loader image
Trump Extends TikTok Reprieve Despite Ban Law

The Trump administration plans to again delay enforcement of its TikTok ban, offering the popular video-sharing platform a temporary reprieve. Trump extends TikTok reprieve under the same legislation that initially sought to block the app — the Protecting Americans from Foreign Adversary Controlled Applications Act. This law targets platforms perceived to be under the influence […]

Jira Tickets Turn Attack Vectors in AI Exploit PoC

A proof-of-concept exploit developed by Cato Networks has demonstrated how Jira tickets turn attack vectors when manipulated through prompt injection techniques. The exploit reveals how attackers can leverage seemingly routine external inputs to compromise internal artificial intelligence tools integrated within enterprise systems. By embedding malicious prompts in Jira tickets, attackers can manipulate AI-driven services that […]

Androxgh0st Botnet Hits US University Servers

The Androxgh0st Botnet hits again, this time targeting servers at U.S. universities as it broadens its digital footprint. Security researchers have observed increased activity from the botnet, which is now exploiting vulnerable infrastructure within academic institutions. These attacks raise concerns over the growing sophistication and persistence of threat actors operating this malware. The botnet reportedly […]

Iranian Hackers Target U.S. Infrastructure, CISA Warns

U.S. cybersecurity and intelligence agencies are warning that Iranian hackers target U.S. critical infrastructure by exploiting outdated software, known vulnerabilities, and weak or default passwords. A joint advisory from CISA, the FBI, NSA, and DC3 urges heightened vigilance amid escalating tensions linked to the ongoing Iran-Israel conflict. While no coordinated campaign has been detected, Iranian […]

Play Ransomware Hit U.S. Using Windows Zero-Day Exploit

Hackers affiliated with the Play ransomware group exploited a now-patched Windows zero-day vulnerability to breach a U.S.-based organization, according to cybersecurity researchers. The flaw, identified as CVE-2025-29824, is a privilege escalation vulnerability in Microsoft’s Common Log File System (CLFS) driver. It had been actively exploited before Microsoft issued a security patch. The Symantec Threat Hunter […]

LockBit Ransomware Chats Exposed in Data Breach

A newly uncovered data breach has exposed internal records of the LockBit ransomware gang, shedding light on the group’s operations. Among the compromised data is a database containing a table labeled “chats,” which includes over 4,000 negotiation conversations between LockBit and its victims. The breach provides a rare glimpse into the communication tactics used by […]

.NET Malware Hides Payloads Inside Bitmap Files

A new strain of .NET malware is employing a stealth technique to evade detection by concealing its malicious payloads within bitmap image resources, according to a post shared on the cybersecurity-focused subreddit r/netsec. The method involves embedding harmful code inside what appear to be standard image files, which are then loaded and executed by the […]

SAP Patches Critical Flaw in NetWeaver Software

SAP has issued 16 new security notes as part of its May 2025 Security Patch Day, addressing several vulnerabilities across its software portfolio, including a critical flaw in its NetWeaver platform. The latest advisory highlights the company’s ongoing efforts to strengthen the security of its widely deployed enterprise systems. The critical vulnerability in NetWeaver could […]

NPM Malware Hijacks Google Calendar to Evade Detection

A newly uncovered supply chain attack targeting the Node Package Manager (NPM) ecosystem is employing Google Calendar as a covert command and control (C2) channel, security researchers at Veracode said. The malware, embedded in JavaScript packages downloaded over 35,000 times, uses obfuscated payloads to evade detection and establish persistent access. Once installed, the malware abuses […]

U.S. Dismantles DanaBot, Charges 16 in $50M Scheme

The U.S. Department of Justice said Thursday it dismantled the infrastructure behind DanaBot, a malware platform tied to a Russia-based cybercriminal group, and unsealed charges against 16 individuals allegedly involved in the scheme. According to the Justice Department, DanaBot—also known as DanaTools—was used to infect more than 300,000 computers globally, facilitating a sprawling cybercrime operation […]

U.S. Plans Data Hub to Centralize Spy Purchases

The U.S. government is developing a centralized platform designed to streamline the purchase of Americans’ personal data by intelligence and law enforcement agencies. The initiative, described as a “one-stop shop,” aims to improve access to commercially available data while raising concerns among privacy advocates about surveillance overreach and potential violations of the Fourth Amendment. In […]

US, Europol Arrest 270 in Dark Web Drug Crackdown

Global law enforcement agencies arrested 288 individuals tied to illicit drug trafficking on the dark web as part of Operation RapTor, a coordinated effort led by U.S. and European Union authorities. The operation resulted in the seizure of more than $200 million in cash and virtual currencies, signaling a major disruption of online narcotics networks. […]