loader image
IBM Maximo Flaw Lets Hackers Bypass Cognos Controls

IBM has issued a critical advisory for a severe vulnerability in IBM Maximo Manage, part of the IBM Maximo Application Suite. Tracked as CVE-2025-36386 and rated 9.8 on the CVSS scale, the IBM Maximo flaw lets hackers gain unauthenticated access to Cognos Analytics. The company urges users to apply recommended remediation steps immediately to prevent […]

DELMIA Apriso Flaws Let Hackers Seize System Control

The Cybersecurity and Infrastructure Security Agency added two critical DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog on Oct. 29, warning that attackers are actively exploiting them. The vulnerabilities enable remote code execution and unauthorized privileged access, posing a severe threat to industrial and manufacturing systems using Dassault Systèmes’ DELMIA Apriso software. CISA’s alert […]

Australia Builds AI to Decode Criminal Emoji Chats

Australian authorities have developed an artificial intelligence tool designed to decipher the hidden meanings behind emoji used by criminals online. As part of a joint effort within the Five Eyes intelligence alliance, the new system highlights how Australia builds AI to decode messages that exploit digital symbols to target children. The Australian Federal Police (AFP) […]

Herodotus Android Malware Fools Biometrics with Typing Trick

A new Android banking trojan identified as Herodotus is raising red flags among mobile security researchers for its advanced evasion tactics. Discovered during routine malware monitoring, Herodotus Android Malware Foolsnaturally by mimicking human behavior to sidestep biometric detection systems. Although it shares infrastructure with known malware like Hook and Octo, Herodotus blends elements from the […]

VSCode Marketplace Hit as Malicious Plugins Found

A recent investigation by cybersecurity firm HelixGuard uncovered a dozen malicious plugins infiltrating the VSCode Marketplace, highlighting growing concerns over supply chain risks in integrated development environments. Attackers used these extensions to target software developers directly, embedding harmful code into seemingly legitimate tools. The plugins, once installed, could grant unauthorized access or leak sensitive development […]

Sweden Grid Operator Probes Ransomware Data Leak

Sweden’s national grid operator has launched an investigation into a potential cybersecurity breach after a ransomware group claimed to possess hundreds of gigabytes of confidential data. The Sweden Grid Operator probes ransomware threats linked to this incident, which could impact critical infrastructure systems across the country. The ransomware gang alleges it stole extensive internal documents […]

U.S. Rejects Landmark UN Cybercrime Treaty in Hanoi

More than 70 countries signed a landmark United Nations treaty aimed at combating cybercrime this weekend in Hanoi. While hailed as a major step toward global digital security, the U.S. rejects landmark UN cybercrime convention by choosing not to sign the agreement alongside the other nations. The new treaty seeks to establish a unified international […]

Microsoft Patches 172 Bugs in Year’s Biggest Update

Microsoft patched 172 security vulnerabilities in its October 2025 Patch Tuesday release, the highest monthly total so far this year. The update includes fixes for three zero-day flaws, two publicly disclosed issues, and eight vulnerabilities rated as critical. Microsoft Patches 172 Bugs across a broad range of products, underscoring the continued need for rapid response […]

Gerar Hack Exposes 546GB of Youth Employment Data

Hackers breached Gerar, a Brazilian non-profit dedicated to youth employment, and claimed to have stolen 546 gigabytes of sensitive data. The Gerar hack exposes 546GB of personal and official records, according to a report published by Cybernews. The compromised information reportedly includes documents tied to the organization’s programs that serve young people across Brazil. Cybernews […]

Iran’s Ravin Academy Breached in MOIS-Linked Attack

Iran’s Ravin Academy, a cybersecurity training facility linked to the country’s Ministry of Intelligence and Security (MOIS), confirmed it suffered a data breach. The organization disclosed the incident through its official Telegram channel and stated that an investigation is underway. Iran’s Ravin Academy breached systems appear to have exposed sensitive internal data, although the full […]

Italian Spyware Firm Tied to Chrome Zero-Day Attacks

A recent wave of cyberattacks exploiting a zero-day vulnerability in Google Chrome has been linked to an Italian spyware firm tied to Memento Labs. The attacks, part of a campaign dubbed Operation ForumTroll, delivered malware to targeted systems earlier this year, leveraging flaws now tracked as CVE-2025-2857 and CVE-2025-2783. Researchers identified the malware as a […]

Hacking Team Successor Tied to New Spyware Campaign

Kaspersky researchers on Monday revealed a malware campaign they have attributed to the Hacking Team successor tied to an infamous Italian surveillance technology firm. The investigation also uncovered a new strain of commercial spyware, dubbed “Dante,” linked to the same entity. Analysts say the malware appears to target systems in a manner consistent with previous […]