loader image
QNAP NAS Backup Hit by Critical .NET Credential Flaw

A critical vulnerability in Microsoft’s ASP.NET framework, tracked as CVE-2025-55315, is now actively affecting QNAP NAS Backup utility users, exposing them to credential theft. Microsoft addressed the flaw with a recent security update, rating it 9.8 on the CVSS scale. Although initially thought to have limited impact, security researchers have since confirmed exploitation in real-world […]

Clearview AI Faces Criminal Complaint Over Photo Scraping

Clearview AI faces a criminal complaint after allegedly collecting billions of photos from the internet without user consent and marketing its facial recognition technology to law enforcement and government entities. The company’s data scraping practices have sparked widespread criticism from privacy advocates across Europe, who argue that Clearview’s actions violate fundamental rights. The complaint, filed […]

CISA Warns CVSS 10.0 Bug Exposes AutomationDirect PLCs

The U.S. Cybersecurity and Infrastructure Security Agency issued an emergency alert on Oct. 26, warning of a critical remote code execution flaw with a CVSS score of 10.0 in AutomationDirect’s Productivity programmable logic controllers. CISA warns CVSS 10 vulnerabilities could allow unauthenticated attackers to take full control of impacted systems, posing significant risks to industrial […]

CISA Warns Veeder-Root Flaw Exposes Fuel Tank Systems

The Cybersecurity and Infrastructure Security Agency issued a critical security alert on Monday, warning that Veeder-Root TLS4B Automatic Tank Gauge systems are vulnerable to remote command injection. The alert highlights two high-severity flaws, including CVE-2025-58428, which if exploited, could allow attackers to execute arbitrary commands. CISA warns Veeder Root flaw poses a significant risk to […]

UN Cybercrime Pact Draws Support, Sparks Rights Fears

Dozens of countries have signed a new international treaty aimed at combating cybercrime, raising fresh concerns among digital rights advocates. The UN Cybercrime Pact draws attention for its provisions that enable expanded surveillance and facilitate cross-border data sharing, moves critics say could erode civil liberties. Supporters argue the agreement strengthens global cooperation against online threats. […]

Telegram Hijacked With Android Malware for Full Control

Cybercriminals are distributing a sophisticated Android backdoor, identified as Android.Backdoor.Baohuo.1.origin, through tampered versions of the Telegram X messenger. This malware, which has effectively left Telegram hijacked with Android malware, provides attackers with full control over user accounts while remaining hidden from victims. It spreads mainly via fake dating and communication apps promoted through deceptive ads […]

LockBit 5.0 Strikes Windows, Linux, ESXi Systems

The LockBit ransomware gang has reemerged with LockBit 5.0, a revamped variant that actively targets Windows, Linux, and ESXi platforms. After months of silence following law enforcement’s Operation Cronos, the group’s administrator rebuilt its infrastructure and resumed attacks. LockBit 5.0 strikes Windows systems in particular, with 80% of infections affecting that platform during a wave […]

Microsoft Patches 172 Flaws, 3 Zero-Days in October

Microsoft’s October 2025 Patch Tuesday rolled out fixes for 172 security flaws, the largest monthly total so far this year. Among those addressed, eight were rated critical, three were zero-day vulnerabilities actively exploited in the wild, and two had been publicly disclosed prior to the update. The company’s response underscores the growing priority on mitigating […]

CrowdStrike Blocks Active Git Exploit in Falcon Defense

CrowdStrike blocks active Git vulnerability CVE-2025-48384 following the detection of targeted exploitation efforts. Threat actors used advanced social engineering techniques to lure developers into cloning malicious Git repositories. Once cloned, these repositories triggered the vulnerability, potentially compromising developer systems. CrowdStrike’s Falcon platform identified and blocked the attack chain in real time, preventing further impact. The […]

Safepay Hacks Xortec, Threatens Security Supply Chain

The Safepay ransomware group has claimed responsibility for breaching Xortec GmbH, a German provider of professional video surveillance and security solutions. As part of the attack, the group listed the company on its data leak site and set a ransom deadline for October 27, 2025. The incident, titled “Safepay Hacks Xortec,” could pose significant risks […]

NTLM Flaw Lets Hackers Jump From User to System Access

A newly uncovered NTLM flaw lets hackers escalate privileges on systems running LDAP or LDAPS services, according to a report published Oct. 26, 2025. Tracked as CVE-2025-54918, the vulnerability impacts domain controllers and allows attackers to move from a standard domain user role to full SYSTEM-level access. The security flaw emerged in September 2025 and […]

HashiCorp Vault Flaws Expose AWS Auth, Trigger DoS Risk

HashiCorp has released critical patches for two high-severity vulnerabilities affecting its Vault identity-based security platform. The newly disclosed HashiCorp Vault flaws expose deployments to risks including unauthorized AWS authentication bypasses and denial-of-service attacks via unauthenticated JSON payloads. The company is urging users to apply updates immediately to mitigate potential threats. The flaws are tracked under […]