loader image
CISA Warns Veeder-Root Flaw Exposes Fuel Tank Systems

The Cybersecurity and Infrastructure Security Agency issued a critical security alert on Monday, warning that Veeder-Root TLS4B Automatic Tank Gauge systems are vulnerable to remote command injection. The alert highlights two high-severity flaws, including CVE-2025-58428, which if exploited, could allow attackers to execute arbitrary commands. CISA warns Veeder Root flaw poses a significant risk to […]

UN Cybercrime Pact Draws Support, Sparks Rights Fears

Dozens of countries have signed a new international treaty aimed at combating cybercrime, raising fresh concerns among digital rights advocates. The UN Cybercrime Pact draws attention for its provisions that enable expanded surveillance and facilitate cross-border data sharing, moves critics say could erode civil liberties. Supporters argue the agreement strengthens global cooperation against online threats. […]

Telegram Hijacked With Android Malware for Full Control

Cybercriminals are distributing a sophisticated Android backdoor, identified as Android.Backdoor.Baohuo.1.origin, through tampered versions of the Telegram X messenger. This malware, which has effectively left Telegram hijacked with Android malware, provides attackers with full control over user accounts while remaining hidden from victims. It spreads mainly via fake dating and communication apps promoted through deceptive ads […]

LockBit 5.0 Strikes Windows, Linux, ESXi Systems

The LockBit ransomware gang has reemerged with LockBit 5.0, a revamped variant that actively targets Windows, Linux, and ESXi platforms. After months of silence following law enforcement’s Operation Cronos, the group’s administrator rebuilt its infrastructure and resumed attacks. LockBit 5.0 strikes Windows systems in particular, with 80% of infections affecting that platform during a wave […]

Microsoft Patches 172 Flaws, 3 Zero-Days in October

Microsoft’s October 2025 Patch Tuesday rolled out fixes for 172 security flaws, the largest monthly total so far this year. Among those addressed, eight were rated critical, three were zero-day vulnerabilities actively exploited in the wild, and two had been publicly disclosed prior to the update. The company’s response underscores the growing priority on mitigating […]

CrowdStrike Blocks Active Git Exploit in Falcon Defense

CrowdStrike blocks active Git vulnerability CVE-2025-48384 following the detection of targeted exploitation efforts. Threat actors used advanced social engineering techniques to lure developers into cloning malicious Git repositories. Once cloned, these repositories triggered the vulnerability, potentially compromising developer systems. CrowdStrike’s Falcon platform identified and blocked the attack chain in real time, preventing further impact. The […]

Safepay Hacks Xortec, Threatens Security Supply Chain

The Safepay ransomware group has claimed responsibility for breaching Xortec GmbH, a German provider of professional video surveillance and security solutions. As part of the attack, the group listed the company on its data leak site and set a ransom deadline for October 27, 2025. The incident, titled “Safepay Hacks Xortec,” could pose significant risks […]

NTLM Flaw Lets Hackers Jump From User to System Access

A newly uncovered NTLM flaw lets hackers escalate privileges on systems running LDAP or LDAPS services, according to a report published Oct. 26, 2025. Tracked as CVE-2025-54918, the vulnerability impacts domain controllers and allows attackers to move from a standard domain user role to full SYSTEM-level access. The security flaw emerged in September 2025 and […]

HashiCorp Vault Flaws Expose AWS Auth, Trigger DoS Risk

HashiCorp has released critical patches for two high-severity vulnerabilities affecting its Vault identity-based security platform. The newly disclosed HashiCorp Vault flaws expose deployments to risks including unauthorized AWS authentication bypasses and denial-of-service attacks via unauthenticated JSON payloads. The company is urging users to apply updates immediately to mitigate potential threats. The flaws are tracked under […]

WatchGuard Flaw Exposes 70,000 Firewalls to Hackers

More than 70,000 WatchGuard Firebox firewall devices remain exposed online due to a critical vulnerability that enables remote code execution. The WatchGuard flaw exposes firewalls to full takeover by attackers if exploited, posing a significant risk to organizations relying on these systems for network protection. Security researchers discovered the flaw, which allows unauthorized access and […]

Dell Storage Flaw Lets Hackers Bypass APIs Remotely

Dell Technologies has disclosed a critical security vulnerability in its Storage Manager software, warning that the Dell Storage Flaw lets hackers bypass authentication via exposed APIs. The flaw, tracked as CVE-2025-43995 and rated 9.8 on the CVSS scale, affects Storage Center and Dell Storage Manager (DSM) platforms. If exploited, attackers could remotely gain unauthorized access […]

CoPhish Breach Uses Microsoft Copilot to Steal Tokens

A new phishing campaign, dubbed CoPhish, exploits Microsoft Copilot Studio to steal OAuth tokens by mimicking legitimate Microsoft services. The CoPhish breach uses Microsoft Copilot’s customizable AI agents hosted on trusted domains to disguise malicious OAuth consent attacks, increasing the likelihood that users will approve harmful app permissions. According to Datadog Security Labs, attackers build […]