loader image
TP-Link Warns of Critical Omada Gateway Flaws

TP-Link warns of critical vulnerabilities affecting its Omada gateway devices, urging users to install firmware updates immediately. The company disclosed four security flaws this week in two advisories, impacting over a dozen models across the ER, G, and FR series. Among them, CVE-2025-6542 stands out with a CVSS score of 9.3, allowing attackers to execute […]

TP-Link Fixes Four Severe Flaws in Omada Gateways

TP-Link has released security updates addressing four critical vulnerabilities in its Omada gateway devices, according to BleepingComputer. The TP-Link fixes four flaws that could have exposed users to unauthorized access or disruption of network services. These flaws, described as severe, prompted urgent attention from the vendor to reduce potential exploitation risks. The affected Omada gateways, […]

Rust Library Flaw Puts Forked Projects at RCE Risk

A critical vulnerability in a discontinued Rust code library has triggered security concerns across multiple software projects. CyberScoop reports that the flaw, identified as CVE-2025-62518, originates from the abandoned async-tar crate and affects several forks that reused its code. The Rust Library Flaw Puts numerous applications at risk by enabling remote code execution through file […]

Cloudflare Block in Spain Spurs 200% VPN Signup Surge

A widespread Cloudflare block in Spain triggered a surge in VPN usage last week, as major internet service providers restricted access to thousands of websites. The move, aimed at curbing illegal La Liga football streams, caused a 200% spike in Proton VPN signups on October 19, according to the company. Monitoring site Hayahora.futbol confirmed that […]

Have I Been Pwned Adds 180 Million Stolen Logins

More than 180 million stolen credentials have been added to the database of Have I Been Pwned, expanding one of the largest public repositories of compromised account information. The newly added data highlights the growing scale of credential theft, which continues to fuel cybercrime across the digital economy. These stolen login details, often obtained through […]

BIND Flaws Revive DNS Cache Poisoning Threat

Security researchers have uncovered cache poisoning vulnerabilities in two DNS-resolving applications, raising concerns about the return of a once-notorious attack method. The flaws, detailed under CVE-2025-40780, CVE-2025-40778, and CVE-2025-11411, affect BIND, the most widely used DNS software. These BIND flaws revive DNS threats similar to those addressed in 2008, when a major vulnerability led to […]

PhantomCaptcha Hits Ukraine Aid With WebSocket RAT

A spear-phishing campaign known as PhantomCaptcha hit Ukraine aid groups on October 8, 2025, deploying a WebSocket-based remote access trojan. SentinelOne researchers identified that attackers impersonated the Ukrainian President’s Office to send malicious PDF files to organizations like the Red Cross, UNICEF and local administrations. Victims were redirected to a fake Zoom site hosting malware. […]

Iranian Hackers Hit 100 Government Agencies With Virus

A state-backed Iranian cyber-espionage group known as MuddyWater has launched a wave of attacks targeting more than 100 government organizations worldwide. In these operations, Iranian hackers hit 100-plus entities using the latest version of their custom surveillance tool, known as the Phoenix backdoor. The campaign highlights the group’s continued focus on intelligence gathering through stealthy […]

Hackers Exploit OAuth to Bypass Password Resets

Hackers exploit OAuth applications to maintain persistent access to cloud environments, even after victims reset passwords or enable multifactor authentication. Researchers at Proofpoint identified a growing trend where cybercriminals and state-backed actors use trusted Microsoft Entra ID mechanisms to bypass conventional account protections. Once inside, attackers register internal applications with custom permissions, enabling access to […]

Vidar Stealer v2.0 Pierces Chrome Data Defenses

Researchers at Trend Micro have uncovered a significant evolution of the Vidar malware family. Dubbed Vidar Stealer v2.0, the upgraded variant pierces Chrome’s AppBound encryption by using a sophisticated multithreaded memory injection technique. This new capability allows the malware to steal sensitive data more efficiently while evading standard detection methods. According to the analysis, Vidar […]

NeuVector Flaw Exposes Containers to RCE Attacks

A critical remote code execution vulnerability in NeuVector, tracked as CVE-2025-54469 with a maximum CVSS score of 10.0, has been disclosed by the SUSE Rancher Security team. The NeuVector flaw exposes containers to potential command injection through unsanitized environment variables, posing a significant risk to organizations relying on the platform for container security. The vulnerability […]

Microsoft WSUS Flaw Enables Remote Code Execution

A critical vulnerability in Microsoft Windows Server Update Services (WSUS), tracked as CVE-2025-59287, has been disclosed with a maximum CVSS score of 9.8. The Microsoft WSUS flaw enables unauthenticated attackers to execute remote code through unsafe cookie deserialization, posing a severe threat to enterprise environments relying on WSUS for patch management. Security researcher Batuhan Er […]