loader image
China-Linked Hackers Target 75 Global Organizations

More than 75 organizations worldwide have been targeted in a cyber-espionage campaign attributed to a suspected Chinese state-sponsored hacking group, according to cybersecurity firm SentinelOne. The campaign was uncovered when the attackers attempted to breach the company’s own servers, prompting further investigation. SentinelOne identified a sophisticated operation aimed at compromising global entities across multiple sectors. […]

Canva User Data Surfaces in Russian AI Leak

A limited set of Canva creator data has been uncovered in a newly leaked database associated with Chroma, a Russian-operated AI chatbot project, according to cybersecurity reporting by Hackread. The exposed data was discovered among files linked to the Chroma platform, which is believed to be used for collecting and processing online information to enhance […]

US Leads World in Unsecured Cameras Exposing Homes

The United States has emerged as the leading country in the number of unsecured surveillance cameras, raising significant concerns over privacy and cybersecurity. A new report reveals that thousands of cameras in homes and offices across the U.S. are accessible without proper security protocols, leaving live footage vulnerable to unauthorized viewing. These exposed devices, often […]

DDoS Attacks Cripple Global Banks in New Cyber Siege

Global banks are facing a surge in highly sophisticated distributed denial-of-service campaigns, a recent report warns. These DDoS attacks cripple global financial systems by overwhelming digital infrastructures and disrupting services. According to the report, the scale and complexity of these attacks are growing, making mitigation increasingly difficult for even the most secure institutions. The campaigns […]

Scammers Drain $43K From CoinMarketCap Users

Cybercriminals have exploited Inferno Drainer, a malicious toolkit, to siphon $43,000 from unsuspecting CoinMarketCap users. The attack, which targeted cryptocurrency enthusiasts through phishing links, highlights growing threats in the digital asset space. Scammers drain $43K from CoinMarketCap users by luring victims into connecting their wallets to fraudulent platforms, giving attackers full access to their funds. […]

Nucor Says Hackers Stole Data in Cybersecurity Breach

Nucor, the largest steel producer and recycler in North America, confirmed that hackers breached its systems and stole data in a recent cyberattack. The company disclosed the incident after conducting an internal investigation that revealed unauthorized access to its network. Nucor says hackers stole sensitive information, though it has not yet specified the nature or […]

New York Governor Signs Sweeping Cybersecurity Law

New York Governor Signs a new cybersecurity bill into law, marking a significant step in strengthening digital defenses across the state. The legislation endorses a “whole of government approach,” targeting the growing wave of cyber threats that continue to challenge state and local agencies across the country. Lawmakers designed the measure to align security strategy […]

Ivanti Blames Open-Source Code as Zero-Days Mount

Ivanti is facing growing scrutiny after disclosing another set of zero-day vulnerabilities affecting its products, raising fresh concerns about the security vendor’s ability to shield users from targeted cyberattacks. The company attributed the latest exploits to unresolved security flaws in unnamed open-source libraries, distancing its proprietary code from the breaches. However, some cybersecurity researchers are […]

HPE StoreOnce Flaws Expose Firms to Remote Code Attacks

Hewlett Packard Enterprise (HPE) has patched multiple critical vulnerabilities in its StoreOnce data protection platform that could allow remote code execution, authentication bypass, and unauthorized access to enterprise storage systems. The flaws impact StoreOnce VSA versions prior to 4.3.11 and pose significant risk to backup infrastructure. The most severe issue, CVE-2025-37093, carries a CVSS score […]

Hacker Sells Critical Roundcube Exploit Online

Hackers are actively exploiting a critical vulnerability in Roundcube, an open-source webmail application, exposing users to remote code execution attacks. The flaw, tracked as CVE-2025-49113, allows attackers to run malicious code on targeted servers without authentication. As technical details about the vulnerability have surfaced online, threat actors are now selling exploits on underground forums, increasing […]

North Face Customer Accounts Breached in Cyberattack

Nearly 3,000 customer accounts on The North Face’s website were compromised in a recent cyberattack, the apparel brand’s parent company disclosed in data breach notification letters. The incident involved credential stuffing, a method where attackers use previously obtained usernames and passwords from unrelated breaches to gain unauthorized access to user accounts. The breach adds to […]

Microsoft Outlook Flaw Opens Door to Remote Code Attacks

Microsoft is warning users of a critical vulnerability in Outlook that could allow attackers to execute arbitrary code remotely, despite requiring local access to initiate. Tracked as CVE-2025-47176, the flaw was disclosed on June 10 with a CVSS score of 7.8, rated “Important.” The vulnerability stems from a path traversal issue involving ‘…/…//’ sequences, allowing […]