loader image
South African Accounts Target Zelensky in Campaign

A coordinated influence campaign targeting Ukraine’s president has been traced to a network of South African influencers-for-hire, according to new findings from the Atlantic Council’s Digital Forensic Research Lab (DFRLab). The analysis identified more than 40 social media accounts involved in the effort, which aimed to manipulate online discourse through traffic amplification tactics. The campaign […]

North Korea Hackers Target South Korea in Spy Campaign

A North Korean-linked hacking group known as APT37, also referred to as ScarCruft, has launched a fresh cyber-espionage campaign targeting South Korean entities with ties to national security, analysts at cybersecurity firm Genians said. The group is reportedly using phishing tactics to infiltrate organizations and extract sensitive information. The campaign highlights ongoing cyber threats from […]

VMware, SharePoint Hacked in $435,000 Pwn2Own Blitz

Security researchers disclosed a series of critical zero-day vulnerabilities affecting major enterprise platforms during Day Two of the Pwn2Own Berlin 2025 contest, with total winnings reaching $435,000. Hosted at OffensiveCon, the event featured successful exploits targeting VMware ESXi, Microsoft SharePoint, Mozilla Firefox, and Red Hat Enterprise Linux. In a first for the contest, a researcher […]

Akamai, Microsoft Clash Over ‘BadSuccessor’ Flaw Patch

Akamai has identified a privilege escalation vulnerability in Windows Server 2025, which it is calling ‘BadSuccessor’, raising concerns over Microsoft’s decision not to release an immediate fix. The flaw, according to Akamai, could allow attackers to escalate privileges on affected systems, posing a potential risk to enterprise environments relying on the upcoming server version. Despite […]

CompTIA Launches SecOT+ to Bridge OT Cyber Gap

CompTIA has introduced a new cybersecurity certification, SecOT+, designed to bridge the skills gap between information technology (IT) and operational technology (OT) professionals. The initiative targets a growing need for cybersecurity expertise in industrial environments, where the convergence of IT and OT systems has introduced new vulnerabilities. The SecOT+ certification aims to equip workers with […]

UK Says Legal Aid Hack Exposed Sensitive Applicant Data

The U.K. government has confirmed a significant data breach involving the Legal Aid Agency, resulting in the potential exposure of a large volume of sensitive personal information. According to officials, the compromised data pertains to individuals who applied for legal aid, raising concerns that the information may now be in the hands of cybercriminals. The […]

Claude 4 Cuts Vibe Coding Errors by 25%, Boosts Speed

Lovable, a company specializing in Vibe coding, reported a 25% reduction in syntax errors after adopting Claude 4, the latest iteration of the large language model developed by Anthropic. In addition to improved coding accuracy, the company said its development process became 40% faster with the tool’s integration. The update reflects the growing trend of […]

ClickFix Tool Spreads Stealthy Rust-Based Infostealer

A newly identified information-stealing malware dubbed EDDIESTEALER is using the ClickFix platform as a distribution vector, according to cybersecurity researchers. The malicious software is written in the Rust programming language and employs code obfuscation techniques alongside dynamic command-and-control (C2) tasking, allowing it to evade standard detection tools and adapt to changing environments. EDDIESTEALER’s reliance on […]

Cartier Urges Vigilance After Customer Data Theft

Luxury jeweler Cartier is urging customers to remain vigilant against phishing attempts following a data breach that compromised user information. While no highly sensitive or financially valuable data appears to have been stolen in the cyberattack, the incident has raised concerns about the privacy of affected individuals. The company confirmed that the breach led to […]

Instantel Devices Exposed to Hack Risk, Researcher Says

More than 1,000 industrial monitoring devices manufactured by Instantel may be vulnerable to cyberattacks following the discovery of a critical command execution flaw in the company’s Micromate units. The flaw, identified by a researcher, could allow an attacker to gain unauthorized control of the devices, potentially disrupting their operation or accessing sensitive environmental data. The […]

Google Says Hackers Pose as IT to Breach Firms

Hackers are increasingly using fake IT support calls as a tactic to infiltrate corporate systems, according to a warning from Google. The attackers impersonate legitimate helpdesk personnel, contacting employees to manipulate them into granting access to sensitive internal resources. These social engineering schemes are designed to bypass security measures by exploiting human trust rather than […]

Infoblox NetMRI Bugs Expose Systems to Remote Attacks

Infoblox NetMRI, a network automation and management platform, has been found to contain multiple critical security vulnerabilities, according to a post shared on the r/netsec forum. The flaws include remote code execution (RCE), authentication bypass, SQL injection (SQLi), and arbitrary file read vulnerabilities. These issues are identified by several CVEs, though specific identifiers were not […]