loader image
Tomcat Flaw Lets Hackers Crash Sites With HTTP/2 Flood

A newly disclosed vulnerability in Apache Tomcat’s Coyote engine, tracked as CVE-2025-53506, exposes servers to denial-of-service attacks via HTTP/2 traffic. The Tomcat flaw lets hackers exploit a loophole where the server fails to cap concurrent streams when a client ignores the SETTINGS frame. Attackers can then flood the server with persistent streams, overwhelming its thread […]

AsyncRAT Spawns 30 Malware Variants in Global Surge

Security researchers at ESET have uncovered a widespread malware campaign involving AsyncRAT, a remote access trojan that has seeded more than 30 variants over the past year. The analysts observed tens of thousands of infected machines, signaling a significant increase in the use of this open-source tool by cybercriminals. AsyncRAT spawns 30 malware variants, creating […]

Hackers Hide JavaScript in SVG to Hijack Web Users

Cybercriminals are deploying a new tactic that embeds malicious JavaScript code within SVG image files to redirect victims to harmful websites. This method, where hackers hide JavaScript in SVG images, allows attackers to exploit the flexibility of image files that often bypass security filters on websites and email platforms. Once a user opens the tampered […]

Fake CNN, BBC News Sites Used in Global Scam Push

Cybersecurity researchers have uncovered an elaborate global fraud campaign that uses fake CNN BBC News websites and other cloned pages from trusted media outlets to run investment scams. The scheme targets users across multiple countries by combining social engineering tactics with technical deception to lure victims into fraudulent platforms. The operation begins with sponsored ads […]

Louis Vuitton Data Breach Hits UK, Korea, Turkey Clients

Louis Vuitton reported that unauthorized access to customer data occurred in Turkey, South Korea and the United Kingdom, highlighting a multi-country incident now known as the Louis Vuitton data breach. A statement from the company’s South Korea division confirmed that customer names, contact details and other submitted information were exposed in the breach. However, financial […]

Russia-Backed Fakes Target Europe in Info War Campaign

A Russia-based cyber group known as Storm-1516 has launched a coordinated disinformation campaign targeting several European nations, according to a new report by The Record, a news outlet from cybersecurity firm Recorded Future. The operation, labeled Russia Backed Fakes Target, used fake news websites to publish content posing as journalism from legitimate reporters. Armenia, France, […]

ENISA Names 26 Advisors to Guide EU Cyber Rules to 2028

The European Union Agency for Cybersecurity, or ENISA, has appointed a new 26-member advisory group tasked with guiding the bloc’s cybersecurity policy through 2028. The move, announced this week, marks a significant step in shaping future governance structures and strategic priorities. ENISA names 26 advisors from across sectors to help align national and EU-wide cybersecurity […]

UK Pet Owners Hit by Fake Microchip Renewal Scam

Cybercriminals are targeting UK pet owners with fake microchip renewal scams, exploiting personal data leaked online. The scheme involves fraudulent emails or messages that pressure recipients to renew their pet’s microchip registration through counterfeit websites. UK Pet Owners Hit naturally by these scams risk both financial loss and exposure of sensitive information. HackRead reports that […]

Red Bull Phishing Scam Lures Job Seekers, Steals Logins

A new Red Bull phishing scam is targeting job seekers with fake recruitment emails, impersonating the energy drink giant to lure victims into surrendering login credentials. The emails, sent from messaging-service@post.xero.com, pass SPF, DKIM and DMARC checks, helping them bypass standard email filters undetected. Recipients are directed through a fake reCAPTCHA check to a professional-looking […]

Wing FTP Flaw Exploited as 2,000 Servers Exposed Online

A critical security flaw in Wing FTP Server is under active exploitation, according to researchers who confirmed attacks began just one day after technical details were published. Tracked as CVE-2025-47812, the vulnerability carries a maximum CVSS score of 10.0 and allows unauthenticated remote code execution with root or SYSTEM privileges. Security teams have warned that […]

FBI Seizes Piracy Sites for Nintendo, PS4 Games

The FBI Seizes Piracy Sites connected to illegal distribution of Nintendo Switch and PlayStation 4 games, following an operation led by its Atlanta field office. Authorities took down a series of websites allegedly involved in game piracy, including nsw2u.com, nswdl.com, game-2u.com, bigngame.com, ps4pkg.com, ps4pkg.net, and mgnetu.com. Each site now displays a seizure banner from the […]

Russia-Linked Group Fakes News Sites to Spread Lies

A Russia-linked group fakes news websites and authorship to distribute disinformation across several European countries, researchers have found. The operation uses spoofed versions of legitimate media outlets to publish fabricated articles, targeting audiences in France, Armenia, Germany, Moldova and Norway. The campaign mimics the appearance of real news platforms, making it difficult for readers to […]