loader image
SpyCloud Finds 94% of Fortune 50 Hit by Phishing

SpyCloud, a cybersecurity firm based in Austin, Texas, has released findings showing that 94% of Fortune 50 companies have experienced employee data exposure linked to phishing attacks. The analysis, published on May 7, 2025, underscores the growing threat posed by credential theft and social engineering tactics targeting major U.S. corporations. The report highlights how stolen […]

Masimo Hit by Cyberattack, Disrupts Operations

Masimo Corp., a medical technology firm, is experiencing operational disruptions following a cybersecurity breach that has impacted parts of its production processes. The company has initiated coordination with law enforcement agencies in response to the incident, which has raised concerns over the security of its digital infrastructure. The breach has triggered interruptions in manufacturing operations, […]

PupkinStealer Malware Loots Logins, Sends Data via Telegram

A new information-stealing malware written in .NET, dubbed PupkinStealer, has emerged, targeting browser credentials and user data with exfiltration conducted via Telegram, cybersecurity firm CYFIRMA said. Detected in April 2025, the malware is attributed to a developer using the alias “Ardent” and reflects a growing trend of threat actors abusing legitimate platforms for command-and-control operations. […]

U.S. Disrupts Botnet, Charges Russians in Crackdown

U.S. authorities have disrupted a major cybercrime operation involving two proxy services—Anyproxy and 5socks—that leveraged infected devices to form a botnet, according to a law enforcement announcement. The takedown targeted infrastructure used to mask malicious online activity by routing traffic through compromised systems without the owners’ knowledge. The operation, which disabled both platforms, marks a […]

EU Cybersecurity Agency Launches Vulnerability Database

The European Union Agency for Cybersecurity (ENISA) has launched the European Vulnerability Database, a centralized resource aimed at enhancing cybersecurity resilience across the region. The platform aggregates reliable and actionable data on security vulnerabilities affecting Information and Communication Technology (ICT) products and services. Designed to support risk mitigation efforts, the database includes critical information such […]

Ivanti Patches Zero-Days Used in Code Execution Attacks

Ivanti urged customers on Thursday to apply security patches for its Endpoint Manager Mobile (EPMM) software to address two critical zero-day vulnerabilities. The flaws, which have been actively exploited in the wild, can be chained together by attackers to achieve remote code execution on targeted systems. The company issued the warning after identifying that threat […]

Hackers Earn $260,000 Breaking AI, Windows at Pwn2Own

Hackers earned a total of $260,000 in cash prizes on the first day of Pwn2Own Berlin 2025, a high-profile security competition that rewards researchers for identifying and exploiting software vulnerabilities. Participants demonstrated successful exploits targeting a range of platforms, including Red Hat, Microsoft Windows, Oracle VirtualBox, Docker Desktop, and artificial intelligence technologies. The competition, known […]

Eventin WordPress Bug Lets Hackers Control 10,000 Sites

More than 10,000 WordPress websites are at risk following the disclosure of a critical vulnerability in the Eventin plugin, a popular tool developed by Themewinter for event management. Tracked as CVE-2025-47539, the flaw enables unauthenticated attackers to create administrator accounts without user interaction, granting full control over affected sites. Security researchers from Patchstack identified the […]

Procolored Site Spread Malware-Loaded Software for Months

Procolored, a printer manufacturer, distributed malicious software through its official website for several months, exposing users to cybersecurity threats. Dozens of downloadable programs available on the site were found to contain information stealer malware and a backdoor, according to a report by *SecurityWeek*. The infected software potentially allowed attackers to harvest sensitive user data and […]

SIM Swapper Jailed for Hijacking SEC’s X Account

A cybercriminal involved in a SIM-swapping scheme that led to the hijacking of the U.S. Securities and Exchange Commission’s account on X (formerly Twitter) has been sentenced to prison. Authorities linked the scammer to the high-profile breach, which underscored persistent vulnerabilities in mobile-based authentication systems widely used across government and corporate platforms. The attacker exploited […]

Microsoft Patch Fixes Windows Server Hyper-V Freezes

Microsoft has issued an emergency update to resolve a critical issue affecting Windows Server 2022, where some Hyper-V virtual machines were freezing or restarting without warning. The problem, which impacted system stability and disrupted operations for affected users, prompted the company to act swiftly with a targeted fix. According to Microsoft, the update addresses a […]

DragonForce Hits MSP, Abuses SimpleHelp to Spread

The DragonForce ransomware group has compromised a managed service provider (MSP), leveraging its SimpleHelp remote monitoring and management (RMM) platform to infiltrate and encrypt systems across multiple customer networks. The attackers reportedly used the MSP’s access to execute data theft and encryption operations on downstream clients, highlighting the risks associated with centralized IT service platforms. […]