loader image
SUR-FBD CMMS Software Hit by Hard-Coded Password Bug

A critical security flaw has been identified in the SUR-FBD CMMS Software, exposing users to unauthorized access risks. The vulnerability, tracked as CVE-2025-3920, stems from the use of hard-coded passwords within the application. Security researchers warn that attackers could exploit this flaw to bypass authentication measures and gain control over the system. The hard-coded credential […]

BlueNoroff Hacks Zoom Calls to Steal Crypto Data

North Korea-linked hackers from BlueNoroff are exploiting the popularity of Zoom in a new wave of cyberattacks targeting cryptocurrency and financial firms. The group, known for its ties to the Lazarus Group, uses deceptive Zoom-related infrastructure to impersonate trusted contacts and trick victims into launching malicious scripts. This campaign, active since March 2025, marks a […]

Chrome, Firefox Fix High-Severity Security Flaws

Google and Mozilla have released Chrome 138 and Firefox 140, addressing more than two dozen security flaws, including several classified as high-severity. The Chrome Firefox fix high severity updates aim to strengthen user protection by resolving critical memory safety issues that could expose users to potential exploits. The latest versions of both browsers contain patches […]

Claroty Finds Ransomware Risks in Building Systems

Cybersecurity firm Claroty has uncovered significant vulnerabilities across building management systems, revealing widespread exposure to ransomware threats and insecure internet configurations. In its latest findings, Claroty finds ransomware risks tied to known exploited vulnerabilities (KEVs) that attackers could weaponize to disrupt critical infrastructure operations. The report highlights numerous systems with direct internet exposure, increasing the […]

Ingram Micro Hit by Ransomware in Prolonged Outage

Ingram Micro, one of the world’s largest technology distributors, has confirmed that a ransomware attack caused the recent multi-day system outage. The incident, now attributed to the SafePay group, disrupted services and raised concerns across its global operations. Ingram Micro hit by ransomware attacks like this one highlights growing threats to supply chain infrastructure in […]

French Court Halts Challenge to Web Censorship Law

France’s highest administrative court has dismissed a legal challenge against the government’s online censorship law, effectively closing the door on further judicial scrutiny. The French Court halts challenge efforts by refusing to refer the case to the Court of Justice of the European Union, a move critics say undermines European legal oversight. The decision, delivered […]

’16 Billion Password Leak’ Dismissed as Baseless

A recent wave of headlines surrounding a so-called 16 Billion Password Leak has drawn criticism from cybersecurity experts, who say the claims lack credibility and distract from real threats. The story, which gained traction across media outlets, suggested a massive breach exposing billions of credentials. However, analysts told CyberScoop the evidence simply doesn’t add up. […]

Prometei Botnet Surges With New Malware, Palo Alto Says

Prometei Botnet Surges With renewed intensity as cybersecurity researchers from Palo Alto Networks report a sharp increase in activity since March 2025. The latest variant, targeting Linux systems, spreads rapidly through HTTP GET requests, delivering a UPX-packed 64-bit ELF file disguised as a .php script. Analysts say the botnet focuses on Monero mining and credential […]

Google Patches Fourth Chrome Zero-Day Exploit of 2025

Google has issued an emergency security update for Chrome to resolve a zero-day vulnerability actively exploited in the wild. This latest release brings the total number of such flaws patched in 2025 to four. Google patches fourth Chrome zero-day this year amid growing concerns over browser-based attacks. The company moved quickly to roll out the […]

Amazon EKS Flaws Let Hackers Steal AWS Credentials

Critical vulnerabilities in Amazon Elastic Kubernetes Service (EKS) allow overprivileged containers to steal AWS credentials through packet sniffing and spoofing attacks. Amazon EKS flaws let attackers exploit the 169.254.170.23:80 endpoint by intercepting plaintext traffic or deploying fake HTTP servers. These exposures, disclosed on June 19, 2025, underscore the risks in AWS’s shared responsibility model. The […]

Visa Applicants Must Make Social Media Profiles Public

The United States Embassy in India has introduced new guidance requiring F, M, and J visa applicants to make their social media accounts publicly viewable. Visa applicants must make social media settings accessible to assist consular officials in verifying identity and confirming eligibility under U.S. immigration law. The embassy emphasized that every visa application undergoes […]

ECSO Names Świątkowska to Succeed Founding Chief

The European Cyber Security Organisation announced that Dr. Joanna Świątkowska will assume the role of Secretary General starting July 2025. ECSO names Świątkowska successor to founding Secretary General Dr. Luigi Rebuffi, who has led the organization since its inception. The appointment marks a significant leadership transition for ECSO, which plays a central role in strengthening […]