cybersecurity threat

AI & Tech

First Android Malware Using Generative AI Discovered

A novel Android malware called "PromptSpy" is the first to use generative AI, specifically Google's Gemini, to automate on-screen navigation…

Read More »
Business

Millions at Risk as Social Security Numbers Exposed

Cybersecurity researchers discovered an unsecured database containing billions of sensitive records, including email addresses, passwords, and Social Security numbers, highlighting…

Read More »
Business

Operation DoppelBrand: How Hackers Hijack Trusted Brands to Steal Your Data

A sophisticated phishing campaign dubbed Operation DoppelBrand, linked to threat actor GS7, is using highly convincing fake websites to impersonate…

Read More »
BigTech Companies

Beware: Fake 7-Zip Site Pushes Malware-Laden Installer

A fraudulent website impersonating the official 7-Zip software distributes a trojanized installer that secretly enrolls the victim's computer into a…

Read More »
Business

New “Vect” RaaS Variant Poses Critical Threat, Researchers Warn

A new, highly sophisticated ransomware-as-a-service operation named **Vect** is rapidly emerging, posing a critical threat by targeting organizations and actively…

Read More »
BigTech Companies

Russian Hackers Attack Using New Microsoft Office Bug

Russian state-backed hackers (APT28/Fancy Bear) are actively exploiting a patched Microsoft Office vulnerability (CVE-2026-21509) in targeted attacks against Ukrainian and…

Read More »
Business

6,000+ SmarterMail Servers Vulnerable to Hijacking

A critical authentication bypass vulnerability (CVE-2026-23760) in SmarterMail email servers allows attackers to reset administrator passwords and take full control…

Read More »
BigTech Companies

WinRAR Path Flaw Still Actively Exploited by Hackers

A critical path traversal vulnerability (CVE-2025-8088) in WinRAR allows attackers to hide malicious files in archives and place them in…

Read More »
Artificial Intelligence

Microsoft Copilot Hijacked in Reprompt Attack for Data Theft

The "Reprompt" attack is a cybersecurity threat that allows attackers to hijack a user's Microsoft Copilot session via a malicious…

Read More »
Artificial Intelligence

Chrome Extensions Stole ChatGPT & DeepSeek Data from 900K Users

Malicious Chrome extensions, posing as legitimate AI tools, stole private conversations and browsing data from over 900,000 users by secretly…

Read More »
Business

VVS Stealer Malware Hijacks Discord Accounts Using Python

A new, affordable Python-based malware called **VVS Stealer** is actively compromising Discord accounts by stealing tokens and data, using obfuscation…

Read More »
Business

Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

A critical five-year-old Fortinet firewall flaw (CVE-2020-12812) allows attackers to bypass two-factor authentication by altering a username's case, and over…

Read More »
AI & Tech

Beware: Google Ads Push Malware via Fake ChatGPT, Grok Guides

A new malware campaign called "ClickFix" uses Google Ads impersonating AI platform guides to distribute the AMOS infostealer, tricking users…

Read More »
BigTech Companies

Beware Malicious VS Code Extensions Stealing Data

Malicious extensions named Bitcoin Black and Codo AI were discovered on the VS Code marketplace, using social engineering and functional…

Read More »
Business

Inside DragonForce Ransomware and Scattered Spider

The DragonForce ransomware operation has evolved into a "cartel" model, offering affiliates high profit shares to scale its impact, and…

Read More »
Cybersecurity

RondoDox Botnet Exploits Critical XWiki Server Flaw

The RondoDox botnet malware is actively exploiting a critical remote code execution vulnerability (CVE-2025-24893) in XWiki Platform, as confirmed by…

Read More »
BigTech Companies

Google: Microsoft WSUS Attacks Strike Multiple Organizations

A critical remote code execution vulnerability (CVE-2025-59287) in Microsoft's WSUS is being actively exploited, affecting Windows Server versions from 2012…

Read More »
Business

Hackers Exploit Critical Oracle Flaw, CISA Confirms

CISA has added the critical Oracle E-Business Suite vulnerability CVE-2025-61884 to its Known Exploited Vulnerabilities catalog, confirming active exploitation and…

Read More »
BigTech Companies

Barracuda Exposes Stealthy Microsoft 365 Phishing Kit

Whisper 2FA is a sophisticated phishing-as-a-service platform that has compromised nearly one million Microsoft 365 accounts by stealing login credentials…

Read More »
Business

Nation-State Hackers Breach F5, Endangering Thousands of Customers

A nation-state hacking group infiltrated F5's networks, compromising thousands of organizations, including US government agencies and Fortune 500 companies, posing…

Read More »