loader image
Symantec Ties China Spy Tools to Global Hacking Campaigns

Symantec researchers have uncovered significant overlaps among Chinese state-linked cyberespionage groups, revealing shared tools and infrastructure across multiple operations. The report, titled “Symantec Ties China Spynaturally,” highlights how threat actors deployed Zingdoor backdoors, ShadowPad malware, and the KrustyLoader trojan in coordinated attacks targeting global networks. The analysis shows these malware variants operating within a broader […]

Jira Flaw Lets Hackers Write Files on Data Center Servers

Atlassian has issued security updates to fix a high-severity vulnerability in Jira Software and Jira Service Management running in Data Center and Server deployments. The Jira flaw lets hackers exploit a path traversal weakness, tracked as CVE-2025-22167, to write arbitrary files on affected systems. This exposure poses a significant risk to organizations relying on these […]

ISC Patches BIND Flaws Enabling DNS Cache Attacks

The Internet Systems Consortium has rolled out security updates for BIND 9, addressing three high-severity vulnerabilities that could allow attackers to launch cache poisoning and denial-of-service attacks. The ISC Patches BIND Flaws to prevent exploitation of these issues, which pose significant risks to DNS infrastructure if left unpatched. Among the disclosed vulnerabilities are CVE-2025-40777 and […]

Apple Sues EU to Block Digital Markets Act Rules

Apple escalated its ongoing dispute with the European Union by launching a legal challenge against the Digital Markets Act, marking a new phase in their regulatory clash. The lawsuit, filed before the EU General Court, underscores the tech giant’s resistance to sweeping compliance demands under the DMA. Apple sues EU to block enforcement of rules […]

Lanscope Bug Hit in Attacks, CISA Warns of Exploits

The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday confirmed that a critical vulnerability in Motex Lanscope Endpoint Manager is being actively exploited in cyberattacks. The Lanscope bug hit on-premises versions of the software, prompting the agency to add the flaw to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2025-61932, the security issue carries a […]

Magento Stores Hacked as New Adobe Flaw Exploited

Hackers have launched a widespread cyberattack targeting over 250 Magento stores overnight, exploiting a newly disclosed vulnerability in Adobe Commerce and Magento Open Source. Security firm Sansec reported the intrusion attempts, warning that attackers are actively taking advantage of CVE-2025-54236—an improper input validation flaw with a critical CVSS score of 9.1. The company detected hundreds […]

Meta Targets Scammers With WhatsApp, Messenger Tools

Meta introduced a suite of security enhancements Tuesday aimed at protecting users of Messenger and WhatsApp from online scammers. The company launched the new tools during Cybersecurity Awareness Month, reinforcing its broader initiative as Meta targets scammers with smarter, real-time detection and user empowerment features. On WhatsApp, users will now see alerts when they share […]

Microsoft Updates Break Logins in Windows, Server 2025

Microsoft confirmed that recent security updates are disrupting login processes on Windows 11 versions 24H2, 25H2, and Windows Server 2025. The problem, which surfaced after updates like KB5064081 and KB5065426, highlights how Microsoft updates break logins on systems with duplicated Security Identifiers (SIDs), especially in enterprise environments using cloned virtual machines. Users report recurring credential […]

Pakistani Hackers Mimic NIC Email to Target India Govt

A cyber-espionage group linked to Pakistan has launched a phishing campaign against Indian government agencies, posing as the National Informatics Centre’s email services. Cybersecurity analysts have attributed the operation to APT36, also known as TransparentTribe. These Pakistani hackers mimic NIC email headers and formats to deceive officials into sharing credentials or downloading malicious files. The […]

Cursor, Windsurf IDEs Expose 94 Chromium Flaws

Developers using the latest versions of Cursor and Windsurf IDEs face heightened risks, as both platforms expose users to over 94 known security flaws tied to outdated Chromium and V8 JavaScript components. These vulnerabilities, previously patched in their original frameworks, remain unaddressed in the IDEs, leaving systems open to possible exploitation. Security researchers identified the […]

AWS Outage Hits 1,000 Firms, DNS Failure Blamed

A widespread disruption on Oct. 20 took more than 1,000 organizations offline, highlighting the internet’s reliance on Amazon Web Services. The AWS outage hits 1,000 firms across sectors, cutting access to websites, applications and digital services as engineers traced the root of the issue to a Domain Name System (DNS) malfunction. The interruption, which lasted […]

AI Agent Hijack Flaw Found in Anthropic’s MCP Protocol

A newly disclosed vulnerability in the Oat++ implementation of Anthropic’s Model Context Protocol (MCP) exposes AI agents to session hijacking, security researchers revealed. The flaw allows attackers to exploit predictable session IDs, enabling unauthorized access to ongoing conversations and effectively executing an AI Agent Hijack Flaw. The issue has been assigned CVE-2025-6515. By capturing or […]