loader image
CrowdStrike Falcon Blocks Git Exploit in Active Attack

CrowdStrike has detected active exploitation of the Git vulnerability identified as CVE-2025-48384. The company reported that its security platform, CrowdStrike Falcon, blocks Git-based attacks by stopping threat actors who use deceptive social engineering techniques alongside compromised repositories. This campaign targets developers by luring them into cloning malicious Git projects, which then trigger the exploit. According […]

Cavalry Werewolf Hackers Target Energy, Mining Sectors

A newly uncovered cyber-espionage campaign tied to the Cavalry Werewolf hackers targets Russia’s public sector and critical industries, exploiting trusted government communications. Active from May through August 2025, the group—also known as YoroTrooper and Silent Lynx—used spear-phishing emails posing as Kyrgyz government agencies to deliver malware. These phishing messages distribute FoalShell and StallionRAT through RAR […]

TP-Link Patches Critical Flaw in Omada Gateways

TP-Link has issued firmware updates to fix four security vulnerabilities affecting its Omada gateway devices, including a critical pre-authentication operating system command injection flaw. The company acted swiftly as the TP-Link patches critical flaw aim to prevent attackers from executing arbitrary commands on impacted devices without user authentication. The vulnerabilities affect a wide range of […]

WatchGuard Firewalls Expose 70,000 Devices to Hackers

More than 70,000 WatchGuard Firebox devices remain exposed online, according to security researchers who warn of a critical remote code execution (RCE) vulnerability. The flaw could allow attackers to seize full control of affected WatchGuard firewalls, exposing devices to unauthorized access and potential network compromise. The discovery highlights the ongoing risk for organizations that have […]

Tykit Phishing Kit Targets Microsoft 365 Credentials

Cybersecurity researchers have identified a phishing-as-a-service toolkit known as the Tykit phishing kit targeting Microsoft 365 credentials. The kit uses a distinct approach by embedding a scalable vector graphics (SVG) image to redirect victims to spoofed login pages, increasing the likelihood of deception. Investigators believe this technique helps attackers bypass standard email security filters, allowing […]

Vidar Stealer 2.0 Upgrades With Faster Data Theft

The developers behind Vidar Stealer, a prominent malware-as-a-service platform, have launched a major update that significantly enhances its capabilities. The Vidar Stealer 2.0 upgrades introduce multi-threaded data theft, allowing the malware to exfiltrate information more efficiently from infected systems. Security analysts say this version marks a notable leap in both performance and stealth. In addition […]

WSO2 Patches Critical Flaws in API, Identity Tools

WSO2 has issued critical security advisories to address two severe access control vulnerabilities—CVE-2025-9804 and CVE-2025-10611—impacting its API Manager and Identity Server products. The company moved quickly after identifying the flaws, which could allow unauthorized access to sensitive enterprise systems. These WSO2 patches for critical flaws aim to prevent potential exploitation in production environments. The vulnerabilities […]

Bitter APT Hits China, Pakistan With WinRAR Zero-Day

China-based cybersecurity firm Qianxin Threat Intelligence Center has identified a new cyber campaign targeting Chinese and Pakistani entities. The attackers, linked to the Bitter APT Hits China group (APT-Q-37), used a zero-day vulnerability in WinRAR along with malicious Microsoft Office macros to deploy a custom C# backdoor. The tools allowed the threat actor to gain […]

ABB Flaw Lets Hackers Seize Control of Load Devices

ABB has confirmed a critical security flaw in its ALS-mini-S4 and S8 IP intelligent load controllers, exposing energy infrastructure to serious risk. Tracked as CVE-2025-9574 and rated 9.9 on the CVSS scale, the vulnerability stems from missing authentication, allowing remote attackers to gain admin-level access without credentials. The ABB flaw lets hackers fully control these […]

Sauter AG Flaw Lets Hackers Upload Files Without Login

Swiss building automation firm Sauter AG has identified six security vulnerabilities in the firmware of its modulo 6 devices, including a critical flaw rated 9.8 on the CVSS scale. The most severe vulnerability, tracked as CVE-2025-41723, allows unauthenticated attackers to upload files remotely via the system’s SOAP interface. The Sauter AG flaw letsnaturally threat actors […]

Google Chrome Patch Fixes V8 Flaw Under Active Attack

Google has issued an urgent Stable Channel update for Chrome on Windows, Mac, and Linux platforms, addressing a high-severity vulnerability in its V8 JavaScript engine. The flaw, tracked as CVE-2025-12036, could allow attackers to exploit memory-related weaknesses in the engine. The latest Google Chrome patch fixes this critical issue in version 141.0.7390.122/.123, and users are […]

OpenAI Challenges Google With ChatGPT Atlas Browser

OpenAI has intensified competition in the AI browser sector with the launch of ChatGPT Atlas, an AI-powered web browser designed to reshape how users interact online. OpenAI challenges Google’s dominance by integrating its advanced conversational AI directly into the browsing experience, signaling a strategic shift toward intelligent, adaptive web tools. The browser war is escalating […]