loader image
Microsoft WSUS Exploits Hit Multiple Firms, Google Says

Google has issued a warning that attackers are actively exploiting Microsoft WSUS vulnerabilities to compromise multiple organizations. The tech giant’s threat intelligence team observed a wave of intrusions targeting Windows Server Update Services, a tool used to manage and distribute Microsoft software updates across enterprise environments. Threat actors appear to be leveraging flaws in the […]

Apache Tomcat Fixes Flaws Risking RCE, Console Attacks

The Apache Software Foundation has released security patches for Apache Tomcat to address three newly discovered vulnerabilities, including CVE-2025-55752, which could allow attackers to bypass URL rewriting mechanisms. The flaw may expose systems to remote code execution and console ANSI injection. The Apache Tomcat fixes flaws that could compromise the integrity of applications relying on […]

SideWinder APT Hits Diplomats With StealerBot Attack

The SideWinder APT group has launched a new cyber espionage campaign targeting South Asian diplomatic missions, according to researchers at Trellix Advanced Research Center. Using a revamped infection chain that begins with malicious PDF files and progresses through ClickOnce deployments, the attackers deliver a custom malware dubbed StealerBot. In this latest operation, SideWinder APT hits […]

Kaspersky Unmasks Chrome Zero-Day Used for Spyware

Kaspersky researchers have uncovered a sophisticated cyberespionage operation leveraging a critical zero-day vulnerability in Google Chrome, tracked as CVE-2025-2783. In a report published Tuesday, Kaspersky unmasks the Chrome zero-day as a remote code execution flaw exploited in a targeted campaign dubbed “ForumTroll.” The attackers delivered commercial spyware linked to the Italian firm Memento Labs through […]

Apache Tomcat Flaws Expose Servers to Code Attacks

Apache Tomcat flaws expose servers to serious security risks, following the disclosure of multiple critical vulnerabilities by the Apache Software Foundation. The open-source Java servlet container, widely deployed to support web applications, contains weaknesses that could allow attackers to execute arbitrary code remotely. Apache published the details on October 27, 2025, underscoring the urgency for […]

OpenVPN Flaw Lets DNS Hack Linux, macOS Devices

Security researchers have identified a high-severity vulnerability in OpenVPN, tracked as CVE-2025-10680, that affects versions 2.7_alpha1 through 2.7_beta1. The OpenVPN flaw lets DNS servers controlled by attackers inject malicious scripts into Linux and macOS systems. If exploited, the flaw could allow unauthorized code execution during VPN connection setup. The vulnerability carries a CVSS score of […]

Python Foundation Rejects $1.5M Grant Over DEI Clash

The Python Foundation rejected a $1.5 million grant from the U.S. National Science Foundation after discovering an anti-DEI clause in the agreement. The proposal, submitted in January 2025, focused on enhancing open-source security through the NSF’s Open Source Ecosystem Security, Safety, and Privacy initiative. The clause conflicted with the Foundation’s commitment to diversity, equity and […]

SideWinder Hacks Diplomats Using ClickOnce Attack Chain

A threat actor known as SideWinder has launched a new cyber campaign targeting diplomatic entities across South Asia, including a European embassy in New Delhi. The operation, which began in September 2025, demonstrates how SideWinder hacks diplomats using a more advanced attack chain. Researchers say the group now leverages malicious PDF files in combination with […]

Microsoft Teams to Auto-Track Workers via Wi-Fi

Microsoft plans to roll out a new feature in its Teams platform this December that will allow the software to auto track user office locations via Wi-Fi. The update, listed in the company’s latest roadmap, aims to streamline workplace coordination by identifying whether employees are working on-site or remotely. The feature will use a device’s […]

QNAP NAS Backup Hit by Critical .NET Credential Flaw

A critical vulnerability in Microsoft’s ASP.NET framework, tracked as CVE-2025-55315, is now actively affecting QNAP NAS Backup utility users, exposing them to credential theft. Microsoft addressed the flaw with a recent security update, rating it 9.8 on the CVSS scale. Although initially thought to have limited impact, security researchers have since confirmed exploitation in real-world […]

Clearview AI Faces Criminal Complaint Over Photo Scraping

Clearview AI faces a criminal complaint after allegedly collecting billions of photos from the internet without user consent and marketing its facial recognition technology to law enforcement and government entities. The company’s data scraping practices have sparked widespread criticism from privacy advocates across Europe, who argue that Clearview’s actions violate fundamental rights. The complaint, filed […]

CISA Warns CVSS 10.0 Bug Exposes AutomationDirect PLCs

The U.S. Cybersecurity and Infrastructure Security Agency issued an emergency alert on Oct. 26, warning of a critical remote code execution flaw with a CVSS score of 10.0 in AutomationDirect’s Productivity programmable logic controllers. CISA warns CVSS 10 vulnerabilities could allow unauthenticated attackers to take full control of impacted systems, posing significant risks to industrial […]