loader image
Google Project Zero to Reveal Bugs After One Week

Google Project Zero plans to publicly disclose security vulnerabilities within seven days of reporting them to vendors, aiming to reduce delays in patch adoption. The policy shift targets what researchers describe as the “upstream patch gap,” where fixes exist but downstream vendors have yet to incorporate them into widely used products. By accelerating transparency, Google […]

IBM Says Data Breach Costs Hit Record $10 Million

U.S. organizations are paying more than ever to recover from data breaches, according to IBM’s latest annual report. IBM says data breach costs now exceed $10 million on average, marking a new record high for the country. The report highlights growing financial pressure on businesses as cyberattacks become more frequent and complex. The findings underscore […]

HOOK Android Trojan Adds Ransomware Extortion Tool

A new variant of the HOOK Android Trojan adds ransomware-like overlay screens to its capabilities, cybersecurity researchers revealed. The malware now deploys full-screen ransom messages that aim to pressure victims into making payments. This marks a significant evolution in the trojan’s tactics, blending traditional banking fraud with extortion. According to researchers from Zimperium zLabs, the […]

CISA Flags Citrix, Git Flaws as Active Threats

The U.S. Cybersecurity and Infrastructure Security Agency on Aug. 25 added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, escalating concerns across enterprise IT teams. CISA flags Citrix Git flaws as active threats, highlighting their potential to compromise infrastructure if left unpatched. The vulnerabilities include CVE-2025-48384, a high-severity issue linked to Git, and […]

Google Play Store Hit as Malware Apps Slip Through

Several malicious applications managed to bypass Google’s security checks and land in the Google Play Store, raising concerns over the platform’s ability to screen threats effectively. Security researchers flagged the suspicious apps after users reported abnormal device behavior, including unexpected pop-ups and performance issues. Despite these findings, Google claims its advertising mechanisms remain secure and […]

Microsoft RDP Servers Hit by Coordinated Scan Surge

A wave of coordinated scanning activity is targeting Microsoft RDP servers, according to internet intelligence firm GreyNoise. The firm reported nearly 1,971 unique IP addresses probing Remote Desktop Web Access and RDP Web Client login portals simultaneously, indicating an organized reconnaissance effort. This surge in scans points to a possible campaign aimed at identifying vulnerable […]

AI Image Hack Hides Prompts to Steal User Data

Researchers have discovered a new method to extract sensitive information by embedding hidden prompts within images that are downscaled before being processed by AI systems. This AI Image Hack Hides commands that, once interpreted by a large language model (LLM), trigger unauthorized data access without detection. The attack manipulates the image processing pipeline, exploiting how […]

Farmers Insurance Hack Hits 1.1 Million in Salesforce Breach

Farmers Insurance disclosed a significant data breach affecting 1.1 million individuals, following a broader cybersecurity incident involving Salesforce. The Farmers Insurance Hack Hits has drawn attention to the ripple effects of third-party vulnerabilities, as attackers accessed personal data through compromised Salesforce systems. The insurer confirmed the breach but has not detailed what specific information was […]

Auchan Data Breach Exposes Loyalty Info of Thousands

French retail giant Auchan has disclosed a data breach that affected hundreds of thousands of customers tied to its loyalty program. The Auchan Data Breach Exposes sensitive information linked to user accounts, prompting concerns over potential misuse of customer data. The company confirmed the attack and is actively investigating the scope of the incident. The […]

Google Pulls Malicious Android Apps With 19M Installs

Google has removed 77 malicious Android apps from its Play Store after security researchers discovered they contained various forms of malware. These apps, which appeared to offer legitimate services, were downloaded more than 19 million times before removal. The wave of takedowns highlights ongoing concerns around app store security as Google pulls malicious Android apps […]

Fake Voicemails Hide UpCrypter Malware in Phishing Push

Cybersecurity analysts have uncovered a phishing campaign that uses fake voicemails to hide UpCrypter, a malware loader designed to deploy remote access trojans. The campaign targets users with emails that appear to contain voicemail messages or purchase orders. These convincing lures aim to trick recipients into clicking on malicious links embedded in the messages. Once […]

Mimo Hacks Magento to Steal Card Data, Hijack Bandwidth

The cybercriminal group known as Mimo has shifted its focus from Craft CMS to Magento ecommerce platforms, escalating its attacks on high-value financial targets. In its latest campaign, Mimo hacks Magento systems by exploiting vulnerabilities in PHP-FPM, allowing unauthorized access to sensitive customer data and backend controls. Researchers at DATADOG Security Labs uncovered the campaign […]