loader image
Misconfigured HMIs Leave U.S. Water Systems Exposed

Hundreds of dashboard interfaces used to control U.S. water utility systems have been found accessible on the open internet, according to researchers at Censys. The exposed human-machine interfaces (HMIs), which are commonly used in industrial control systems, were misconfigured in a way that allowed anyone with a web browser to view sensitive control-room data. Investigators […]

Fake DocuSign, Gitcode Sites Spread NetSupport RAT

Hackers are leveraging fake Gitcode and DocuSign websites to distribute the NetSupport Remote Access Trojan (RAT), according to a report from The Hacker News. The campaign uses lookalike domains that mimic legitimate platforms to deceive users into downloading the malware. Once installed, NetSupport RAT grants attackers remote control over compromised systems, enabling them to steal […]

SentinelOne Ties ShadowPad Hack to China-Backed Group

SentinelOne researchers have attributed recent cyberattacks involving the ShadowPad and PurpleHaze malware families to China-aligned threat actors, the company said. The cybersecurity firm’s analysis established the link with what it described as “high confidence,” signaling an escalation in the attribution of sophisticated cyber campaigns targeting global networks. ShadowPad, a modular backdoor framework, and PurpleHaze, a […]

AWS Enforces MFA for All Root Users at re:Inforce

Amazon Web Services now requires multi-factor authentication for 100% of root users, marking a significant shift in its cloud security strategy. The announcement came during the company’s re:Inforce event, where AWS Enforces MFA as part of a broader effort to tighten access controls across its platform. This move aims to reduce the risk of unauthorized […]

AT&T Wins Court Nod for $117 Million Breach Deal

AT&T won court approval for a $117 million settlement tied to multiple data breaches that exposed customer information last year. The ruling, issued by U.S. District Judge Ada Brown, allows the telecom giant to resolve a series of lawsuits brought by affected users. AT&T wins court nod as it seeks to close the chapter on […]

WinRAR Fixes Flaw Letting Malware Run on Extraction

WinRAR has released a security update to resolve a directory traversal vulnerability identified as CVE-2025-6218. Under specific conditions, the flaw could allow malware to execute automatically after a user extracts a specially crafted archive. This update follows reports that threat actors might exploit the vulnerability to bypass standard file extraction safety measures. WinRAR fixes flaw […]

Johnson Controls Reveals Victims in 2023 Hack

Johnson Controls reveals victims of a 2023 ransomware attack as it begins notifying individuals impacted by the breach. The multinational manufacturer of automation systems confirmed the incident but has not disclosed what type of data was compromised. The breach, which occurred last year, follows a growing trend of cyberattacks targeting industrial and infrastructure firms. The […]

Hackers Use Malicious Chargers to Breach Smartphones

Cybersecurity researchers have uncovered a new attack method known as “ChoiceJacking,” which enables malicious charging stations to compromise both Android and iOS devices. Discovered by researchers at Graz University of Technology, the technique bypasses long-standing USB security protections by exploiting flaws in user confirmation mechanisms. The attack combines elements of USB host and accessory protocols, […]

PathWiper Malware Hits Ukraine’s Critical Systems

A newly identified data-wiping malware known as “PathWiper” is being deployed in targeted attacks against critical infrastructure in Ukraine, aiming to disrupt essential operations across the country. The malware is designed to erase data irreversibly, posing a significant threat to the stability and functionality of national systems. The attacks appear to be part of a […]

Kettering Health Hit by Interlock in Data Leak Attack

The Interlock ransomware group has taken credit for a cyberattack on Kettering Health, a healthcare network, and has released data it claims was stolen during the breach. The group posted samples of the allegedly compromised information on its leak site, asserting that the files were extracted from Kettering Health’s internal systems. The scope of the […]

OpenAI Shuts 10 Malicious AI Ops Tied to US Rivals

OpenAI has dismantled ten covert influence operations leveraging its artificial intelligence tools, linking the campaigns to state-affiliated actors in China, Russia, Iran and North Korea. The takedowns mark a significant move in the company’s efforts to combat the misuse of generative AI technologies for geopolitical manipulation. According to a report published by Hackread, the terminated […]

Envilder CLI Secures AWS Secrets With Fast Sync Tool

Envilder, a newly introduced command-line interface (CLI) tool, offers a streamlined and secure method for managing environment variables by synchronizing them directly from Amazon Web Services (AWS) Systems Manager (SSM) Parameter Store. Designed to enhance secrets management and configuration hygiene, the tool enables developers and system administrators to sync parameters efficiently into local shell environments […]