loader image
HPE Flaw Exposes Admin Access via Hard-Coded Logins

Hewlett-Packard Enterprise has issued a security update to patch a critical vulnerability in its Instant On Access Points. The HPE flaw exposes admin access by allowing attackers to bypass authentication using hard-coded credentials embedded in the system. Tracked as CVE-2025-37103, the flaw carries a near-maximum CVSS severity rating of 9.8, signaling a significant risk to […]

3,500 Websites Hijacked in Stealth Crypto Mining Attack

A new wave of browser-based cryptojacking has emerged, with attackers compromising 3,500 websites hijacked to secretly mine cryptocurrency. Researchers from c/side uncovered the campaign, which uses stealthy JavaScript code and WebSocket connections to siphon computing power from unsuspecting visitors. The findings highlight a resurgence of tactics once used by now-defunct services like CoinHive, which faded […]

EncryptHub Lures Web3 Devs With Fake AI to Steal Data

The financially motivated threat group EncryptHub, also known as LARVA-208 or Water Gamayun, has launched a new campaign aimed at Web3 developers. In this latest operation, EncryptHub lures Web3 devs by posing as representatives of fake artificial intelligence platforms such as Norlax AI, a clone of the legitimate Teampilot service. The attackers contact potential victims […]

SquidLoader Malware Targets Hong Kong Financial Firms

A new wave of cyberattacks using SquidLoader malware targets Hong Kong financial firms, according to cybersecurity researchers. The campaign appears to focus on compromising sensitive systems within the financial sector, raising concerns about growing threats to regional economic infrastructure. Analysts observed that the malware uses sophisticated delivery methods to evade detection and gain access to […]

CISA Flags Fortinet Flaw as Hackers Target Firewalls

The U.S. Cybersecurity and Infrastructure Security Agency added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities catalog, warning of widespread exploitation. CISA Flags Fortinet Flaw CVE-2025-25257, a SQL injection bug rated 9.6 out of 10 on the CVSS scale, which allows unauthenticated attackers to execute malicious SQL commands via crafted HTTP or HTTPS […]

Google Sues 25 in Botnet Case Over Ad Fraud, Damage

Google filed a lawsuit against 25 unnamed individuals it accuses of operating the BadBox 2.0 botnet, a malicious network that allegedly harmed the company’s reputation and financial interests. The tech giant claims the defendants used the botnet to distribute malware through compromised Android devices, misleading users and advertisers. The case, filed in the U.S., underscores […]

Citrix Denied Attacks as Hackers Hit Weeks Earlier

A critical vulnerability in Citrix NetScaler, identified as CVE-2025-5777 and known as CitrixBleed 2, was exploited nearly two weeks before public proof-of-concept (PoC) exploits emerged. During that period, Citrix denied attacks were taking place, stating there was no evidence of active exploitation. Security researchers later confirmed that threat actors had already launched attacks targeting this […]

QR Code Phishing Bypasses FIDO Keys in New Attack

A new phishing campaign is exploiting QR codes to sidestep FIDO security keys, raising concerns about cross-device authentication methods. The method, identified as a man-in-the-middle attack, uses a deceptive login page to intercept sign-in attempts. This approach, where QR Code Phishing Bypasses traditional authentication layers, targets users who rely on QR-based login flows between devices. […]

TeleMessage SGNL Flaw Hit as Hackers Exploit Bug

Cybercriminals are actively exploiting a newly discovered vulnerability in the TeleMessage SGNL platform, raising concerns across the enterprise communications landscape. The TeleMessage SGNL flaw hit naturally during a surge in targeted cyberattacks, with threat actors leveraging it to bypass security protocols and gain unauthorized access to sensitive messaging data. The flaw resides in the platform’s […]

Microsoft Teams Calls Used to Spread Matanbuchus Malware

Cybercriminals are exploiting Microsoft Teams calls malware tactics to distribute the Matanbuchus malware loader, using voice calls that mimic IT helpdesk support. Attackers initiate contact through Teams, posing as legitimate internal staff. Once the user engages, they share malicious files or links designed to deploy the malware onto the victim’s system. Security researchers have linked […]

United Natural Foods Hit by Cyberattack, Loses $400M

United Natural Foods hitnaturally a major disruption last month after a cyberattack forced the company to shut down all its systems. The food distributor and wholesaler reported that the incident led to a loss of up to $400 million in sales. Despite the severity of the breach, the company managed to restore its core systems […]

Google Sues to Kill Botnet Infecting 10 Million Devices

Google has filed a lawsuit targeting the operators behind BadBox 2.0, an Android-based botnet that has infected over 10 million devices globally. The legal action, in which Google sues to kill botnet operations, accuses the unnamed defendants of orchestrating a large-scale ad fraud scheme that exploited the company’s advertising ecosystem. The malware, embedded in modified […]