loader image
F5 Flaw Lets Admins Run Rogue Commands as Root

F5 Networks has disclosed a high-severity command injection vulnerability affecting its BIG-IP products operating in Appliance mode. Tracked as CVE-2025-31644, the flaw resides in an undisclosed iControl REST endpoint and a TMOS Shell (tmsh) command, allowing authenticated attackers to execute arbitrary system commands by bypassing security restrictions. The vulnerability is rated 8.7 on the CVSS […]

Kosovo Man Extradited to U.S. for Dark Web Market

A 33-year-old citizen of Kosovo has been extradited to the United States to face charges in connection with the operation of an illegal online marketplace, U.S. authorities said. The individual is accused of playing a significant role in managing the platform, which allegedly facilitated unlawful transactions over the internet. The extradition underscores ongoing efforts by […]

Windows 10 Update Triggers BitLocker Recovery Errors

A recent Windows 10 update, labeled KB5058379, is triggering unexpected BitLocker recovery prompts on some devices following installation and a system reboot. The cumulative update, pushed as part of Microsoft’s regular release cycle, appears to inadvertently activate the recovery process for BitLocker, the operating system’s built-in encryption feature. Users who applied the update have reported […]

Google Calendar Abused to Hide Stealthy NPM Malware

A newly discovered malicious package in the NPM ecosystem is leveraging Google Calendar as a covert communication channel, allowing attackers to evade traditional detection mechanisms. The malware uses the calendar service as a “middleman” to receive commands and exfiltrate data, masking its activity behind legitimate infrastructure. In addition to this novel approach, the package employs […]

SAP Cyberattack Spreads, Echoes Typhoon APT Tactics

A wave of zero-day cyberattacks targeting SAP, Europe’s largest software maker, is expanding, with hundreds of victims identified globally. The scale and sophistication of the campaign have drawn comparisons to operations conducted by Salt Typhoon and Volt Typhoon—advanced threat groups linked to state-backed cyber activity. Although the full extent of the breach remains unclear, the […]

Zimbra Hack Hits 129,000 Servers; Sednit Suspected

A critical cross-site scripting (XSS) vulnerability tracked as CVE-2024-27443 has impacted more than 129,000 Zimbra Collaboration Suite servers worldwide, according to cybersecurity sources. The flaw has drawn scrutiny due to suspected exploitation by Sednit, a threat group believed to have ties with advanced persistent threat operations. The vulnerability allows attackers to inject malicious scripts into […]

Coinbase Fires Staff After Breach Hits 70,000 Users

Coinbase has confirmed that an internal breach compromised the personal data of approximately 70,000 users, following the discovery that support staff were bribed. The cryptocurrency exchange said the involved employees have been identified and terminated. The breach raises concerns about insider threats within digital asset platforms, particularly as Coinbase continues to expand its global operations. […]

Cybersecurity Pay 2025 Rises for Top Tech, Falls Elsewhere

Cybersecurity salaries are showing notable divergence heading into 2025, with specialized roles commanding higher pay while generalist and support positions see compensation stagnate, according to CyberSN’s 2025 Salary Data Report. The report highlights growing demand for advanced technical expertise and leadership capabilities, which are driving salary increases for professionals in those segments. In contrast, positions […]

O2 UK Fixes Flaw That Exposed Caller Location Data

O2 UK has addressed a security vulnerability in its implementation of Voice over LTE (VoLTE) and WiFi Calling technologies that exposed mobile users’ general location and unique identifiers. The flaw allowed anyone who placed a call to a target number to potentially extract sensitive metadata, including details that could reveal the recipient’s approximate whereabouts. The […]

UTC Joins ISASecure to Boost Utility Cyber Standards

The Utilities Technology Council (UTC) has joined ISASecure, a globally recognized cybersecurity certification program, in a move aimed at bolstering cybersecurity standards across utility infrastructure. The collaboration is expected to enhance the resilience of operational technology (OT) systems that underpin critical utility services. By aligning with ISASecure, UTC seeks to advance the development and implementation […]

Self-Spreading Malware Turns Docker into Dero Botnet

A newly discovered malware strain is targeting misconfigured Docker API endpoints, transforming exposed containers into nodes of a growing botnet used to mine Dero cryptocurrency. The campaign is distinguished by its self-propagating, worm-like behavior, allowing the malware to autonomously spread to other vulnerable Docker instances without requiring manual intervention. Security researchers at Kaspersky observed the […]

AVCheck Takedown Hits Cybercrime Malware Testing Network

Law enforcement agencies from the U.S., Europe, and other international partners have dismantled AVCheck, a cybercriminal platform used to test and encrypt malware to evade antivirus detection. Officials seized four domains and associated servers as part of Operation Endgame, a multinational crackdown on malware infrastructure. AVCheck offered counter-antivirus (CAV) services and crypting tools, enabling cybercriminals […]