loader image
M&S Says Cyberattack to Cut Profit by £300 Million

Marks & Spencer said a recent cyberattack will reduce its operating profit by an estimated £300 million, citing ongoing disruption expected to last through July. The British retailer disclosed that the financial impact figure is calculated before factoring in potential cost mitigation, insurance coverage or trading-related actions. The company did not specify details about the […]

Enzene Biosciences Hit by Cyberattack on U.S. Ops

Enzene Biosciences, a biotechnology subsidiary of Indian pharmaceutical giant Alkem Laboratories, has experienced a cybersecurity breach that disrupted its U.S. operations, according to a report by The Cyber Express. The incident, which involved unauthorized access, reportedly led to a compromise of company funds, although the scope and financial impact have not been disclosed. The attack […]

Crawlomatic Plugin Patched for Critical RCE Flaw

A critical remote code execution vulnerability with a CVSS score of 9.8 has been patched in the Crawlomatic WordPress plugin, according to a notice published by cybersecurity sources. The flaw stemmed from a missing file type validation mechanism, which allowed attackers to upload arbitrary files to affected systems. This oversight enabled unauthorized users to execute […]

Arla Foods Hit by Cyberattack, Production Disrupted

Arla Foods has confirmed that it was targeted by a cyberattack that disrupted production operations, causing delays across its supply chain. The dairy giant disclosed the incident to BleepingComputer, stating that the attack affected its ability to produce and distribute goods efficiently. While the company did not provide details about the nature or scope of […]

vBulletin Flaw Exposes Forums to Remote Code Attacks

A critical vulnerability in vBulletin, one of the most widely used internet forum platforms, has exposed thousands of websites to unauthenticated remote code execution (RCE), cybersecurity researchers have disclosed. The flaw affects vBulletin versions 5.x and 6.x running on PHP 8.1 or later, where changes to PHP’s Reflection API allow attackers to invoke protected methods […]

Fred Hutch to Pay $50 Million in Data Breach Deal

Fred Hutchinson Cancer Center has agreed to pay over $50 million in the aftermath of a 2023 data breach, earmarking the funds for damages, infrastructure upgrades, and fraud monitoring services. The financial commitment follows a cyberattack that compromised sensitive information, prompting the organization to take corrective measures to mitigate fallout and prevent future incidents. According […]

Victoria’s Secret Delays Results After Cyberattack

Victoria’s Secret & Co. has postponed the release of its first-quarter 2025 earnings after experiencing a security incident that disrupted its corporate systems. The fashion retailer is currently engaged in system restoration efforts following the breach, which occurred on May 24, according to a company statement. The decision to delay the earnings report highlights the […]

**Splunk Windows Flaw Lets Users Bypass Admin Controls**

A high-severity vulnerability in Splunk’s Universal Forwarder for Windows is exposing enterprise systems to unauthorized access by non-administrator users. Tracked as CVE-2025-20298 with a CVSS v3.1 score of 8.0, the flaw stems from incorrect permission settings applied during installation or upgrade processes. Affected versions include branches 9.4 (below 9.4.2), 9.3 (below 9.3.4), 9.2 (below 9.2.6), […]

Lee Enterprises Says Hack Exposed Data of 40,000

Lee Enterprises said a ransomware attack led to a data breach affecting approximately 40,000 individuals, following the completion of its internal investigation. The media company confirmed that unauthorized access to its systems resulted in the exposure of sensitive personal information, though it did not specify the exact nature of the compromised data. The breach was […]

Meta Removes China, Iran Fake News Networks

Meta Platforms Inc. has dismantled three covert influence operations tied to China, Iran and Romania that were using fake accounts to manipulate political discourse across multiple regions, according to *The Record*. The campaigns operated on Meta-owned platforms, including Facebook and Instagram, and were designed to spread propaganda and shape public opinion through coordinated inauthentic behavior. […]

GitLab Flaws Expose Millions to Account Takeover Risk

GitLab has issued emergency patches to fix ten security vulnerabilities affecting its Community Edition (CE) and Enterprise Edition (EE) platforms, some of which could allow complete account takeover. The flaws span versions 17.9 through 18.0 and include high-severity vulnerabilities with CVSS scores exceeding 8.0. The most critical, CVE-2025-4278, is an HTML injection flaw that impacts […]

Paraguay Data of 7.4 Million Leaked via Infostealer

A massive cybersecurity breach has exposed sensitive information tied to the Paraguay data of 7.4 million individuals, according to researchers who traced the leak to malware infections. The stolen data, now circulating on dark web forums, reportedly includes details about nearly the entire population of the South American country. Experts believe the breach began when […]