loader image
Kelly Benefits Data Breach Hits 550,000 Customers

Kelly & Associates Insurance Group, operating as Kelly Benefits, has disclosed a data breach that compromised the personal information of approximately 550,000 individuals. The Kelly Benefits data breach, which occurred earlier in 2024, has prompted the company to begin notifying affected customers about the exposure of their sensitive data. The company has not specified the […]

APT41 Hides Malware in Google Calendar Traffic

Chinese state-sponsored hacking group APT41 is deploying a new malware strain dubbed “ToughProgress” that exploits Google Calendar for covert command-and-control (C2) communication, according to cybersecurity analysts. The malicious software uses the popular cloud-based scheduling service to blend its traffic with legitimate operations, making detection significantly more challenging. By embedding commands within calendar event data, the […]

Russia-Linked Wiper Hits Ukraine Infrastructure Again

A newly identified strain of data-wiping malware, dubbed PathWiper, has been detected targeting critical infrastructure in Ukraine, according to cybersecurity researchers. The malicious software exhibits characteristics similar to previous wipers associated with Sandworm, a hacking group linked to disruptive cyber operations. The attack marks another instance of destructive malware being deployed against Ukrainian systems amid […]

AT&T Data Leak Tied SSNs, Birth Dates to 49M Users

A threat actor has resurfaced data stolen from a 2021 AT&T breach, this time combining previously separate files to intensify privacy risks for millions. The restructured leak links Social Security numbers and dates of birth to individual phone numbers, potentially exposing sensitive information of up to 49 million users. Originally part of a breach that […]

Hackers Use Ruby Gems to Steal Telegram Bot Tokens

Hackers have launched a targeted supply chain attack against the RubyGems ecosystem, deploying malicious packages to exfiltrate Telegram bot tokens and messages. The campaign, detected by Socket.dev researchers, coincided with Vietnam’s nationwide block of Telegram on May 21, 2025. Threat actors uploaded two typosquatted gems—fastlane-plugin-telegram-proxy and fastlane-plugin-proxy_teleram—masquerading as legitimate Fastlane plugins widely used in CI/CD […]

Paragon Cuts Ties With Italy Over Journalist Hack

Israel-based spyware vendor Paragon has severed ties with the Italian government following a dispute over an investigation into a cyber intrusion involving a journalist’s phone. The company had offered to assist in an audit to determine whether its technology was used in the alleged hack of journalist Francesco Cancellato’s device. However, Italian authorities declined the […]

ClickFix ‘LightPerlGirl’ Malware Hijacks Clipboards

Security researchers have uncovered a stealthy new variant of the ClickFix LightPerlGirl malware that targets users through PowerShell scripting and clipboard hijacking. The attackers deliver the malicious payload via a compromised travel website, increasing the threat’s reach and complexity. This latest strain focuses on silently injecting the Lumma infostealer into victims’ systems. The method involves […]

Iran Hacks Israeli Cameras to Guide Missile Strikes

Israeli authorities have warned that Iranian operatives are targeting local surveillance systems to help guide missile strikes, echoing tactics observed in the war in Ukraine. Officials urged security camera owners to take precautions as Iran hacks Israeli cameras, potentially turning civilian technology into tools for military intelligence. The warning highlights growing concerns over the misuse […]

Firefox 140 Patches Critical Code Execution Flaws

Mozilla has released Firefox 140, addressing a collection of critical security vulnerabilities that include a high-severity code execution flaw. Firefox 140 patches critical issues such as CVE-2025-6424, a use-after-free bug in the FontFaceSet component, which could allow attackers to execute arbitrary code on targeted systems. The update resolves 12 security flaws, including CVE-2025-6436, a group […]

Visual Studio Code Flaw Lets Malicious Add-Ons In

A newly identified vulnerability in popular integrated development environments, including Visual Studio Code, has exposed a significant security gap in how these platforms verify third-party extensions. Researchers found that flawed verification mechanisms allow malicious publishers to bypass trusted status checks and embed harmful code in what appear to be legitimate extensions. The flaw affects several […]

PumaBot Botnet Hacks IoT Devices via SSH Attacks

A newly identified Linux-based botnet known as PumaBot is targeting embedded Internet of Things (IoT) devices by brute-forcing SSH credentials, according to cybersecurity researchers. Written in the Go programming language, PumaBot is designed to infiltrate vulnerable systems and deploy malicious payloads after gaining unauthorized access. The malware specifically targets devices with weak or default SSH […]

Cisco Fixes Critical ISE Flaw Amid Public Exploit PoC

Cisco has issued patches for a critical vulnerability affecting cloud deployments of its Identity Services Engine (ISE), a key component in network access control. The flaw, which impacts the security of cloud-based ISE instances, was accompanied by the public release of a proof-of-concept (PoC) exploit, heightening the urgency for organizations to apply the fix. The […]