ClayRat campaign uses Telegram and phishing sites to distribute Android spyware

2 months ago

ClayRat Android spyware targets Russian users via fake Telegram channels and phishing sites posing as popular apps like WhatsApp and…

CVE-2025-5947: WordPress Plugin flaw lets hackers access Admin accounts

2 months ago

Threat actors are exploiting a critical flaw, tracked as CVE-2025-5947, in the Service Finder WordPress theme’s Bookings plugin. Threat actors…

Threat actors steal firewall configs, impacting all SonicWall Cloud Backup users

2 months ago

All SonicWall Cloud Backup users were impacted after hackers stole firewall configuration files from the MySonicWall service in early September.…

Discord denies massive breach, confirms limited exposure of 70K ID photos<gwmw style="display:none;"></gwmw>

2 months ago

Discord won’t pay threat actors claiming 5.5M user breach, saying only about 70K ID photos were actually exposed. Discord announced…

Qilin ransomware claimed responsibility for the attack on the beer giant Asahi

2 months ago

Qilin ransomware claimed responsibility for the recent attack on the beer giant Asahi that disrupted operations in Japan. Asahi Group…

DragonForce, LockBit, and Qilin, a new triad aims to dominate the ransomware landscape

2 months ago

DragonForce, LockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat…

DraftKings thwarts credential stuffing attack, but urges password reset and MFA

2 months ago

DraftKings warns of credential stuffing using stolen logins; No evidence of data loss, but users must reset passwords and enable…

Redis patches 13-Year-Old Lua flaw enabling Remote Code Execution

2 months ago

Redis warns of CVE-2025-49844, a Lua script flaw enabling RCE via use-after-free. Attackers need authenticated access to exploit it. Redis…

U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

2 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The…

GoAnywhere MFT zero-day used by Storm-1175 in Medusa ransomware campaigns

2 months ago

Storm-1175 exploits GoAnywhere MFT flaw CVE-2025-10035 in Medusa attacks, allowing easy remote code execution via License Servlet bug. A cybercrime…

This website uses cookies.