loader image
HPE Fixes StoreOnce Flaw Allowing Remote Intrusion

Hewlett Packard Enterprise has issued security patches addressing a set of eight vulnerabilities in its StoreOnce data backup and deduplication product. The flaws, if left unpatched, could allow attackers to bypass authentication mechanisms and execute arbitrary code remotely, the company said. The vulnerabilities impact the StoreOnce platform, which is used by enterprises to manage and […]

CISA Flags Chrome 0-Day Bug Exploited in Active Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert for a zero-day vulnerability in Google Chrome, actively exploited by attackers to execute arbitrary code. Tracked as CVE-2025-5419, the flaw resides in Chrome’s V8 JavaScript and WebAssembly engine and impacts versions prior to 137.0.7151.68. Added to CISA’s Known Exploited Vulnerabilities Catalog on […]

Apache Tomcat Panels Hit by Coordinated Login Attacks

Hackers are launching a coordinated wave of brute-force attacks on Apache Tomcat Manager interfaces exposed to the internet, using hundreds of unique IP addresses to escalate their efforts. The campaign targets web servers running the open-source Apache Tomcat software, aiming to gain unauthorized access to administrative panels by systematically guessing login credentials. Security analysts report […]

Quasar RAT Spread by Bat Files in Stealth Malware Push

Cybersecurity analysts have uncovered a new campaign in which threat actors are using Windows batch files to deploy the Quasar RAT, a known remote access Trojan. The attack begins with a deceptive batch file that appears benign but covertly initiates the download and execution of malicious payloads, marking a notable shift in malware delivery tactics. […]

Washington Post Email Hack Tied to Foreign Spy Effort

A cyberattack has compromised the email system of The Washington Post, exposing the accounts of several journalists. The incident, referred to by cybersecurity analysts as the Washington Post Email Hack, is believed to have been carried out by a foreign government, though the source has not been publicly confirmed. The breach targeted internal communications, raising […]

M&S, Co-op Cyberattacks May Cost Up to £440 Million

The recent cyberattacks on Marks & Spencer and Co-op may cost the UK retail sector up to £440 million, according to the Cyber Monitoring Centre. The agency classified the M&S Co-op cyberattacks as a Category 2 systemic event, citing their financial severity and disruption to business operations and supply chains. Hackers from the DragonForce group […]

GitHub Fixes Flaw Letting Hackers Execute Code Remotely

GitHub has addressed a high-severity vulnerability in its Enterprise Server software that could have enabled remote attackers to execute arbitrary code. The flaw posed a significant risk to organizations relying on the platform for code collaboration and deployment. GitHub fixes flaw naturally by releasing a security patch to mitigate the issue and protect its enterprise […]

Fake Recruiters Use NetBird to Target CFOs Globally

A new spear-phishing campaign is targeting Chief Financial Officers and financial executives across six global regions, cybersecurity researchers have warned. The operation, which spans Europe, Africa, Canada, the Middle East, and South Asia, leverages fake recruiter emails to lure victims into downloading a legitimate remote access tool called NetBird. The attackers appear to be executing […]

KiranaPro Cloud Wiped in Attack, CEO Promises Action

KiranaPro, an Indian e-commerce platform that digitizes operations for local convenience stores, suffered a significant cyberattack that led to the deletion of its cloud-based resources. The company’s CEO described the incident as a “deliberate attack” and pledged to identify and expose the perpetrator behind the disruption. The platform, which enables small retailers to manage inventory […]

Malware Hits npm, PyPI in Global Supply Chain Attack

A new supply chain malware campaign is targeting the npm and PyPI open-source ecosystems, compromising over a dozen packages linked to GlueStack, according to cybersecurity researchers. The attack, disclosed by Aikido Security, involves a malicious modification to the ‘lib/commonjs/index.js’ file within these packages. The alteration enables attackers to execute shell commands, capture screenshots, and upload […]

Ukrainian Police Nab Hacker in Crypto Mining Bust

Ukrainian authorities have arrested a hacker accused of hijacking a hosting provider’s servers to illegally mine cryptocurrency, police said. The suspect, a resident of Poltava in central Ukraine, had allegedly been engaging in cyberattacks since at least 2018. According to law enforcement, the individual exploited access to server infrastructure to install unauthorized mining software, diverting […]

Microsoft Launches EU-Wide Cybersecurity Offensive

Microsoft launched a new European Security Programme designed to enhance cybersecurity resilience across the European Union and neighboring regions, as digital threats continue to grow, according to a report by *Computer Weekly*. The initiative will cover all 27 EU member states, candidate countries seeking EU accession, the United Kingdom, and several bordering nations. The program […]