loader image
FBI Warns Iran Used Telegram to Spy on Dissidents

The FBI warns Iran’s Ministry of Intelligence and Security is using Telegram as a command-and-control platform in a cyber campaign targeting dissidents and journalists. The malware attacks enable surveillance and data theft amid escalating geopolitical tensions in the Middle East. According to a recent alert, Iranian cyber actors deliver malware that disguises itself as legitimate […]

Aqua Trivy Scanner Compromised in Supply Chain

The Aqua Trivy scanner, a widely-used open-source tool for identifying vulnerabilities, recently became the target of a sophisticated supply chain attack. Cybercriminals infiltrated the distribution channel and released a malicious version of the scanner. By altering specific tags, these attackers redirected users towards information-stealing malware. This unauthorized release underscores the growing complexity and danger of […]

Global Crackdown Dismantles 4 DDoS Botnets

A global crackdown dismantles botnets responsible for significant distributed denial-of-service (DDoS) attacks, dealing a significant blow to cybercriminal operations. Authorities targeted four notorious botnets, aiming to curb their ability to disrupt online services. Known for orchestrating large-scale DDoS campaigns, the botnets, identified as “Aisuru,” “Kimwolf,” “Jackskid,” and “Mossad,” posed a severe threat to digital infrastructures […]

Clayrat Malware Collapses After Developer Arrest

The collapse of the clayrat malware operation signifies a quick downfall for an Android malware effort that briefly gained ground in Russia. Researchers noted that security weaknesses led to the exposure of its underlying infrastructure. The operation’s troubles intensified when authorities arrested the individual believed to be its developer. These developments unfolded mere months after […]

Charles de Gaulle Tracked on Strava

The Charles de Gaulle aircraft carrier’s location in the Mediterranean was inadvertently revealed due to a sailor’s use of the Strava fitness app, highlighting an operational security lapse. According to Le Monde, a French naval officer unknowingly shared running data, captured via a smartwatch, which was then made accessible to the public because his Strava […]

Apple Warns Older iPhones Vulnerable to DarkSword

Apple warns older iPhones are increasingly vulnerable to sophisticated cyber threats due to outdated iOS software. The tech giant urges users to update their devices to protect against web-based attacks using exploit kits, notably Coruna and DarkSword. These exploits deliver malicious web content, targeting older iOS versions, leading to potential breaches of sensitive user data. […]

Aisuru, Kimwolf Botnets Disrupted in Global Raid

Authorities from multiple nations launched a coordinated operation that successfully disrupted the Aisuru and Kimwolf botnets, which have been responsible for large-scale DDoS attacks. This international effort, announced today, also targeted the JackSkid and Mossad botnets, lesser-known networks that contributed to cybersecurity threats. The operation reflects rising cooperation between countries aiming to curb the activities […]

Langflow Flaw Exploited Hours After Disclosure

A critical flaw in Langflow, a popular data management tool, has been exploited just hours following its public disclosure. This vulnerability permits unauthenticated remote code execution due to the handling of attacker-supplied flow data within public flows. The exposure of this exploit underscores the urgent need for developers and users alike to prioritize patching vulnerable […]

PSpice AES-256 Broken by Copy-Paste Bug

A potential vulnerability emerged within the PSpice AES-256 encryption due to a seemingly innocuous error—a copy-paste bug. This development has drawn significant attention from the cybersecurity community, highlighting how simple mistakes can compromise complex cryptographic protocols. The incident underscores the need for meticulous attention to detail during the coding process, especially when handling sensitive encryption […]

Moxie Marlinspike Will Help Encrypt Meta AI

Moxie Marlinspike, renowned for creating the messaging app Signal, is extending his expertise to Meta AI. His end-to-end encryption technology, first implemented in his AI chatbot, Confer, will soon be integrated into Meta’s artificial intelligence framework. This step could significantly enhance the privacy of millions engaging in AI-driven conversations through Meta’s platforms. The integration aims […]

DarkSword iOS Kit Hijacks iPhones Without Tap

The DarkSword iOS kit is making waves as multiple threat actors exploit a troubling new vulnerability. This six-vulnerability exploit kit affects iPhones running iOS versions 18.4 through 18.6.2. Users need only to load a single webpage on certain compromised Ukrainian government sites for their personal data, including messages, photos, and passwords, to be exposed without […]

CISA Warns on Zimbra and SharePoint Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that government agencies should urgently patch vulnerabilities found in Synacor Zimbra Collaboration Suite and Microsoft Office SharePoint. These security flaws, one of which is cataloged as CVE-2025-66376 with a CVSS score of 7.2, have already been exploited by malicious actors. The agency stresses that these vulnerabilities […]