Singapore CSA warns of maximun severity SmarterMail RCE flaw

2 months ago

Singapore’s CSA warns of CVE-2025-52691, a critical SmarterMail flaw enabling unauthenticated remote code execution via arbitrary file upload. Singapore’s Cyber…

MongoBleed (CVE-2025-14847): the US, China, and the EU are among the top exploited GEOs<gwmw style="display:none;"></gwmw>

2 months ago

MongoBleed (CVE-2025-14847) lets attackers remotely leak memory from unpatched MongoDB servers using zlib compression, without authentication. A critical vulnerability, CVE-2025-14847…

Coupang announces $1.17B compensation plan for 33.7M data breach victims

2 months ago

Coupang will spend about $1.17B to compensate 33.7 million users affected by a data breach, providing purchase vouchers to those…

Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver

2 months ago

China-linked APT Mustang Panda used a signed kernel-mode rootkit driver to load shellcode and deploy its ToneShell backdoor. China-linked APT…

Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems

2 months ago

A Lithuanian national was arrested for allegedly spreading KMSAuto malware that stole clipboard data and infected 2.8 million Windows and…

U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog<gwmw style="display:none;"></gwmw>

2 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a MongoDB Server flaw to its Known Exploited Vulnerabilities catalog. The U.S.…

Romania’s Oltenia Energy Complex suffers major ransomware attack

2 months ago

A ransomware attack hit Romania’s Oltenia Energy Complex on December 26, knocking out IT systems at the country’s largest coal…

Korean Air discloses data breach after the hack of its catering and duty-free supplier

2 months ago

Korean Air employee discloses a data breach after a hack of its catering and duty-free supplier, KC&D, affecting thousands of…

MongoBleed flaw actively exploited in attacks in the wild

2 months ago

A recently disclosed MongoDB flaw (MongoBleed) is under active exploitation, with over 87,000 potentially vulnerable instances exposed worldwide. A newly…

Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor

2 months ago

China-linked APT Evasive Panda used DNS poisoning to deliver the MgBot backdoor in targeted cyber-espionage attacks in Türkiye, China, and…

This website uses cookies.