Category: Information Security
Researchers at Wordfence Threat Intelligence have uncovered a large-scale campaign involving the use of so-called “nulled plugins”—pirated copies of premium WordPress extensions that have been tampered with by third parties. These counterfeit packages have...
Cybercriminal groups have begun exploiting a new phishing service, VoidProxy, on a massive scale, enabling them to steal credentials, multi-factor authentication codes, and session tokens from Microsoft and Google accounts in real time. According...
According to declassified documents, U.S. Immigration and Customs Enforcement (ICE) employed the so-called Stingray device—technology that mimics the function of a cellular base station. When a phone connects to this “false” transmitter, it inadvertently...
SAP has addressed two critical vulnerabilities in the NetWeaver Java application server that could allow attackers to execute arbitrary code and fully compromise affected systems. The security updates, released in September 2025, remediate CVE-2025-42922...
Researchers at ETH Zurich have unveiled a novel attack dubbed VMScape, bearing strong resemblance to Spectre and posing a significant threat to virtualization infrastructures. The attack enables a malicious virtual machine to extract cryptographic...
Researchers from Cybernews have reported a major data breach involving Vyro AI, a company renowned for its popular generative applications on Android and iOS. An unsecured Elasticsearch server belonging to the developer had been...
Researchers at Palo Alto Networks have reported a surge in attacks leveraging the open-source platform AdaptixC2, originally designed for penetration testing but now increasingly exploited by cybercriminals. Unit 42 specialists first detected traces of...
An unusual incident unfolded at the Spinoza campus in Amsterdam: an unknown intruder hacked into the digital payment system of five washing machines. For several weeks, students were able to use the machines free...
The UK’s Information Commissioner’s Office (ICO) has raised alarm over a troubling trend: schoolchildren are increasingly responsible for cyberattacks and data breaches within educational institutions. An analysis of 215 incidents recorded between January 2022...
A European DDoS mitigation provider has been struck by an unprecedented attack, with traffic volumes peaking at 1.5 billion packets per second. The massive wave originated from thousands of compromised IoT devices and MikroTik...
Researchers at Oligo Security have uncovered a vulnerability in Apple CarPlay that enables remote code execution with root privileges, granting attackers full control over a vehicle’s multimedia system. The flaw, registered as CVE-2025-24132, resides...
Two Kenyan documentary filmmakers have come under surveillance by state security services for their work on a film about youth-led protests. Digital forensics experts revealed that their phones had been infected with the spyware...