loader image
Hackers Lure Victims With Fake Prompts in ClickFix Attacks

Hackers are deploying a new social engineering tactic known as “ClickFix” to exploit human error by mimicking routine computer prompts, cybersecurity researchers warned. First observed in March 2024, the method disguises malicious activity as legitimate system messages—such as CAPTCHA verifications or maintenance alerts—tricking users into executing harmful PowerShell commands. The technique has been linked to […]

Iran Hackers Target Iraq, Kurd Officials Since 2017

A hacking group with ties to Iran has been conducting a prolonged cyberespionage campaign targeting Kurdish and Iraqi officials, according to cybersecurity researchers. The group has been active since at least 2017, initially breaching systems associated with the Kurdistan Regional Government. Over the years, the scope of the campaign has widened to include entities within […]

Microsoft Issues Fix for Windows 11 Update Conflict

Microsoft has issued a revised version of its Windows 11 24H2 update to address compatibility issues reported with the original release earlier this month. The company confirmed Tuesday that the new update targets systems deemed incompatible with the initial Patch Tuesday rollout, which included security enhancements. The separate build is intended to ensure that affected […]

Euro Cops Bust Archetyp, Seize $270 Million Drug Hub

European law enforcement agencies dismantled a major dark web drug marketplace known as Archetyp, arresting eight individuals linked to the illicit operation. Authorities said the takedown, dubbed one of the largest of its kind, came after a coordinated investigation across multiple countries. Euro Cops Bust Archetyp marked a significant blow to underground online drug trade […]

NHS Teams Embrace AI as Calls Grow for Clear Rules

NHS communications teams are increasingly integrating artificial intelligence into their operations, according to a new survey by the NHS Confederation. The findings show growing enthusiasm across organizations as NHS teams embrace AI naturally to manage workloads, streamline messaging, and enhance public engagement. While the report highlights a surge in adoption, it also underscores the need […]

Hackers Twist ScreenConnect Into Signed Malware

Hackers twist ScreenConnect into a new cyber threat by manipulating the installer’s digital signature, turning the legitimate remote access tool into a vehicle for malware. According to recent findings, threat actors are exploiting the ConnectWise ScreenConnect client by altering concealed settings within its Authenticode signature. This technique allows them to create signed remote access malware […]

UK Anti-Encryption Site Promotes Payday Loan Ads

A UK Anti-Encryption Site backed by the Home Office has come under scrutiny after it unexpectedly began promoting payday loan services. Investigators discovered that users visiting the campaign’s website, which aims to raise awareness about the risks of encrypted communication, were being redirected to financial products unrelated to the site’s original purpose. The company responsible […]

**Microsoft Patches Critical Remote Desktop Flaws**

Microsoft has patched two critical vulnerabilities in its Remote Desktop services that could allow attackers to execute malicious code remotely, the company said in its May 2025 Patch Tuesday release. The flaws—tracked as CVE-2025-29966 and CVE-2025-29967—affect the Remote Desktop Client and Gateway Service. Both are heap-based buffer overflow vulnerabilities with high CVSS scores, enabling remote […]

Australia Orders Ransomware Payment Reports in 3 Days

Australia has enacted new regulations mandating that covered organizations report ransomware and cyber extortion payments within three days. The requirement is part of a broader effort to strengthen the country’s cybersecurity posture and improve incident transparency. Under the new rules, entities classified as covered organizations must disclose any payments made in response to ransomware attacks […]

HPE Fixes StoreOnce Flaw Allowing Remote Intrusion

Hewlett Packard Enterprise has issued security patches addressing a set of eight vulnerabilities in its StoreOnce data backup and deduplication product. The flaws, if left unpatched, could allow attackers to bypass authentication mechanisms and execute arbitrary code remotely, the company said. The vulnerabilities impact the StoreOnce platform, which is used by enterprises to manage and […]

CISA Flags Chrome 0-Day Bug Exploited in Active Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert for a zero-day vulnerability in Google Chrome, actively exploited by attackers to execute arbitrary code. Tracked as CVE-2025-5419, the flaw resides in Chrome’s V8 JavaScript and WebAssembly engine and impacts versions prior to 137.0.7151.68. Added to CISA’s Known Exploited Vulnerabilities Catalog on […]

Apache Tomcat Panels Hit by Coordinated Login Attacks

Hackers are launching a coordinated wave of brute-force attacks on Apache Tomcat Manager interfaces exposed to the internet, using hundreds of unique IP addresses to escalate their efforts. The campaign targets web servers running the open-source Apache Tomcat software, aiming to gain unauthorized access to administrative panels by systematically guessing login credentials. Security analysts report […]