Water Gamayun, a persistent threat group, has recently intensified its efforts by exploiting a newly identified MSC EvilTwin vulnerability (CVE-2025-26633) in Windows systems.
India has asked all smartphone makers to preload all new devices with a state-owned cyber security app that cannot be deleted.
Not all "E2E" encryption claims are equal.
Big Tech loves to sell privacy snake oil by claiming encryption and privacy, when in reality they hold the master key and can access your data on a whim. - Cyber Dispatch
Big Tech loves to sell privacy snake oil by claiming encryption and privacy, when in reality they hold the master key and can access your data on a whim. - Cyber Dispatch
Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild.
French Football Federation faces own-goal after club software data breach.
Google deletes X post after getting caught using a ‘stolen’ AI recipe infographic.
Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware.
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control.
Swiss government says give M365, and all SaaS, a miss as it lacks end-to-end encryption.
Hackers are attacking Israeli networks with a new tool called MuddyViper.
The group MuddyWater used fake emails and VPN bugs to break into systems in tech, transport, and utilities.
MuddyViper can steal passwords, browser data, and control infected computers — while pretending to be the Snake game.
The group MuddyWater used fake emails and VPN bugs to break into systems in tech, transport, and utilities.
MuddyViper can steal passwords, browser data, and control infected computers — while pretending to be the Snake game.
Google just fixed 107 security flaws in Android — including two that hackers already used in real attacks.
The exploited bugs (CVE-2025-48633 & CVE-2025-48572) affect the Android Framework and could expose data or give attackers higher access.
The exploited bugs (CVE-2025-48633 & CVE-2025-48572) affect the Android Framework and could expose data or give attackers higher access.
ShadyPanda quietly turned trusted Chrome and Edge extensions into spyware.
Over 4.3 million installs in 7 years — some were even once verified by Google.
After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.
Over 4.3 million installs in 7 years — some were even once verified by Google.
After silent updates in mid-2024, they began sending users’ browsing data and cookies to remote servers.
Tomiris is back — and harder to spot.
Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.
Its new malware — written in Python, Rust, Go, PowerShell & C#.
Kaspersky reports the group is using Telegram & Discord as C2 servers to hide attacks on government networks in Russia & Central Asia.
Its new malware — written in Python, Rust, Go, PowerShell & C#.