Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading.
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto.
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion.
SmarterMail flaw is under active attack within 48 hours of patching.
The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.
Activity points to patch reverse-engineering.
The bug lets attackers bypass auth, reset the admin password, then abuse built-in admin features to run OS commands as SYSTEM.
Activity points to patch reverse-engineering.
After X opened up its algorithm, users discovered that those criticizing Israel were massively censored and had their reach reduced by 90%.
The entire algorithm is now based on whether or not the user criticizes Israel.
The entire algorithm is now based on whether or not the user criticizes Israel.
Fortinet confirms active exploitation of CVE-2025-59718 / 59719, allowing FortiGate FortiCloud SSO bypass — even on fully patched devices.
Attackers abuse crafted SAML logins to gain admin access, add persistent accounts, enable VPN, and steal configs. Disabling FortiCloud SSO is advised.
Attackers abuse crafted SAML logins to gain admin access, add persistent accounts, enable VPN, and steal configs. Disabling FortiCloud SSO is advised.
Attackers are abusing trusted IT tools, not deploying malware.
A new campaign steals email logins, then installs legitimate RMM software for silent, long-term access.
Because the tools are signed and allowed, many security controls don’t trigger.
A new campaign steals email logins, then installs legitimate RMM software for silent, long-term access.
Because the tools are signed and allowed, many security controls don’t trigger.
Email is still the easiest way in.
In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
In Google Workspace, BEC attacks often carry no links or malware, so native defenses miss them. One compromised inbox can expose years of sensitive email and files.
Fortinet FortiGate under automated SSO abuse.
Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
Attackers exploit CVE-2025-59718/59719 to add admin users, enable VPN access, and export firewall configs within seconds, per Arctic Wolf.
RCE flaws found in widely used AI Python libraries.
Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.
These tools power popular AI models. Patches are out, no active exploitation seen yet.
Researchers report bugs in Apple FlexTok, NVIDIA NeMo, and Salesforce Uni2TS that trigger when malicious model metadata is loaded.
These tools power popular AI models. Patches are out, no active exploitation seen yet.
Spain’s court probe into the hacking of the prime minister’s phone with Pegasus spyware has collapsed after Government of Israel refused to cooperate.
By blocking judicial assistance, Israel effectively shielded NSO Group, whose Pegasus spyware has been used to target politicians, journalists, and activists worldwide
By blocking judicial assistance, Israel effectively shielded NSO Group, whose Pegasus spyware has been used to target politicians, journalists, and activists worldwide