loader image
Python Turns Down $1.5 Million U.S. Grant Over Ethics

The Python Software Foundation has withdrawn a $1.5 million grant proposal to the U.S. National Science Foundation, citing ethical concerns over the funding terms. The decision, in which Python turns down 15 million in government support, centers on conditions that the foundation believes would compromise its principles on diversity, equity and inclusion. According to the […]

Windows 11 Update Adds Admin Cybersecurity Shield

Microsoft has started rolling out the KB5067036 preview cumulative update for Windows 11 versions 24H2 and 25H2, introducing new cybersecurity improvements. The Windows 11 Update Adds the Administrator Protection feature, which enhances system security by restricting access to high-risk administrative tools unless explicitly authorized. This release also includes a refreshed Start Menu design, aiming to […]

MikroTik Flaw Exposes Admin Logins Over Plain HTTP

A critical security vulnerability in MikroTik’s RouterOS and SwitchOS platforms, tracked as CVE-2025-61481, has been assigned a maximum CVSS score of 10.0. The MikroTik flaw exposes admin logins through the unencrypted HTTP version of the WebFig interface, enabling unauthenticated attackers to steal credentials and execute arbitrary code remotely. Devices running RouterOS version 7.14.2 and SwitchOS […]

Magento Flaw Lets Hackers Hijack Sessions, Run Code

Security researchers at Akamai have issued an urgent alert following the discovery of active attacks targeting a critical Magento flaw that lets hackers take over user sessions and execute remote code without authentication. Tracked as CVE-2025-54236 and dubbed “SessionReaper,” the vulnerability allows attackers to hijack sessions and gain high-level access to Magento-based online stores. Akamai’s […]

Wear OS Bug Lets Apps Send Texts Without Permission

A newly disclosed vulnerability in Google Messages for Wear OS allows unprivileged apps to send SMS and RCS messages without user permission, raising concerns over unauthorized communications. The flaw, tracked as CVE-2025-12080 and rated 6.9 under CVSS v4, was discovered by security researcher Gabriele Digregorio. A proof-of-concept exploit is already available, highlighting the ease with […]

Docker Compose Bug Lets Hackers Overwrite Any File

A newly disclosed Docker Compose bug lets hackers overwrite arbitrary files on affected systems by exploiting a high-severity path traversal flaw tracked as CVE-2025-62725. The vulnerability, which carries a CVSS v4 score of 8.9, impacts users of Docker Desktop, standalone Compose binaries, and Compose V2 integrations within the Docker CLI. Attackers can abuse the way […]

Tata Motors Leak Exposes 70TB via AWS Key Flaws

Tata Motors Leak Exposes more than 70 terabytes of customer and operational data due to critical flaws in the company’s cloud infrastructure. Security researcher Eaton Zveare found hardcoded AWS access keys embedded in Tata’s E-Dukaan platform, giving unrestricted access to cloud storage buckets containing sensitive customer records, market data, and financial documents. The exposed credentials […]

MPDV MES Flaw Exposes Files in Unauthenticated Access

A newly disclosed vulnerability in MPDV Mikrolab’s manufacturing execution systems could allow unauthenticated local file access, raising concerns across industrial network environments. The MPDV MES flaw exposes sensitive data in MIP 2, FEDRA 2, and HYDRA X platforms, potentially compromising operational integrity in automated production systems. SEC Consult identified the issue under CVE-2025-12055 and published […]

Phishing Emails Hide Malware Triggers in Subject Lines

Cybercriminals are using a new method to bypass email security systems by embedding invisible characters in subject lines through MIME encoding. These phishing emails hide malware and credential theft schemes by leveraging Unicode soft hyphens to split key terms undetectable to automated filters. The attack disguises malicious intent while maintaining a clean appearance in the […]

IBM Maximo Flaw Lets Hackers Bypass Cognos Controls

IBM has issued a critical advisory for a severe vulnerability in IBM Maximo Manage, part of the IBM Maximo Application Suite. Tracked as CVE-2025-36386 and rated 9.8 on the CVSS scale, the IBM Maximo flaw lets hackers gain unauthenticated access to Cognos Analytics. The company urges users to apply recommended remediation steps immediately to prevent […]

DELMIA Apriso Flaws Let Hackers Seize System Control

The Cybersecurity and Infrastructure Security Agency added two critical DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog on Oct. 29, warning that attackers are actively exploiting them. The vulnerabilities enable remote code execution and unauthorized privileged access, posing a severe threat to industrial and manufacturing systems using Dassault Systèmes’ DELMIA Apriso software. CISA’s alert […]

Australia Builds AI to Decode Criminal Emoji Chats

Australian authorities have developed an artificial intelligence tool designed to decipher the hidden meanings behind emoji used by criminals online. As part of a joint effort within the Five Eyes intelligence alliance, the new system highlights how Australia builds AI to decode messages that exploit digital symbols to target children. The Australian Federal Police (AFP) […]