loader image
QNAP Warns of Critical Flaw in Windows Backup Tool

QNAP has issued an urgent security alert, urging users to patch a critical ASP.NET Core vulnerability that affects its NetBak PC Agent software. The flaw, tracked as CVE-2025-55315, exposes systems running the Windows-based backup utility to potential exploitation. This vulnerability originates from ASP.NET Core, a web framework developed by Microsoft, and could allow attackers to […]

Microsoft to Prompt Memory Scans After BSOD Crashes

Microsoft is testing a new Windows 11 feature that alerts users to scan system memory following a blue screen of death (BSOD) crash. The prompt appears upon the next login, aiming to help users detect potential hardware or software issues that may have triggered the system failure. The initiative signals Microsoft to prompt memory diagnostics […]

ChatGPT Atlas Tool Exposes Users to Prompt Injection Risks

Security researchers have identified a new method for prompt injection attacks using the address bar in OpenAI’s ChatGPT Atlas Tool Exposes. According to findings, a prompt concealed as a URL can deceive users into unknowingly copying and pasting malicious instructions into the AI interface. This tactic creates a potential entry point for attackers to manipulate […]

Microsoft WSUS Exploits Hit Multiple Firms, Google Says

Google has issued a warning that attackers are actively exploiting Microsoft WSUS vulnerabilities to compromise multiple organizations. The tech giant’s threat intelligence team observed a wave of intrusions targeting Windows Server Update Services, a tool used to manage and distribute Microsoft software updates across enterprise environments. Threat actors appear to be leveraging flaws in the […]

Apache Tomcat Fixes Flaws Risking RCE, Console Attacks

The Apache Software Foundation has released security patches for Apache Tomcat to address three newly discovered vulnerabilities, including CVE-2025-55752, which could allow attackers to bypass URL rewriting mechanisms. The flaw may expose systems to remote code execution and console ANSI injection. The Apache Tomcat fixes flaws that could compromise the integrity of applications relying on […]

SideWinder APT Hits Diplomats With StealerBot Attack

The SideWinder APT group has launched a new cyber espionage campaign targeting South Asian diplomatic missions, according to researchers at Trellix Advanced Research Center. Using a revamped infection chain that begins with malicious PDF files and progresses through ClickOnce deployments, the attackers deliver a custom malware dubbed StealerBot. In this latest operation, SideWinder APT hits […]

Kaspersky Unmasks Chrome Zero-Day Used for Spyware

Kaspersky researchers have uncovered a sophisticated cyberespionage operation leveraging a critical zero-day vulnerability in Google Chrome, tracked as CVE-2025-2783. In a report published Tuesday, Kaspersky unmasks the Chrome zero-day as a remote code execution flaw exploited in a targeted campaign dubbed “ForumTroll.” The attackers delivered commercial spyware linked to the Italian firm Memento Labs through […]

Apache Tomcat Flaws Expose Servers to Code Attacks

Apache Tomcat flaws expose servers to serious security risks, following the disclosure of multiple critical vulnerabilities by the Apache Software Foundation. The open-source Java servlet container, widely deployed to support web applications, contains weaknesses that could allow attackers to execute arbitrary code remotely. Apache published the details on October 27, 2025, underscoring the urgency for […]

OpenVPN Flaw Lets DNS Hack Linux, macOS Devices

Security researchers have identified a high-severity vulnerability in OpenVPN, tracked as CVE-2025-10680, that affects versions 2.7_alpha1 through 2.7_beta1. The OpenVPN flaw lets DNS servers controlled by attackers inject malicious scripts into Linux and macOS systems. If exploited, the flaw could allow unauthorized code execution during VPN connection setup. The vulnerability carries a CVSS score of […]

Python Foundation Rejects $1.5M Grant Over DEI Clash

The Python Foundation rejected a $1.5 million grant from the U.S. National Science Foundation after discovering an anti-DEI clause in the agreement. The proposal, submitted in January 2025, focused on enhancing open-source security through the NSF’s Open Source Ecosystem Security, Safety, and Privacy initiative. The clause conflicted with the Foundation’s commitment to diversity, equity and […]

SideWinder Hacks Diplomats Using ClickOnce Attack Chain

A threat actor known as SideWinder has launched a new cyber campaign targeting diplomatic entities across South Asia, including a European embassy in New Delhi. The operation, which began in September 2025, demonstrates how SideWinder hacks diplomats using a more advanced attack chain. Researchers say the group now leverages malicious PDF files in combination with […]

Microsoft Teams to Auto-Track Workers via Wi-Fi

Microsoft plans to roll out a new feature in its Teams platform this December that will allow the software to auto track user office locations via Wi-Fi. The update, listed in the company’s latest roadmap, aims to streamline workplace coordination by identifying whether employees are working on-site or remotely. The feature will use a device’s […]