loader image
Kering Breach Exposes Millions of Luxury Shopper Records

Hackers breached systems at French luxury group Kering, stealing sensitive data from customers of Gucci, Balenciaga and Alexander McQueen. The Kering breach exposes millions of clients, with attackers exfiltrating names, phone numbers, email addresses, home addresses and purchase histories. Kering confirmed the incident and alerted data protection authorities, though it declined to specify the number […]

HybridPetya Revives Petya Tactics, Hits UEFI Systems

Security researchers have identified HybridPetya, a newly emerged ransomware strain that builds on the destructive legacy of Petya and NotPetya. HybridPetya revives Petya tactics by combining advanced boot-level attacks with firmware exploitation, targeting systems at their most vulnerable layers. First detected in September 2025, the malware has quickly drawn attention for its ability to compromise […]

NPM Malware Breach Hits ctrl/tinycolor, 40 Packages

A coordinated supply chain attack has compromised over 40 NPM packages, including the widely used @ctrl/tinycolor, which sees more than 2 million downloads weekly. This NPM Malware Breach Hits a critical point in the ecosystem, as attackers deployed a self-propagating worm to steal developer credentials and infect additional packages. The incident surfaced after suspicious GitHub […]

Zscaler Hit in 700-Firm SaaS Hack Targeting Salesforce

Cybersecurity firm Zscaler confirmed a data breach after attackers exploited compromised OAuth tokens linked to Salesloft Drift, a Salesforce-integrated marketing platform. The attack, part of a global supply-chain campaign believed to affect more than 700 organizations, resulted in Zscaler hit in SaaS through unauthorized access to its Salesforce environment. The company stated that its core […]

Qualcomm Modem Flaws CVE-2025-21483, 27034 Rated 9.8

Qualcomm has disclosed two critical vulnerabilities in its latest September 2025 Security Bulletin, highlighting severe issues in modem components used across mobile and automotive platforms. Identified as CVE-2025-21483 and CVE-2025-27034, both flaws carry a CVSS score of 9.8, indicating maximum severity. These Qualcomm modem flaws present significant security risks, potentially exposing affected devices to remote […]

Wireshark 4.4.9 Fixes Critical Bugs, Boosts Protocols

The Wireshark Foundation has released version 4.4.9 of its widely used network traffic analyzer, delivering a maintenance update that enhances stability and resolves several key issues. Wireshark 4.4.9 fixes critical bugs, including a vulnerability in the SSH dissector (wnpa-sec-2025-03) that previously caused unexpected crashes during secure shell traffic analysis. The release improves protocol support for […]

Hackers Threaten Google, Demand Firing of Two Staff

A hacker collective has reportedly demanded that Google terminate two employees or face the release of confidential company data. In a message posted on Telegram, a group calling itself “Scattered LapSus Hunters” threatened to leak the tech giant’s databases unless the company fires Austin Larsen and Charles Carmakal, both with Google’s Threat Intelligence Group. Hackers […]

Amazon Disrupts Russian Hackers Targeting Microsoft 365

Amazon has taken active measures to disrupt a cyber-espionage operation linked to Midnight Blizzard, a Russian state-backed hacking group also tracked as APT29. The campaign targeted Microsoft 365 accounts in an attempt to steal sensitive information, according to cybersecurity researchers. As part of the intervention, Amazon disrupts Russian hackers by neutralizing infrastructure used to impersonate […]

eSIM Emerges as Key Defense as SIM Swaps Soar 1,055%

SIM swapping attacks are surging globally, with the U.K. reporting a 1,055% increase in 2024. Criminals exploit mobile carriers to hijack phone numbers, using stolen data to bypass identity checks. These attacks enable access to bank accounts, crypto wallets, and email services. In response, eSIM emerges as key defense, offering built-in hardware security that limits […]

Microsoft Pressures OEMs to Fix USB-C Warnings in Windows 11

Microsoft is urging original equipment manufacturers to correct hardware configurations that block USB-C troubleshooting alerts in Windows 11. The company’s guidance comes as part of a broader push—Microsoft pressures OEMs to fix recurring issues that prevent users from receiving vital notifications about slow charging, unsupported accessories, and faulty connections. Although Windows 11 supports these alerts […]

Microsoft to Enforce MFA for Azure Admin Access

Microsoft will enforce MFA for all user accounts accessing the Azure portal and related admin centers, beginning in October 2024. The phased rollout, announced on August 26, 2025, aims to curb credential-based attacks by requiring multifactor authentication for key administrative functions across Microsoft Entra, Intune, and Microsoft 365 portals. In the second phase, starting October […]

Hackers Mimic Hotel Software in Ad Scam to Steal Logins

A targeted phishing campaign launched in August 2025 is exploiting malicious search engine ads to breach hotel management systems. Hackers mimic hotel software by typosquatting well-known platforms like SiteMinder and RoomRaccoon. These fake ads appear above legitimate search results, tricking hoteliers and vacation rental operators into clicking fraudulent links. Once clicked, users land on cloned […]