loader image
Linux Bugs Expose Password Hashes in Core Dumps

Two newly discovered vulnerabilities in popular Linux distributions could allow local attackers to access sensitive data, including password hashes, security researchers have found. The flaws, tracked as CVE-2025-5054 and CVE-2025-4598, affect apport and systemd-coredump—core dump handling utilities used in Ubuntu, Red Hat Enterprise Linux (RHEL), and Fedora. According to the Qualys Threat Research Unit, both […]

Microsoft, CrowdStrike Unite to Decode Hacker Aliases

Microsoft Corp. and CrowdStrike Holdings Inc. have launched a joint initiative to streamline cyber threat actor identification, aiming to eliminate confusion caused by inconsistent naming conventions across the cybersecurity industry. The collaboration, announced yesterday, introduces a cross-referenced mapping system that links varying threat actor names used by different vendors, without enforcing a unified standard. The […]

Crocodilus Malware Fakes Contacts to Mimic Banks

A newly observed campaign involving the Crocodilus malware is raising alarms among cybersecurity researchers, who warn that the Android-based threat is adopting deceptive tactics to facilitate banking fraud. The malware reportedly infiltrates victims’ devices and inserts fake entries into their contact lists, making it appear as though incoming messages or calls are coming from legitimate […]

Google Play Apps Lure Crypto Users for Seed Phrases

More than 20 malicious applications found on the Google Play Store have been targeting cryptocurrency users by attempting to steal their seed phrases, according to cybersecurity researchers. These apps, disguised as legitimate crypto wallet tools, were designed to trick users into entering sensitive information that could grant attackers full access to their digital assets. The […]

Cisco Patches ISE, CCP Flaws Amid Exploit Code Threat

Cisco has issued security updates to fix three vulnerabilities affecting its Identity Services Engine (ISE) and Customer Collaboration Platform (CCP), warning that public exploit code is already available for the flaws. The company released patches to mitigate the risks associated with these security weaknesses, which could potentially be used by threat actors to compromise affected […]

WordPress Hijacked to Spread VexTrio Scam Globally

Cybercriminals are exploiting legitimate WordPress websites in a growing scheme tied to the VexTrio Viper Traffic Distribution Service (TDS). The operation, which security researchers describe as highly organized, uses WordPress hijacked to spread malicious software and scams across a global network. VexTrio appears to operate alongside other TDS platforms, including Help TDS and Disposable TDS. […]

Tines Uses AI to Speed IT Ticket Resolution

IT teams facing a flood of support tickets can now streamline their response times with an automated workflow powered by AI and Tines. Designed to handle repetitive tasks, the system triages frequent issues such as password resets and known bugs. By automating these common requests, teams can reallocate resources to more complex problems and reduce […]

North Korea Hacks npm in Supply Chain Attack on Devs

Cybersecurity researchers have identified a new wave of North Korea hacks npm as part of an ongoing supply chain attack targeting software developers. The campaign, known as Contagious Interview, involves 35 malicious JavaScript packages published through 24 separate npm accounts. Security firm Socket reported that these packages have already been downloaded more than 4,000 times. […]

PlexTrac Unifies SOC Data to Halve Cyberattacks by 2028

PlexTrac Unifies SOC Data by integrating exposure management with incident response, offering security teams a centralized platform to streamline operations. As cyber threats grow more sophisticated, organizations face mounting pressure to reduce attack surfaces and accelerate remediation. PlexTrac’s platform consolidates critical security data, equipping analysts with real-time visibility and actionable insights. By enriching SOC data […]

Poland Arrests 4 in Takedown of DDoS Attack Rings

Polish authorities, collaborating with Europol and other international law enforcement agencies, have arrested four individuals accused of operating six distributed denial-of-service (DDoS) platforms. The takedown is part of a coordinated multinational effort to disrupt the growing market for DDoS-for-hire services—commonly known as “booter” or “stresser” sites. According to officials, the seized platforms were linked to […]

South African Airways Hit by Cyberattack, Probes Hack

South African Airways said a cyberattack temporarily disrupted its operational systems, affecting some of its services. The airline is currently investigating the incident to determine whether any sensitive information may have been compromised during the breach. The disruption caused by the attack was limited in duration, the company said, and efforts are ongoing to fully […]

Masimo Cyberattack Disrupts Device Production, Orders

Masimo Corp., a manufacturer of medical devices, disclosed that it is grappling with a cyberattack that has disrupted its production operations, resulting in delays in order fulfillment. The company did not specify the nature or origin of the attack but confirmed that the incident is directly impacting its ability to meet customer demand on schedule. […]