loader image
Hackers Seize WordPress Sites via Theme File Flaw

Hackers are actively exploiting a critical vulnerability in the popular WordPress theme “Alone – Charity Multipurpose Non-profit” to gain control of websites. The flaw, identified as CVE-2025-5394, holds a severity rating of 9.8 on the CVSS scale. Threat actors are using it to upload arbitrary files, allowing them to install unauthorized plugins and seize full […]

FunkSec Ransomware Defeated as Decryptor Released

Cybersecurity researchers at Avast have released a free decryptor for the FunkSec ransomware, allowing victims to recover encrypted files without paying a ransom. Gen Digital confirmed the tool’s release after collaboration with law enforcement, marking a turning point in the fight against the malware strain. With the FunkSec ransomware defeated, the team determined the threat […]

Base44 Hack Exposes Private Apps in Wix AI Platform

A critical security flaw in Base44, the AI-powered vibe coding platform recently acquired by Wix, exposed private enterprise applications to unauthorized access. The Base44 hack exposes private app access by allowing attackers to exploit a logic flaw using publicly available app IDs, bypassing authentication even for apps protected by Single Sign-On. Wiz Research identified the […]

Qilin Ransomware Gains Edge With On-Demand Legal Help

The Qilin ransomware gang has introduced a new legal support service for its affiliates, marking a troubling shift in cybercrime tactics. The move, first revealed on a Russian-language darknet forum in June 2025, shows how Qilin Ransomware Gains Edge by combining technical extortion with legal intimidation. This strategy targets victims’ fears of regulatory penalties and […]

Cybercrime Stokes Thai-Cambodian Border Tensions

Rising tensions between Thailand and Cambodia have taken a digital turn, as cybercrime stokes Thai-Cambodian conflict beyond traditional political and territorial disputes. A surge in online scams, allegedly orchestrated from within Cambodia’s borders, has drawn sharp criticism from Thai authorities, who link the cybercriminal activity to broader regional instability. Investigations reveal that call centers and […]

Qwins Ltd Linked to Malware Surge via Cheap Hosting

A UK-registered company, Qwins Ltd, has emerged as a major enabler of cybercrime, according to cybersecurity researchers who linked its infrastructure to global malware campaigns. Operating under ASN 213702, Qwins Ltd has provided bulletproof hosting services that support malware families like Lumma Stealer, Amadey, and Mirai variants. Researchers observed its servers distributing over 120 malware […]

0bj3ctivityStealer Hides Payload in Images, Hits Firms

A newly uncovered information-stealing malware known as 0bj3ctivityStealer has drawn attention for its advanced exfiltration tactics and layered execution chain. First identified by HP Wolf Security researchers, the malware hides payload using obfuscated JavaScript and steganographic methods to bypass traditional detection systems. Its attack begins with phishing emails disguised as purchase order requests, luring users […]

Apple Releases Urgent MacOS, Safari Security Updates

Apple has rolled out security-focused updates for Mac users running macOS Sonoma and macOS Ventura, delivering macOS Sonoma 14.7.7 and macOS Ventura 13.7.7. The company labeled these releases as critical, addressing undisclosed security vulnerabilities. Apple releases urgent macOS patches periodically to maintain robust system protection and improve user safety. Alongside the macOS updates, Apple also […]

Dollar Tree Denies Hack, Blames Old Chain for Data Leak

Dollar Tree denied reports of a ransomware attack this week after a cybercriminal group claimed it had breached the discount retailer’s systems. Dollar Tree denies hack allegations, asserting that the data in question originated from a separate entity no longer in operation. The company clarified that the alleged stolen data came from a defunct discount […]

Hackers Lure Python Devs With Fake PyPI Login Site

Hackers lure Python devs into phishing traps by deploying a counterfeit version of the Python Package Index (PyPI) website, according to a warning issued this week by the Python Software Foundation. The attackers aim to steal user credentials by mimicking the official PyPI platform, a repository widely used by developers to share and install packages. […]

XWorm V6 Malware Evades Detection, Hits Windows Users

A newly discovered XWorm V6 malware variant has surfaced in active attacks against Windows users, showcasing advanced anti-analysis features and memory-only execution. Security researchers at Netskope uncovered the strain following a year-long investigation into XWorm’s development. The XWorm V6 malware evades detection through obfuscated VBScript droppers and runtime payload reconstruction via reversed character arrays. The […]

Ingram Micro Hit as Safepay Threatens Data Leak

The SafePay ransomware group has claimed responsibility for a cyberattack that compromised systems at global IT distributor Ingram Micro, threatening to leak 3.5 terabytes of stolen data. According to the threat actors, the breach occurred earlier this month, and the stolen files allegedly include internal documents, client records, and business communications. Ingram Micro hit SafePay’s […]