loader image
Google Chrome 142 Fixes 20 Flaws in Security Push

Google has released Chrome version 142 to the stable channel for Windows, Mac, and Linux, patching 20 security vulnerabilities that could impact millions of users. The Google Chrome 142 fixes arrive as part of an urgent update, addressing critical flaws and enhancing browser security across all desktop platforms. The update, identified as version 142.0.744, aims […]

Wordfence Alerts to WP Freeio Flaw Under Active Attack

The Wordfence Threat Intelligence team has issued an urgent advisory about active exploitation of a critical vulnerability in the WP Freeio plugin for WordPress. Tracked as CVE-2025-11533, the flaw carries a CVSS score of 9.8 and enables privilege escalation, allowing attackers to take over vulnerable sites. Wordfence alerts to WP Freeio users emphasize the severity […]

Jenkins Hit by Plugin Flaws, SAML Bypass Exposed

The Jenkins project on Thursday issued a critical security advisory revealing multiple vulnerabilities in its plugin ecosystem, including a serious authentication bypass affecting SAML-based logins. Jenkins hit by plugin flaws now faces heightened risks to server integrity and user confidentiality, with attackers potentially gaining unauthorized access through compromised modules. Among the identified issues is CVE-2025-64131, […]

CISA Warns of Active Hacks Targeting WSUS Flaw

The Cybersecurity and Infrastructure Security Agency (CISA) released updated threat detection guidance on October 29, 2025, addressing the actively exploited Windows Server Update Services (WSUS) vulnerability tracked as CVE-2025-59287. The alert comes after CISA warns of active hacks targeting this flaw, urging organizations to strengthen monitoring and apply mitigations immediately. The agency detailed new indicators […]

Microsoft Azure, 365 Outage Deepens Cloud Fears

A widespread Microsoft Azure 365 outage has disrupted services across multiple sectors, just days after a similar issue affected Amazon Web Services. The back-to-back incidents have intensified concerns about the public sector’s heavy dependence on a few dominant cloud platforms. With key systems increasingly hosted in the cloud, the impact of such disruptions can ripple […]

Clearview AI Sued in Europe Over Privacy Breaches

Clearview AI sued in Europe as the facial recognition firm faces renewed legal pressure over alleged violations of data privacy laws. The complaint, filed by the advocacy group noyb, accuses Clearview of ignoring previous bans and enforcement actions issued by European data protection authorities. These regulators had previously ruled that the company’s data collection practices […]

Hackers Combine Cache, FileFix in Stealthy Malware Push

Hackers combine cache FileFix techniques in a new phishing campaign that uses deceptive FortiClient pages and browser caching to bypass detection. Cybersecurity analysts found that attackers trick users into pasting commands into Windows Explorer’s address bar, exploiting a 2048-character entry limit to deliver larger payloads than possible in traditional ClickFix attacks. The campaign hides PowerShell […]

Dentsu Discloses Data Breach at Merkle Unit

Japanese advertising conglomerate Dentsu has confirmed a cybersecurity breach at its U.S.-based subsidiary Merkle, exposing sensitive information belonging to employees and clients. Dentsu discloses data breach details following an internal investigation that identified unauthorized access to company systems. The company has not confirmed the number of affected individuals or the nature of the compromised data. […]

HSBC USA Customer Data Leaked in Reported Hack

Cybercriminals have reportedly exposed a database containing sensitive HSBC USA customer data, according to a report by Cybernews. The leaked information allegedly includes full names, Social Security numbers, bank account details, and transaction histories. The breach raises concerns about the scope of data compromised and the potential for identity theft or financial fraud. The report […]

Everest Hackers Claim Breach at Sweden’s Power Grid

The Everest ransomware group has claimed responsibility for a cyberattack on Svenska kraftnät, Sweden’s state-owned power grid operator. In a statement posted to a leak site, Everest hackers claim breach of the utility’s internal systems and say they have exfiltrated approximately 280 gigabytes of sensitive corporate data. The alleged breach has triggered an investigation, according […]

Anivia Stealer Malware Bypasses UAC in Dark Web Sale

A new strain of credential-stealing malware named Anivia Stealer is being marketed across underground forums, according to researchers at KrakenLabs. Developed in C++17, the Anivia Stealer malware bypasses User Account Control (UAC) protections on Windows systems ranging from XP to Windows 11, allowing cybercriminals to execute privileged operations without alerting users. Threat actor ZeroTrace is […]