loader image
North Korean Hackers Expand Remote Job Scam Globally

North Korean hackers expand their remote IT worker scam beyond U.S. companies, according to cybersecurity researchers tracking recent activity. Previously, these threat actors focused on applying for outsourced IT support roles at American firms, often gaining access through falsified identities and credentials. Now, security experts report that the campaign has widened to include businesses operating […]

Telegram Data Targeted in RubyGems Supply Attack

Hackers have launched a supply chain attack targeting Telegram data through malicious RubyGems packages that impersonate popular Fastlane CI/CD plugins, according to a report from BleepingComputer. The attackers uploaded two fraudulent libraries to the RubyGems repository, where developers typically obtain trusted components for building and deploying applications. By mimicking Fastlane tools, the packages aimed to […]

Salt Typhoon Hacks Canada Telco Using Cisco Flaw

The Canadian Centre for Cyber Security has confirmed that a Chinese state-sponsored group known as Salt Typhoon carried out a cyberattack against a Canadian telecommunications company in February. The hacking operation exploited a vulnerability in Cisco networking equipment, allowing the attackers unauthorized access to internal systems. The FBI has corroborated the findings, adding that the […]

CISA Flags D-Link, Fortinet Flaws in Exploits List

The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active threats to critical systems. CISA flags D-Link flaws among the trio, alongside issues affecting AMI’s MegaRAC and Fortinet’s FortiOS. The agency urged immediate mitigation to reduce potential exposure to attacks. The vulnerabilities include […]

DragonForce Variant Linked to New DEVMAN Threat Actor

A new DragonForce variant linked to the emerging DEVMAN threat actor has raised concerns among cybersecurity analysts due to unusual behavior in its code. Researchers discovered that the ransomware sample encrypts its own ransom note, a rare trait that complicates both analysis and victim response. The anomaly suggests a possible attempt to evade detection or […]

ModSecurity Flaw Lets Hackers Crash Web Servers

A newly disclosed vulnerability in ModSecurity, one of the most widely used open-source web application firewalls, could allow attackers to crash affected systems. Tracked as CVE-2025-48866, the flaw impacts all versions of mod_security2 prior to 2.9.10 and stems from improper handling of the `sanitiseArg` and `sanitizeArg` actions. Attackers can exploit the vulnerability remotely without authentication, […]

Qilin Ransomware Adds Lawyers to Squeeze Victims

The Qilin ransomware group has introduced a new “Call Lawyer” function to its affiliate platform, aiming to intensify pressure on victims during ransom negotiations. According to cybersecurity firm Cybereason, the Qilin ransomware adds lawyers to its toolkit as part of a broader strategy to expand its influence and fill gaps left by rival criminal groups. […]

UK Police Advisor Flags 7 Key Tech Trends in Report

The Office of the Police Chief Scientific Advisor has released a new report outlining seven emerging technologies that could reshape law enforcement practices in the UK. Titled the Police Emerging Science and Technology Trends report, the document highlights innovations in digital forensics, biometric identification, and artificial intelligence. The UK Police Advisor flags these developments as […]

Iran-Linked Hack Disrupts Services in Albanian Capital

A hacker group tied to Iran’s Islamic Revolutionary Guard Corps has taken responsibility for a cyberattack that disrupted digital services in Tirana, Albania’s capital. The attack targeted the city’s municipal website, marking the latest Iran-linked hack disruption in a growing pattern of hostile cyber activity against Albanian infrastructure. Authorities have not disclosed the full extent […]

AT&T Unveils Wireless Lock to Thwart SIM Swaps

AT&T unveils Wireless Lock, a new feature designed to shield customers from SIM swapping attacks by blocking unauthorized changes to account information and number porting. The safeguard aims to prevent criminals from taking control of a user’s phone number to access sensitive data, including banking and authentication codes. Once activated, Wireless Lock restricts any modifications […]

ASUS Routers Hacked in Botnet Attack Using SSH Key

A newly discovered botnet campaign known as “AyySSHush” has compromised more than 9,000 ASUS routers globally, cybersecurity researchers said. The attackers gained persistent remote access by injecting an SSH public key, enabling control that survives reboots and firmware upgrades. Uncovered in March 2025, the campaign exploits two previously unknown authentication bypass flaws and CVE-2023-39780, a […]

EU Unveils Cyber Plan to Coordinate Crisis Response

The European Union has unveiled a comprehensive Cyber Blueprint aimed at streamlining crisis management across member states, establishing a unified response framework, and reinforcing cross-border coordination. The initiative is designed to improve the EU’s collective resilience against large-scale cyber incidents by enabling faster, more coordinated responses among national authorities. The blueprint introduces a structured approach […]