loader image
Microsoft Zero-Day in SharePoint Triggers Global Attacks

Microsoft has issued emergency security updates and detection tools following active exploitation of a Microsoft Zero-Day in SharePoint. Attackers are targeting two vulnerabilities, CVE-2025-53770 and CVE-2025-53771, affecting on-premises SharePoint servers worldwide. Since July 18, threat actors have compromised dozens of organizations, including U.S. federal agencies, universities, and energy firms. The Microsoft Zero-Day in SharePoint enables […]

NICE Backs AI Tools to Spot Spinal Fractures Early

The National Institute for Health and Care Excellence (NICE) has issued draft guidance supporting the conditional use of four artificial intelligence technologies to help diagnose spinal fractures. In this early-stage recommendation, NICE backs AI tools that assist healthcare professionals by analyzing CT scans for vertebral compression fractures. The guidance allows the provisional deployment of these […]

DeerStealer Malware Hides in LNK File Using LOLBins

A recent phishing campaign has emerged, delivering the DeerStealer malware through weaponized shortcut files that exploit trusted Windows utilities. Disguised as a PDF titled “Report.lnk,” the file initiates a multi-stage infection chain using legitimate binaries in a technique known as Living off the Land. This tactic enables attackers to bypass traditional defenses, allowing DeerStealer malware […]

npm Maintainers Hit as Hackers Inject Code in Popular Packages

Threat actors launched a targeted phishing campaign that compromised multiple popular npm packages, aiming to steal authentication tokens from project maintainers. The attackers lured victims through a typosquatted domain, npnjs.com, which mimicked the official npmjs.org site. This supply chain attack saw npm maintainers hit as hackers used stolen credentials to publish malicious packages directly to […]

WordPress Sites Hijacked by Google Tag Spam Scripts

A new spam campaign targeting WordPress sites hijacked by a malicious script embedded in Google Tag Manager is redirecting users to fraudulent destinations. The attack operates without deploying traditional malware, relying instead on a fileless method that executes a hidden script within the browser. This tactic allows attackers to bypass endpoint defenses and redirect unsuspecting […]

Intel Shuts Clear Linux OS After Decade of Development

Intel has officially ended development of its Clear Linux operating system, closing the chapter on a decade-long open-source project. Intel shuts Clear Linux as part of a broader shift in focus, archiving the project’s GitHub repositories and ceasing all future updates. The OS, known for its optimization on Intel hardware, will no longer receive support. […]

CrushFTP Warns of Zero-Day Hack Hitting File Servers

CrushFTP warns of a zero-day vulnerability actively exploited by hackers in the wild, prompting immediate concern among users of the widely used file transfer software. The company identified the flaw after detecting unusual activity targeting its systems. It has not disclosed the technical details of the vulnerability but confirmed that attackers are using it to […]

Ring Blames Bug for Surge in Suspicious Logins

Ring has denied experiencing a security breach after users reported suspicious login activity on May 28. The Amazon-owned company stated that a recent backend update triggered the issue, which led customers to see unfamiliar devices listed under their accounts. Ring blames bug-related disruptions in the software update process for the confusion. Multiple users flagged unusual […]

Trump Bill Sends $1 Billion to AI, Quantum, Cyber Wars

Congress has dropped plans for a federal artificial intelligence mandate, but the Trump bill sends $1 billion into emerging technologies, opening the door to major defense investments. The funding package prioritizes military applications of AI, quantum computing, and advanced cryptography, signaling a strategic push to outpace global rivals in next-generation digital warfare. While regulatory oversight […]

NailaoLocker Uses China’s SM2 Crypto in Rare Attack

A newly identified ransomware strain, NailaoLocker, is targeting Windows systems using China’s SM2 cryptographic standard in a rare deviation from typical ransomware encryption methods. FortiGuard Labs researchers say NailaoLocker uses China’s SM2 cryptography to encrypt AES-256-CBC keys, marking the first known case of this method in ransomware campaigns. The malware’s name, drawn from the Chinese […]

Dell Hit by Breach as 1.3 Terabytes of Data Leaked

A hacking group calling itself World Leaks claims to have compromised Dell Technologies, alleging it exfiltrated 1.3 terabytes of sensitive data. The group shared a screenshot of the leaked files in an online post, stoking concerns across the cybersecurity community. Dell hit by breach headlines have circulated rapidly, though the company has not yet confirmed […]

Iran Spyware Poses as VPN to Target Dissidents

Cybersecurity researchers have identified a new strain of Android spyware linked to Iran’s Ministry of Intelligence and Security. The malicious tool, which poses as VPN services and Starlink internet apps, has targeted users with the intent to monitor dissidents. Iran spyware poses as VPN platforms to lure victims into downloading applications that secretly collect sensitive […]