Venezuela’s state-owned oil company says cyberattack targeted operations, blames US aggression.
Venezuela’s state-owned oil company PDVSA said on Monday that it was targeted by a cyberattack intended to disrupt its operations, describing the incident as part of a broader campaign of external pressure against the country’s energy sector.
Venezuela’s state-owned oil company PDVSA said on Monday that it was targeted by a cyberattack intended to disrupt its operations, describing the incident as part of a broader campaign of external pressure against the country’s energy sector.
Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode): Say hello to Kali Linux 2025.4!
The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release
The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release
The official Kali NetHunter Pro documentation page, which links to the images, is:https://www.kali.org/docs/nethunter-pro/
https://kali.download/nethunter-images/current/
https://kali.download/nethunter-images/current/
Cyber Dispatch™️
Kali Linux 2025.4 Release (Desktop Environments, Wayland & Halloween Mode): Say hello to Kali Linux 2025.4! The summary of the changelog since the 2025.3 https://www.kali.org/blog/kali-linux-2025-4-release
Official download URLUse this full URL in your browser to get Kali Linux 2025.4 (all platforms and images):https://www.kali.org/get-kali/#kali-platforms
Amazon security boss blames Russia's GRU for years-long energy-sector hacks.
SoundCloud confirms breach after member data stolen, VPN access disrupted.
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE.
PayPal closes loophole that let scammers send real emails with fake purchase notices.
Ink Dragon, a China-aligned hacking group, is focusing on European government targets while staying active in Asia and South America.
It exploits SharePoint and IIS flaws to drop web shells and maintain long-term access using ShadowPad and FINALDRAFT malware.
It exploits SharePoint and IIS flaws to drop web shells and maintain long-term access using ShadowPad and FINALDRAFT malware.
Researchers uncover GhostPoster malware hidden in 17 Firefox add-ons with 50,000+ downloads.
Disguised as VPNs, translators, and ad blockers. 50k+ installs.
JavaScript was hidden inside logo images, activated after days, then hijacked links, tracked browsing, and ran ad fraud.
Disguised as VPNs, translators, and ad blockers. 50k+ installs.
JavaScript was hidden inside logo images, activated after days, then hijacked links, tracked browsing, and ran ad fraud.
Amazon flagged a new AWS crypto-mining campaign using custom persistence techniques.
Attackers validate permissions with DryRun, deploy miners across ECS and EC2, then enable instance termination protection to block cleanup.
Attackers validate permissions with DryRun, deploy miners across ECS and EC2, then enable instance termination protection to block cleanup.
A fake NuGet package stole crypto wallets for more than five years.
It copied a popular .NET tracing library and hid as a normal dependency. One extra letter in the author name led to about 2,000 downloads since 2020.
It exfiltrated Stratis wallet JSON files and passwords to a Russian IP.
It copied a popular .NET tracing library and hid as a normal dependency. One extra letter in the author name led to about 2,000 downloads since 2020.
It exfiltrated Stratis wallet JSON files and passwords to a Russian IP.
Amazon confirms a Russian GRU unit hacked Western energy and infrastructure networks for years.
The threat wasn’t malware, it was silent credential theft from live traffic.
From 2021–2025, APT44 relied less on zero-days and more on exposed routers and VPN gateways.
The threat wasn’t malware, it was silent credential theft from live traffic.
From 2021–2025, APT44 relied less on zero-days and more on exposed routers and VPN gateways.
Fortinet FortiGate devices are under active attack via SSO authentication bypass flaws.
CVE-2025-59718 and CVE-2025-59719 both have CVSS scores of 9.8 and exploit the FortiCloud SSO feature.
Disable FortiCloud SSO until systems are fully updated.
CVE-2025-59718 and CVE-2025-59719 both have CVSS scores of 9.8 and exploit the FortiCloud SSO feature.
Disable FortiCloud SSO until systems are fully updated.