A critical RCE flaw (CVSS 9.9) was found in the n8n workflow automation platform.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
A malicious WhatsApp API package on npm quietly hands attackers full account access.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
Vivaldi, a browser company from Iceland and Norway. We make a browser for all major platforms that's big on privacy and customization. Employee-owned, user-focused, and built for people who want actual control over their browsing 🧰
A truly decentralized Signal alternative messenger app with default E2EE, onion-routed messaging, no phone number or email required, and fully open source clients and servers https://alternativeto.net/software/session/about/ #session
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations
Медицинская лаборатория Гемотест (Gemotest) - 6,341,495 breached accounts.
Nomani investment scams rose 62% in 2025, ESET says.
Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
Campaigns now run on YouTube as well as Facebook, pushing fake returns with AI-made videos.
64,000+ scam URLs were blocked this year.
From a land under siege, we light a candle this Christmas. It is a small flame against a great darkness, a whisper of hope that refuses to be silenced. Our celebration is an act of steadfast faith. May your holidays be filled with true peace.
25/12/25
25/12/25
Fortinet confirms active exploitation of a FortiOS SSL VPN flaw that bypasses 2FA.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CISA added a Digiever NVR bug to its exploited list after confirmed attacks.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
A new MacSync malware variant hit macOS via a signed and notarized app, letting it bypass Apple Gatekeeper.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution.
Ten former Samsung employees arrested for industrial espionage charges for giving China chipmaker 10nm tech — executives and researchers allegedly leaked DRAM technology to China-based CXMT, resulting in trillions of losses in Korean Won.