loader image
Google AI Uncovers 5 Flaws in Apple’s Safari WebKit

Google’s cybersecurity-focused AI tool, Big Sleep, recently uncovered five previously unknown vulnerabilities in Apple’s Safari WebKit. The flaws, which Apple has acknowledged, could allow attackers to trigger browser crashes or manipulate memory, posing risks to user security. This marks another instance where Google AI uncovers flaws in widely used software components, reinforcing the role of […]

Putty, Teams Ads Used to Spread Rhysida Ransomware

Cybercriminals are using deceptive online ads to disguise malware as legitimate software like PuTTY and Microsoft Teams, in a campaign known as Putty Teams Ads Spread. The effort delivers OysterLoader, a stealthy tool that enables intrusions into corporate networks and serves as an entry point for the Rhysida ransomware group. Researchers at Expel uncovered this […]

Hackers Target XWiki Flaw in Mass Internet Scanning

A critical remote code execution flaw in XWiki’s SolrSearch component has triggered a wave of exploitation attempts, as hackers target the XWiki flaw through mass internet scanning. The vulnerability permits attackers with guest-level access to execute arbitrary commands, posing a serious threat to organizations running the open-source enterprise wiki platform. Though XWiki issued a patch […]

Android Flaw Lets Hackers Take Over Phones With No Click

Google has issued a critical alert warning of a severe Android flaw that lets hackers execute remote code without user interaction. Detailed in the November 2025 Android Security Bulletin, the vulnerability—tracked as CVE-2025-48593—resides in the System component and affects Android Open Source Project versions 13 through 16. Attackers could exploit it via crafted network packets […]

Fake Forex Sites Lure Investors, Steal Logins Globally

Cybercriminals are increasingly launching fraudulent trading platforms that mimic legitimate forex and cryptocurrency exchanges, with fake forex sites luring investors across Asia and beyond. These schemes use social engineering tactics to convince victims to transfer funds into attacker-controlled systems disguised as authentic investment platforms. Unlike earlier scams confined to single regions, these operations now span […]

EY Exposes 4TB of Client Data in Azure Cloud Blunder

A 4-terabyte SQL Server backup belonging to global accounting firm Ernst & Young was found publicly accessible on Microsoft Azure, exposing a staggering volume of client-related information. The discovery, made by cybersecurity company Neo Security during routine asset mapping, underscores how even major corporations like EY expose 4TB of client data through simple cloud misconfigurations. […]

CrowdStrike Falcon Blocks Git Exploit in Active Attack

CrowdStrike has detected active exploitation of a critical Git vulnerability, identified as CVE-2025-48384. The company reports that its endpoint protection platform, CrowdStrike Falcon, blocks Git-based attacks by intercepting malicious repositories crafted through advanced social engineering tactics. Threat actors are using these deceptive techniques to lure developers into cloning compromised repositories, triggering the exploit. The campaign […]

ClickFix, QR Codes, LOLBins Breach SOC Defenses

Cybercriminals are increasingly leveraging ClickFix, QR codes, and LOLBins to outmaneuver Security Operations Centers (SOCs), according to a recent threat analysis by ANY.RUN. The tactics capitalize on user interaction and system-native tools to bypass traditional detection methods, raising concerns about the readiness of current defense frameworks. ClickFix attacks simulate trusted platforms with fake CAPTCHAs, luring […]

Canada Says Hacktivists Hit Water, Energy Systems

Canada Says Hacktivists Hit critical infrastructure in a series of cyberattacks targeting water and energy systems, according to a warning issued by the Canadian Centre for Cyber Security. The agency reported that the intrusions allowed attackers to access and alter industrial control systems, creating the potential for hazardous situations. Officials said the breaches occurred at […]

Russian Hackers Breach Gov’t Systems Using Native Tools

Russian hackers breached government systems in Ukraine using stealthy tactics that rely heavily on legitimate tools to evade detection, according to new analysis by Symantec researchers. The campaign targeted public sector infrastructure and business services organizations, focusing on long-term access rather than immediate disruption. Investigators tied the operation to Sandworm, a notorious military intelligence unit […]

Chromium Flaw Crashes Edge, Brave in DOS Attack

A critical vulnerability has struck browsers built on the Chromium engine, triggering widespread disruptions across several platforms. The Chromium flaw crashes Edge naturally along with other browsers like Atlas and Brave, exposing a shared weakness in the underlying codebase. The flaw enables a denial-of-service attack by exploiting how these browsers render specific web content. Security […]

Malicious NPM Packages Deploy Cross-Platform Spyware

Security researchers have identified ten malicious npm packages deploynaturally to imitate legitimate software tools and infect systems across multiple platforms. These packages, hosted in the npm registry, deliver an information-stealing component that targets Windows, Linux, and macOS environments. Once installed, the malware collects sensitive data from affected devices, putting users and organizations at risk. The […]