loader image
Citrix ‘Bleed 2’ Flaw Joins CISA Exploited List

The U.S. Cybersecurity and Infrastructure Security Agency added the Citrix Bleed 2 flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation in the wild. Tracked as CVE-2025-5777, the vulnerability affects Citrix NetScaler ADC and Gateway products configured as VPN or AAA virtual servers, allowing unauthenticated attackers to steal session cookies and bypass multi-factor authentication. […]

Citrix Flaw Hit by 200,000 Hacking Attempts in Days

Cybersecurity researchers are warning of active exploitation of a critical Citrix flaw hit by attackers, tracked as CVE-2025-5777 and dubbed “CitrixBleed 2.” The vulnerability affects NetScaler ADC and Gateway devices and allows unauthenticated actors to leak sensitive memory contents, including session tokens and passwords. Public proof-of-concept code has triggered over 200,000 scanning attempts across the […]

French Police Arrest Russian Athlete in Ransomware Case

French police arrested a Russian basketball player suspected of involvement in a ransomware operation, according to reports from local media. The case has drawn attention due to the athlete’s lack of known technical expertise, raising questions about the charges. The incident marks the latest international cybercrime crackdown as authorities continue to pursue global ransomware networks. […]

Laravel Flaw Exposes 600 Apps to Remote Code Attacks

A critical Laravel flaw exposes 600 apps to remote code execution by leaking APP_KEY values, according to recent research by GitGuardian and Synacktiv. Since 2018, attackers have accessed over 260,000 APP_KEYs from public GitHub repositories, enabling exploitation across multiple Laravel versions. The flaw stems from Laravel’s decrypt() function, which automatically deserializes data without validation. Malicious […]

SureForms Flaw Exposes 200,000 WordPress Sites to Hackers

A critical flaw in the SureForms WordPress plugin has exposed over 200,000 websites to potential full-site takeover attacks. The vulnerability, identified as CVE-2025-6691 with a CVSS score of 8.8, allows unauthenticated users to delete arbitrary files—including wp-config.php—directly from servers. This SureForms flaw exposes WordPress installations to a risk where attackers can trigger setup mode and […]

Europol, Jordan Join Forces to Fight Cross-Border Crime

Europol and Jordan’s Public Security Directorate signed a Working Arrangement on July 10 to intensify their joint efforts against serious and organized crime. As Europol and Jordan join forces, the agreement creates a formal framework for structured cooperation aimed at countering cross-border threats, including terrorism, impacting the EU, the Middle East and beyond. The arrangement […]

ZuRu Malware Hijacks Termius App to Target macOS Users

A newly discovered variant of the ZuRu malware hijacks Termius, a popular SSH client, to target macOS users with advanced infection tactics. Security researchers uncovered the campaign in late May 2025, marking a significant shift in the malware’s delivery method. Instead of poisoning search results, attackers now bundle malicious code within legitimate applications used by […]

Hackers Steal $500,000 in Crypto via AI Dev Tool Trap

Hackers exploited a malicious extension in the Cursor AI development environment to steal $500,000 in cryptocurrency from a Russian blockchain developer. The attack, which Securelist analysts linked to a fake “Solidity Language” extension, marks a new phase in supply chain intrusions using AI-assisted platforms. Hackers steal 500000 crypto assets by manipulating search algorithms to elevate […]

**US Sanctions North Korea Hackers in IT Jobs Scheme**

The U.S. Treasury on July 8 imposed sanctions on Song Kum Hyok and four entities based in Russia, exposing a covert cyber campaign that has helped fund North Korea’s weapons development. The move, part of a broader push as US sanctions North Korea hackers, highlights the use of remote IT workers embedded in legitimate projects […]

Schneider Electric Flaws Expose Data Centers to Attacks

Schneider Electric has confirmed six critical security weaknesses in its EcoStruxure IT Data Center Expert software, exposing data centers to potential remote code execution. The Schneider Electric flaws expose systems running versions 8.3 and earlier to attacks that could allow unauthorized access and OS-level command injection. The most serious issue, tracked as CVE-2025-50121, received a […]

SafePay Ransomware Hits 200 Firms Using RDP, VPN Hack

SafePay ransomware has rapidly emerged as a major cyber threat, targeting managed service providers and small-to-midsize enterprises across industries. SafePay ransomware hits 200 victims globally in Q1 2025 alone, marking a sharp rise in its activity since its 2024 debut. The group infiltrates networks using compromised Remote Desktop Protocol and Virtual Private Network credentials. Unlike […]

Rockerbox Breach Exposes SSNs, Licenses of 245,949 Users

A misconfigured cloud storage bucket at Dallas-based tax consultancy Rockerbox exposed 245,949 sensitive user records, including Social Security numbers and driver’s licenses. The Rockerbox breach exposes SSNs through an unencrypted 286.9 GB repository that was openly accessible via a simple HTTP GET request and indexed online by early July 2025. The exposed data included tax […]