Spotify music library scraped by pirate activist group and made available as a torrent.
Includes 86M audio files, now circulating in bulk torrents totaling ~300 terabytes.
Spotify is "actively investigating the incident."
Includes 86M audio files, now circulating in bulk torrents totaling ~300 terabytes.
Spotify is "actively investigating the incident."
INTERPOL led a cybercrime sweep across Africa. 574 arrests and $3M recovered after targeting BEC, extortion, and ransomware in 19 countries.
Separately, a Ukrainian Nefilim ransomware affiliate pleaded guilty in the U.S.
Separately, a Ukrainian Nefilim ransomware affiliate pleaded guilty in the U.S.
Purdue University tested deepfake detectors where they actually break: real, compressed social media video.
Not clean demos. Not lab data.
The benchmark shows why false-acceptance rate matters more than accuracy when camera feeds drive access and trust.
Not clean demos. Not lab data.
The benchmark shows why false-acceptance rate matters more than accuracy when camera feeds drive access and trust.
A critical RCE flaw (CVSS 9.9) was found in the n8n workflow automation platform.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
A malicious WhatsApp API package on npm quietly hands attackers full account access.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
Vivaldi, a browser company from Iceland and Norway. We make a browser for all major platforms that's big on privacy and customization. Employee-owned, user-focused, and built for people who want actual control over their browsing 🧰
A truly decentralized Signal alternative messenger app with default E2EE, onion-routed messaging, no phone number or email required, and fully open source clients and servers https://alternativeto.net/software/session/about/ #session
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations
Медицинская лаборатория Гемотест (Gemotest) - 6,341,495 breached accounts.
Nomani investment scams rose 62% in 2025, ESET says.
Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
From a land under siege, we light a candle this Christmas. It is a small flame against a great darkness, a whisper of hope that refuses to be silenced. Our celebration is an act of steadfast faith. May your holidays be filled with true peace.
25/12/25
25/12/25
Fortinet confirms active exploitation of a FortiOS SSL VPN flaw that bypasses 2FA.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CISA added a Digiever NVR bug to its exploited list after confirmed attacks.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
A new MacSync malware variant hit macOS via a signed and notarized app, letting it bypass Apple Gatekeeper.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution.