loader image
React Router Flaw Exposes Server Files

Security researchers have discovered a critical React Router flaw that enables attackers to perform directory traversal, gaining unauthorized access to server filesystem locations. The vulnerability, tracked as CVE-2025-61686, affects several packages within the React Router ecosystem. Exploiting the flaw allows malicious users to read, write or even overwrite sensitive server files outside of expected application […]

Sweden Detains IT Consultant Over Russia Spy Claim

Sweden detains an IT consultant who formerly worked with the Swedish Armed Forces, as authorities suspect him of spying for Russian intelligence. The 33-year-old man was taken into custody earlier this week, prosecutors announced. Officials believe he accessed sensitive information during his time working as a consultant and may have passed it to a foreign […]

Amsterdam Court Jails Hacker in Port Cocaine Plot

The Amsterdam Court of Appeal on Friday ruled that a hacker who manipulated European port systems to enable cocaine smuggling played a key technical role in a criminal trafficking operation. In a decision that underscores the growing intersection of cybercrime and organized drug trade, the Amsterdam court jailed the hacker for seven years, linking him […]

Ofcom Probes X Over Nonconsensual Deepfakes

British communications regulator Ofcom has launched an inquiry into social media platform X, formerly known as Twitter, over alleged failures to curb the spread of nonconsensual deepfake pornography involving both adults and minors. The move comes as Ofcom probes X under its new online safety powers, marking one of the first high-profile cases to test […]

Nissan Says 900GB Stolen in Everest Hack

The hacker group Everest Ransomware has claimed responsibility for a cybersecurity breach at Nissan, alleging that it stole 900GB of sensitive corporate data. The cybercriminals posted evidence of the intrusion on their leak site, showcasing documents they say belong to the Tokyo-headquartered automaker. Among the files are marketing materials, vehicle client data, legal documents and […]

Gmail Adds AI Inbox; Google Won’t Train on Emails

Google is introducing a major update to its email platform as Gmail adds a new AI inbox powered by its Gemini large language model. The feature automatically summarizes email threads, helping users quickly understand the content without opening each message individually. Despite the increased integration of artificial intelligence, the company emphasized that it will not […]

China-Linked Hackers Breach Telco Edge Devices

A threat group believed to operate from China has expanded its cyber operations, now targeting telecom firms in Southeastern Europe using edge device vulnerabilities. Security researchers say the china-linked hackers breach telco infrastructure by deploying custom Linux-based malware designed to exploit poorly secured internet-facing systems. This group reportedly shifted tactics, focusing on edge devices to […]

ValleyRAT_S2 Hijacks Firms to Steal Financial Data

A new malware campaign using a variant of the ValleyRAT family is raising alarms across cybersecurity circles as ValleyRAT_S2 hijacks firms through deceptive productivity tools and trojanized installers disguised as AI spreadsheet software. Delivered via spearphishing, modified software updaters, and DLL side-loading, ValleyRAT_S2 functions as a powerful C++-based remote access trojan. Once installed, it provides […]

FBI Warns North Korean Hackers Using QR Codes

The FBI warns QR codes are being weaponized by North Korean hackers in a new wave of spear-phishing campaigns targeting U.S.-based organizations. In an advisory issued Thursday, federal investigators said state-sponsored actors tied to North Korea have begun embedding malicious QR codes into phishing emails aimed at compromising systems at think tanks, academic institutions, and […]

ICO Warns on Poor Agentic AI in Public Sector

The Information Commissioner’s Office (ICO) warns that poorly developed agentic AI applications in government could result in flawed decision-making and reduced public trust. The regulator raised concerns about the use of automated systems that act independently, especially without clear oversight or accountability in the public sector. In response, the ICO plans to open a consultation […]

UK Overhauls Cyber Plan, Creates Cyber Unit

The UK overhauls its cyber plan as part of a £210 million investment aimed at protecting public services from growing digital threats. As part of the initiative, authorities introduced a new Government Cyber Unit to improve coordination, bolster cyber resilience, and respond rapidly to incidents affecting critical infrastructure. The revamped Cyber Action Plan emphasizes enhanced […]

Asseco InfoMedica Plus Hit by Two Flaws

Poland’s national cybersecurity team, CERT Polska, has disclosed two newly identified vulnerabilities affecting the Asseco InfoMedica Plus software. The issues, tracked as CVE-2025-8306 and CVE-2025-8307, emerged following an external report that prompted further analysis by the agency. Both vulnerabilities could pose a risk to users of the healthcare-focused application, though details surrounding their technical implications […]