prompts. Security firm Trail of Bits identified the design weakness, noting how AI Agents Flawednaturally rely on system tools like grep, git, and go test to streamline operations. These tools, while […]

Salt Typhoon Hacks SharePoint, Hits 3 Governments

Chinese-linked threat group Salt Typhoon exploited a critical Microsoft SharePoint flaw to breach government systems across three continents, according to security researchers. The campaign, described as more widespread than initially believed, shows how Salt Typhoon hacks SharePoint vulnerabilities to infiltrate sensitive networks. Investigators now suspect multiple Chinese-affiliated actors participated in the wave of attacks. The […]

TP-Link Warns of Critical Omada Gateway Flaws

TP-Link warns of critical vulnerabilities affecting its Omada gateway devices, urging users to install firmware updates immediately. The company disclosed four security flaws this week in two advisories, impacting over a dozen models across the ER, G, and FR series. Among them, CVE-2025-6542 stands out with a CVSS score of 9.3, allowing attackers to execute […]

TP-Link Fixes Four Severe Flaws in Omada Gateways

TP-Link has released security updates addressing four critical vulnerabilities in its Omada gateway devices, according to BleepingComputer. The TP-Link fixes four flaws that could have exposed users to unauthorized access or disruption of network services. These flaws, described as severe, prompted urgent attention from the vendor to reduce potential exploitation risks. The affected Omada gateways, […]

Rust Library Flaw Puts Forked Projects at RCE Risk

A critical vulnerability in a discontinued Rust code library has triggered security concerns across multiple software projects. CyberScoop reports that the flaw, identified as CVE-2025-62518, originates from the abandoned async-tar crate and affects several forks that reused its code. The Rust Library Flaw Puts numerous applications at risk by enabling remote code execution through file […]