loader image
AT&T Unveils Wireless Lock to Thwart SIM Swaps

AT&T unveils Wireless Lock, a new feature designed to shield customers from SIM swapping attacks by blocking unauthorized changes to account information and number porting. The safeguard aims to prevent criminals from taking control of a user’s phone number to access sensitive data, including banking and authentication codes. Once activated, Wireless Lock restricts any modifications […]

ASUS Routers Hacked in Botnet Attack Using SSH Key

A newly discovered botnet campaign known as “AyySSHush” has compromised more than 9,000 ASUS routers globally, cybersecurity researchers said. The attackers gained persistent remote access by injecting an SSH public key, enabling control that survives reboots and firmware upgrades. Uncovered in March 2025, the campaign exploits two previously unknown authentication bypass flaws and CVE-2023-39780, a […]

EU Unveils Cyber Plan to Coordinate Crisis Response

The European Union has unveiled a comprehensive Cyber Blueprint aimed at streamlining crisis management across member states, establishing a unified response framework, and reinforcing cross-border coordination. The initiative is designed to improve the EU’s collective resilience against large-scale cyber incidents by enabling faster, more coordinated responses among national authorities. The blueprint introduces a structured approach […]

Misconfigured HMIs Leave U.S. Water Systems Exposed

Hundreds of dashboard interfaces used to control U.S. water utility systems have been found accessible on the open internet, according to researchers at Censys. The exposed human-machine interfaces (HMIs), which are commonly used in industrial control systems, were misconfigured in a way that allowed anyone with a web browser to view sensitive control-room data. Investigators […]

Fake DocuSign, Gitcode Sites Spread NetSupport RAT

Hackers are leveraging fake Gitcode and DocuSign websites to distribute the NetSupport Remote Access Trojan (RAT), according to a report from The Hacker News. The campaign uses lookalike domains that mimic legitimate platforms to deceive users into downloading the malware. Once installed, NetSupport RAT grants attackers remote control over compromised systems, enabling them to steal […]

SentinelOne Ties ShadowPad Hack to China-Backed Group

SentinelOne researchers have attributed recent cyberattacks involving the ShadowPad and PurpleHaze malware families to China-aligned threat actors, the company said. The cybersecurity firm’s analysis established the link with what it described as “high confidence,” signaling an escalation in the attribution of sophisticated cyber campaigns targeting global networks. ShadowPad, a modular backdoor framework, and PurpleHaze, a […]

AWS Enforces MFA for All Root Users at re:Inforce

Amazon Web Services now requires multi-factor authentication for 100% of root users, marking a significant shift in its cloud security strategy. The announcement came during the company’s re:Inforce event, where AWS Enforces MFA as part of a broader effort to tighten access controls across its platform. This move aims to reduce the risk of unauthorized […]

AT&T Wins Court Nod for $117 Million Breach Deal

AT&T won court approval for a $117 million settlement tied to multiple data breaches that exposed customer information last year. The ruling, issued by U.S. District Judge Ada Brown, allows the telecom giant to resolve a series of lawsuits brought by affected users. AT&T wins court nod as it seeks to close the chapter on […]

WinRAR Fixes Flaw Letting Malware Run on Extraction

WinRAR has released a security update to resolve a directory traversal vulnerability identified as CVE-2025-6218. Under specific conditions, the flaw could allow malware to execute automatically after a user extracts a specially crafted archive. This update follows reports that threat actors might exploit the vulnerability to bypass standard file extraction safety measures. WinRAR fixes flaw […]

Johnson Controls Reveals Victims in 2023 Hack

Johnson Controls reveals victims of a 2023 ransomware attack as it begins notifying individuals impacted by the breach. The multinational manufacturer of automation systems confirmed the incident but has not disclosed what type of data was compromised. The breach, which occurred last year, follows a growing trend of cyberattacks targeting industrial and infrastructure firms. The […]

Hackers Use Malicious Chargers to Breach Smartphones

Cybersecurity researchers have uncovered a new attack method known as “ChoiceJacking,” which enables malicious charging stations to compromise both Android and iOS devices. Discovered by researchers at Graz University of Technology, the technique bypasses long-standing USB security protections by exploiting flaws in user confirmation mechanisms. The attack combines elements of USB host and accessory protocols, […]

PathWiper Malware Hits Ukraine’s Critical Systems

A newly identified data-wiping malware known as “PathWiper” is being deployed in targeted attacks against critical infrastructure in Ukraine, aiming to disrupt essential operations across the country. The malware is designed to erase data irreversibly, posing a significant threat to the stability and functionality of national systems. The attacks appear to be part of a […]