• GPUHammer: New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs
    Saturday, July 12, 2025 from THN : The Hacker News
    NVIDIA is urging customers to enable System-level Error Correction Codes (ECC) as a defense against a variant of a RowHammer attack demonstrated against its graphics processing units (GPUs). "Risk of successful exploitation from...
  • Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub
    Saturday, July 12, 2025 from THN : The Hacker News
    Cybersecurity researchers have discovered a serious security issue that allows leaked Laravel APP_KEYs to be weaponized to gain remote code execution capabilities on hundreds of applications. "Laravel's APP_KEY, essential for encrypting...
  • Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
    Friday, July 11, 2025 from THN : The Hacker News
    Fortinet has released fixes for a critical security flaw impacting FortiWeb that could enable an unauthenticated attacker to run arbitrary database commands on susceptible instances. Tracked as CVE-2025-25257, the vulnerability carries a...
  • PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
    Friday, July 11, 2025 from THN : The Hacker News
    Cybersecurity researchers have discovered a set of four security flaws in OpenSynergy's BlueSDK Bluetooth stack that, if successfully exploited, could allow remote code execution on millions of transport vehicles from different vendors....
  • MoD supply chain cyber scheme gets up and running
    Friday, July 11, 2025 from ComputerWeekly: IT security
    The Ministry of Defence and IASME have launched a certification scheme for organisations working in the UK defence supply chain, with construction firm Morgan Sindall the first business to achieve compliance.
  • Securing Data in the AI Era
    Friday, July 11, 2025 from THN : The Hacker News
    The 2025 Data Risk Report: Enterprises face potentially serious data loss risks from AI-fueled tools. Adopting a unified, AI-driven approach to data security can help. As businesses increasingly rely on cloud-driven platforms and...
  • Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
    Friday, July 11, 2025 from THN : The Hacker News
    A recently disclosed maximum-severity security flaw impacting the Wing FTP Server has come under active exploitation in the wild, according to Huntress. The vulnerability, tracked as CVE-2025-47812 (CVSS score: 10.0), is a case of...
  • Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
    Friday, July 11, 2025 from THN : The Hacker News
    An Iranian-backed ransomware-as-a-service (RaaS) named Pay2Key has resurfaced in the wake of the Israel-Iran-U.S. conflict last month, offering bigger payouts to cybercriminals who launch attacks against Israel and the U.S. The...
  • CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises
    Friday, July 11, 2025 from THN : The Hacker News
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog, officially confirming the...
  • Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
    Thursday, July 10, 2025 from THN : The Hacker News
    Cybersecurity researchers have discovered a critical vulnerability in the open-source mcp-remote project that could result in the execution of arbitrary operating system (OS) commands. The vulnerability, tracked as CVE-2025-6514, carries...
  • Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
    Thursday, July 10, 2025 from THN : The Hacker News
    Cryptocurrency users are the target of an ongoing social engineering campaign that employs fake startup companies to trick users into downloading malware that can drain digital assets from both Windows and macOS systems. "These malicious...
  • Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods
    Thursday, July 10, 2025 from THN : The Hacker News
    The U.K. National Crime Agency (NCA) on Thursday announced that four people have been arrested in connection with cyber attacks targeting major retailers Marks & Spencer, Co-op, and Harrods. The arrested individuals include two men...
  • Government funding to help SMEs protect their IP
    Thursday, July 10, 2025 from ComputerWeekly: IT security
    Scheme will see SMEs and innovative startups working in sensitive sectors receive advice on enhancing cyber and physical security measures to protect their valuable intellectual property
  • What Security Leaders Need to Know About AI Governance for SaaS
    Thursday, July 10, 2025 from THN : The Hacker News
    Generative AI is not arriving with a bang, it’s slowly creeping into the software that companies already use on a daily basis. Whether it is video conferencing or CRM, vendors are scrambling to integrate AI copilots and assistants into...
  • New ZuRu Malware Variant Targeting Developers via Trojanized Termius macOS App
    Thursday, July 10, 2025 from THN : The Hacker News
    Cybersecurity researchers have discovered new artifacts associated with an Apple macOS malware called ZuRu, which is known to propagate via trojanized versions of legitimate software. SentinelOne, in a new report shared with The Hacker...
  • AMD Warns of New Transient Scheduler Attacks Impacting a Wide Range of CPUs
    Thursday, July 10, 2025 from THN : The Hacker News
    Semiconductor company AMD is warning of a new set of vulnerabilities affecting a broad range of chipsets that could lead to information disclosure. The flaws, collectively called Transient Scheduler Attacks (TSA), manifest in the form of...
  • UK and France forge closer cyber, tech research ties
    Thursday, July 10, 2025 from ComputerWeekly: IT security
    The navigation and timing systems used by power suppliers and emergency services to run their operations will fall in scope of an Anglo-French research pact that will also foster development in AI and supercomputing
  • Four arrested in M&S cyber attack investigation
    Thursday, July 10, 2025 from ComputerWeekly: IT security
    Police have made four arrests in connection with a trio of cyber attacks on UK retailers Marks & Spencer, Co-op and Harrods
  • ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs
    Thursday, July 10, 2025 from THN : The Hacker News
    A high-severity security flaw has been disclosed in ServiceNow's platform that, if successfully exploited, could result in data exposure and exfiltration. The vulnerability, tracked as CVE-2025-3648 (CVSS score: 8.2), has been described...
  • Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to Targets
    Wednesday, July 9, 2025 from THN : The Hacker News
    The Initial Access Broker (IAB) known as Gold Melody has been attributed to a campaign that exploits leaked ASP.NET machine keys to obtain unauthorized access to organizations and peddle that access to other threat actors. The activity...
  • DoNot APT Expands Operations, Targets European Foreign Ministries with LoptikMod Malware
    Wednesday, July 9, 2025 from THN : The Hacker News
    A threat actor with suspected ties to India has been observed targeting a European foreign affairs ministry with malware capable of harvesting sensitive data from compromised hosts. The activity has been attributed by Trellix Advanced...
  • U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme
    Wednesday, July 9, 2025 from THN : The Hacker News
    The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday sanctioned a member of a North Korean hacking group called Andariel for their role in the infamous remote information technology (IT) worker scheme....
  • NAO says government should employ data analytics to tackle fraud
    Wednesday, July 9, 2025 from ComputerWeekly: IT security
    The National Audit Office recommends public bodies share and manage data in a way that prevents fraud and saves taxpayers’ money
  • How To Automate Ticket Creation, Device Identification and Threat Triage With Tines
    Wednesday, July 9, 2025 from THN : The Hacker News
    Run by the team at workflow orchestration and AI platform Tines, the Tines library features over 1,000 pre-built workflows shared by security practitioners from across the community - all free to import and deploy through the platform’s...
  • Chinese Hacker Xu Zewei Arrested for Ties to Silk Typhoon Group and U.S. Cyber Attacks
    Wednesday, July 9, 2025 from THN : The Hacker News
    A Chinese national has been arrested in Milan, Italy, for his alleged links to a state-sponsored hacking group known as Silk Typhoon and for carrying out cyber attacks against American organizations and government agencies. The...
  • Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server
    Wednesday, July 9, 2025 from THN : The Hacker News
    For the first time in 2025, Microsoft's Patch Tuesday updates did not bundle fixes for exploited security vulnerabilities, but the company acknowledged one of the addressed flaws had been publicly known. The patches resolve a whopping...
  • July Patch Tuesday brings over 130 new flaws to address
    Tuesday, July 8, 2025 from ComputerWeekly: IT security
    Microsoft patched well over 100 new common vulnerabilities and exposures on the second Tuesday of the month, but its latest update is mercifully light on zero-days
  • Hackers Use Leaked Shellter Tool License to Spread Lumma Stealer and SectopRAT Malware
    Tuesday, July 8, 2025 from THN : The Hacker News
    In yet another instance of threat actors repurposing legitimate tools for malicious purposes, it has been discovered that hackers are exploiting a popular red teaming tool called Shellter to distribute stealer malware. The company behind...
  • Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play
    Tuesday, July 8, 2025 from THN : The Hacker News
    Cybersecurity researchers have discovered an Android banking malware campaign that has leveraged a trojan named Anatsa to target users in North America using malicious apps published on Google's official app marketplace. The malware,...
  • M&S calls for mandatory ransomware reporting
    Tuesday, July 8, 2025 from ComputerWeekly: IT security
    The government should extend ransomware reporting mandates to businesses to help gather more intelligence and better support victims, says M&S chairman Archie Norman
  • Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension
    Tuesday, July 8, 2025 from THN : The Hacker News
    Cybersecurity researchers have flagged a supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension called Ethcode that has been installed a little over 6,000 times. The compromise, per ReversingLabs, occurred via a...
  • 5 Ways Identity-based Attacks Are Breaching Retail
    Tuesday, July 8, 2025 from THN : The Hacker News
    From overprivileged admin roles to long-forgotten vendor tokens, these attackers are slipping through the cracks of trust and access. Here’s how five retail breaches unfolded, and what they reveal about... In recent months, major...
  • AI for Good: Signal president warns of agentic AI security flaw
    Tuesday, July 8, 2025 from ComputerWeekly: IT security
    Secure by design is a mantra of the tech sector, but not if it’s agentic AI, which wants ‘root’ access to everything
  • RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks
    Tuesday, July 8, 2025 from THN : The Hacker News
    Cybersecurity researchers are calling attention to a malware campaign that's targeting security flaws in TBK digital video recorders (DVRs) and Four-Faith routers to rope the devices into a new botnet called RondoDox. The vulnerabilities...
  • SEC and SolarWinds to settle lawsuit over 2020 breach
    Tuesday, July 8, 2025 from ComputerWeekly: IT security
    The US SEC and SolarWinds have reached a settlement in principle to resolve litigation over alleged security failings that led to the 2020 compromise of the supplier’s Orion platform by Russian cyber spies
  • BaitTrap: Over 17,000 Fake News Websites Caught Fueling Investment Fraud Globally
    Tuesday, July 8, 2025 from THN : The Hacker News
    A newly released report by cybersecurity firm CTM360 reveals a large-scale scam operation utilizing fake news websites—known as Baiting News Sites (BNS)—to deceive users into online investment fraud across 50 countries. These...
  • What is the domain name system (DNS)?
    Tuesday, July 8, 2025 from ComputerWeekly: IT security
    The domain name system (DNS) is a naming database in which internet domain names are located and translated into Internet Protocol (IP) addresses.
  • Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms
    Tuesday, July 8, 2025 from THN : The Hacker News
    Russian organizations have been targeted as part of an ongoing campaign that delivers a previously undocumented Windows spyware called Batavia. The activity, per cybersecurity vendor Kaspersky, has been active since July 2024. "The...
  • CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation
    Tuesday, July 8, 2025 from THN : The Hacker News
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of flaws is as...
  • SEO Poisoning Campaign Targets 8,500+ SMB Users with Malware Disguised as AI Tools
    Monday, July 7, 2025 from THN : The Hacker News
    Cybersecurity researchers have disclosed a malicious campaign that leverages search engine optimization (SEO) poisoning techniques to deliver a known malware loader called Oyster (aka Broomstick or CleanUpLoader). The malvertising...
  • ⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and More
    Monday, July 7, 2025 from THN : The Hacker News
    Everything feels secure—until one small thing slips through. Even strong systems can break if a simple check is missed or a trusted tool is misused. Most threats don’t start with alarms—they sneak in through the little things we...
  • Manufacturing Security: Why Default Passwords Must Go
    Monday, July 7, 2025 from THN : The Hacker News
    If you didn't hear about Iranian hackers breaching US water facilities, it's because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn't its scale, but how easily the...
  • Gartner’s view on AI security: A Computer Weekly Downtime Upload podcast
    Monday, July 7, 2025 from ComputerWeekly: IT security
    We speaker to Gartner's Nader Heinen about why access control should be built into enterprise AI
  • TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail Sectors
    Monday, July 7, 2025 from THN : The Hacker News
    A hacking group with ties other than Pakistan has been found targeting Indian government organizations with a modified variant of a remote access trojan (RAT) called DRAT. The activity has been attributed by Recorded Future's Insikt...
  • Taiwan NSB Alerts Public on Data Risks from Douyin, Weibo, and RedNote Over China Ties
    Saturday, July 5, 2025 from THN : The Hacker News
    Taiwan's National Security Bureau (NSB) has warned that China-developed applications like RedNote (aka Xiaohongshu), Weibo, Douyin, WeChat, and Baidu Cloud pose security risks due to excessive data collection and data transfer to China....
  • Alert: Exposed JDWP Interfaces Lead to Crypto Mining, Hpingbot Targets SSH for DDoS
    Saturday, July 5, 2025 from THN : The Hacker News
    Threat actors are weaponizing exposed Java Debug Wire Protocol (JDWP) interfaces to obtain code execution capabilities and deploy cryptocurrency miners on compromised hosts. "The attacker used a modified version of XMRig with a...
  • NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech Sectors
    Friday, July 4, 2025 from THN : The Hacker News
    Cybersecurity researchers have shed light on a previously undocumented threat actor called NightEagle (aka APT-Q-95) that has been observed targeting Microsoft Exchange servers as a part of a zero-day exploit chain designed to target...
  • From the FBI to F&A: lessons learnt in safeguarding systems and data
    Friday, July 4, 2025 from ComputerWeekly: IT security
    One chief information security officer shares her experience of marshalling what she learned at the FBI for business security, with a particular focus on finance and accounting
  • Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It
    Friday, July 4, 2025 from THN : The Hacker News
    Generative AI is changing how businesses work, learn, and innovate. But beneath the surface, something dangerous is happening. AI agents and custom GenAI workflows are creating new, hidden ways for sensitive enterprise data to leak—and...
  • Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
    Friday, July 4, 2025 from THN : The Hacker News
    Cybersecurity researchers have disclosed two security flaws in the Sudo command-line utility for Linux and Unix-like operating systems that could enable local attackers to escalate their privileges to root on susceptible machines. A...
  • Powered by Feed Informer