loader image
China Hackers Target African Government IT Systems

A China-linked cyber espionage group known as APT41 has launched a targeted campaign against government IT infrastructure across Africa, according to researchers at Kaspersky. In this latest operation, China hackers target African systems using advanced techniques that suggest prior knowledge of internal networks. Analysts reported that malware deployed in the attack contained hardcoded service names, […]

CoinDCX Says $44 Million Stolen From Crypto Reserves

Indian cryptocurrency exchange CoinDCX says $44 million was stolen from its reserves in a security breach that did not impact customer funds. The company’s founders disclosed the incident, emphasizing that user assets remain safe and operational services continue without disruption. The breach targeted the exchange’s hot wallets, which hold a portion of its digital assets […]

ExpressVPN Bug Exposed User IPs in RDP Sessions

ExpressVPN has patched a critical vulnerability in its Windows application that allowed Remote Desktop Protocol (RDP) traffic to bypass the encrypted VPN tunnel. The ExpressVPN bug exposed user IP addresses during RDP sessions, undermining the core privacy protection the service is designed to provide. The flaw caused RDP traffic to route outside the VPN tunnel, […]

SharePoint Zero-Day Forces Urgent U.S. Gov Patch Order

A critical SharePoint Zero Day Forces immediate action from federal agencies after U.S. cybersecurity officials added the vulnerability to the government’s exploited vulnerabilities catalog. The flaw affects Microsoft SharePoint servers and has been linked to hundreds of known breaches, raising red flags about its impact across public and private systems. The Cybersecurity and Infrastructure Security […]

Veeam Update Locks Out Users After MFA Rollout

A recent Veeam update locks out users from accessing the Web UI of Recovery Orchestrator after enabling multi-factor authentication, the company warned on Friday. The issue affects the latest version of the product, which was released with enhanced security features, including MFA support. However, once MFA is activated, users are unable to log in through […]

Ukraine Blames Russia’s APT28 for AI LameHug Attacks

Ukraine has accused the Russian-backed hacker group APT28 of deploying a new strain of AI-enhanced malware, dubbed LameHug, to target its defense sector. The campaign, which Ukraine attributes to APT28, signals a sharp escalation in the use of artificial intelligence in cyber warfare. Ukraine blames Russia’s APT28 for orchestrating these attacks, which reportedly aim to […]

Malware Steals WhatsApp Data to Track Iran Dissidents

Researchers at cybersecurity firm Lookout have identified a new variant of DCHSpy, a malware strain that can now exfiltrate sensitive data from WhatsApp and device-stored files. The discovery came just one week after Israel launched airstrikes targeting Iran’s nuclear infrastructure. The malware steals WhatsApp data as part of a broader effort to monitor individuals perceived […]

Poland Probes Sabotage in Air Traffic Disruption

Flights at major Polish airports faced delays after a technical failure triggered temporary airspace restrictions, prompting an urgent investigation. Poland probes sabotage as authorities examine whether the disruption to air traffic control systems stemmed from intentional interference rather than a standard equipment malfunction. The incident halted departures and arrivals across several key transportation hubs, though […]

Europol Hits Kremlin-Backed NoName Gang in Crackdown

Europol hit a major milestone in its fight against state-linked cybercrime by dismantling NoName057(16), a pro-Kremlin hacking group accused of launching disruptive attacks across Europe. In a coordinated international operation, law enforcement agencies took down over 100 servers linked to the group, arrested two members, and issued seven additional arrest warrants. The action comes as […]

PoisonSeed Hack Bypasses FIDO Keys With QR Code Trick

A newly identified phishing campaign by the PoisonSeed group enables attackers to bypass Fast IDentity Online (FIDO) key protections by manipulating cross-device sign-in features. The PoisonSeed hack bypasses FIDO by tricking users into scanning malicious QR codes with their mobile multifactor authentication (MFA) applications, allowing adversaries to intercept login credentials and complete authentication flows without […]

Alaska Airlines Grounds Flights After IT Outage Hit

Alaska Airlines grounds flights across its network after an unspecified IT issue disrupted operations early Monday. The airline cited a technical failure that forced it to halt all departures temporarily, stranding passengers and delaying schedules at multiple airports. Officials have yet to confirm the source of the disruption or offer a timeline for resolution. Industry […]

7-Zip Flaw Lets Malicious RAR5 Files Crash Systems

A newly discovered 7 Zip flaw lets malicious RAR5 archive files crash systems by exploiting a memory corruption vulnerability in the file archiver’s RAR5 decoder. Tracked as CVE-2025-53816, the bug affects all 7-Zip versions before 25.00 and allows attackers to trigger denial-of-service conditions without executing arbitrary code. Security researchers found the flaw in the CDecoder […]