loader image
EvilWorker Hijacks Browsers in Stealthier Phishing Blitz

A newly surfaced adversary-in-the-middle (AiTM) attack framework known as “EvilWorker” is gaining attention within the cybersecurity community for its innovative use of service workers to intercept and manipulate web traffic. Highlighted in a recent post on the r/netsec forum, EvilWorker is being compared to the widely known Evilginx2 tool, with users suggesting it may be […]

KrebsOnSecurity Hit by Record 6.3 Tbps DDoS Blast

Cybersecurity news site KrebsOnSecurity was targeted in a massive distributed denial-of-service (DDoS) attack that peaked at 6.3 terabits per second, according to HackRead. The attack was reportedly carried out by the Aisuru botnet, a network of compromised devices used to flood websites with traffic in an attempt to disrupt access. The scale of the incident […]

O2 Flaw Let Callers Track Users’ Locations Since 2017

A critical flaw in O2 UK’s Voice over LTE (VoLTE) service exposed the real-time location and device identifiers of its mobile customers during phone calls, according to a recent disclosure. The vulnerability, present since the service’s launch in March 2017, leaked sensitive data—including IMSI, IMEI, and precise cell tower information—via improperly configured SIP headers in […]

France Denies Telegram CEO’s Romania Election Claim

France’s foreign ministry pushed back against claims made by Telegram’s CEO, stating it “categorically rejects” accusations that French intelligence requested the platform to suppress conservative voices in Romania ahead of national elections. The ministry’s response follows a statement from Pavel Durov, who alleged that French authorities attempted to influence political discourse in the country through […]

SK Telecom Hack Exposes 27 Million SIM Records

SK Telecom, one of South Korea’s largest telecommunications providers, suffered a major data breach exposing nearly 26.69 million international mobile subscriber identity (IMSI) records, according to a disclosure by the Ministry of Science and ICT. The breach, first reported last month, has raised concerns over the security of mobile communications and subscriber data in the […]

Fake Clinics Lure Victims in Healthcare Phishing Wave

Cybercriminals are targeting the healthcare sector with a new wave of phishing scams involving fake medical clinics, according to GBHackers News. The attacks have contributed to a sharp rise in data breaches across the industry, with 92% of healthcare organizations reporting incidents that compromised more than 276 million patient records. On average, 758,000 records are […]

Adidas Confirms Hack, Customer Data Compromised

Adidas has confirmed a cybersecurity breach that resulted in unauthorized access to customer data, the company disclosed in a recent statement. The sportswear giant did not specify the scale of the attack or the exact nature of the compromised information. The incident highlights growing concerns over data security in the retail and apparel sectors, which […]

Dadsec Hackers Exploit Tycoon2FA to Breach Office365

A coordinated phishing campaign exploiting shared cybercriminal infrastructure has emerged as a growing threat to enterprise Microsoft 365 users, according to researchers at Trustwave. The operation connects the Tycoon2FA Phishing-as-a-Service (PhaaS) platform—active since August 2023—with the threat group Storm-1575, also known as Dadsec. Attackers employ adversary-in-the-middle (AiTM) techniques to bypass multi-factor authentication, distributing phishing emails […]

PyPI Malware Mimics Popular Tools to Backdoor Systems

Two malicious Python packages uploaded to the Python Package Index (PyPI) are targeting Windows and Linux systems, according to Hackread. The attack involves backdoored libraries designed to infiltrate developer environments. One of the packages mimics “colorama,” a legitimate and widely used Python tool for color formatting in terminal output. The second imitates “colorizr,” a similarly […]

Google Warns Hackers Target Salesforce With Vishing Ploy

Google has issued a warning about a financially motivated cybercriminal group targeting Salesforce customers through a vishing and extortion campaign. The attackers are using voice phishing tactics to deceive victims into revealing sensitive information, which is then leveraged to gain unauthorized access to Salesforce accounts. Once inside, the threat actors reportedly extort the victims, demanding […]

Microsoft Patches 66 Flaws, One Bug Actively Exploited

Microsoft addressed 66 vulnerabilities in its latest Patch Tuesday release, with 10 of the flaws classified as “critical,” the company disclosed. Among the patched issues, two carry a Common Vulnerability Scoring System (CVSS) rating of 8.8, signaling high severity. Notably, one of these high-rated vulnerabilities is currently under active exploitation, heightening the urgency for users […]

Chrome, Firefox Fix High-Risk Memory Flaws

Google and Mozilla have issued security updates addressing four high-severity memory-related vulnerabilities in their respective web browsers, Chrome and Firefox. The patches, released separately by the two companies, are designed to mitigate risks stemming from memory bugs that could be exploited to compromise user systems or cause application instability. The updates reflect ongoing efforts by […]