Topic: cybersecurity threat
-
14,000+ F5 BIG-IP APM Systems Vulnerable to RCE Attacks
A critical remote code execution vulnerability (CVE-2025-53521) in F5 BIG-IP APM systems is being actively exploited, with over 14,000 vulnerable instances exposed online. The U.S. CISA mandated federal agencies to patch by a recent deadline, but the high number of exposed systems indicates many ...
Read More » -
New .elock Ransomware Spreads with !README_RECOVER.txt Note
The new .elock ransomware variant targets Linux infrastructure by encrypting critical systems like Zimbra mail databases and spreading via a deceptive note file. Attackers threaten to publish exfiltrated sensitive data on dark web leak sites if victims do not pay a 50 XMR ransom within 72 hours, ...
Read More » -
New AI Worm Poses a Potentially Unstoppable Cyber Threat
Researchers have introduced an AI-powered computer worm that autonomously spreads and adapts in real time, representing a "fundamentally new threat" to cybersecurity. Unlike traditional malware, this worm uses generative AI to rewrite its attack strategies, evade detection, and craft convincing p...
Read More » -
Critical RCE Bug Threatens PTC Windchill and FlexPLM Users
A critical, unauthenticated remote code execution vulnerability (CVE-2024-xxxx) has been identified in PTC's Windchill and FlexPLM software, posing a severe security risk. Successful exploitation could allow attackers to steal intellectual property, tamper with critical product data, or deploy ra...
Read More » -
Oracle Patches Critical RCE Flaw in Identity Manager
Oracle has issued an urgent patch for a critical, easily exploitable flaw (CVE-2026-21992) in its Identity Manager and Web Services Manager products, advising immediate action. The vulnerability allows unauthenticated attackers to achieve remote code execution via network protocols by exploiting ...
Read More » -
149 Million Login Credentials Leaked in Database Breach
A massive, publicly accessible database containing nearly 149 million stolen login credentials—including 48 million for Gmail—was discovered and taken offline, highlighting the persistent threat of unsecured data troves. The database, found by a security researcher, was highly organized and conta...
Read More » -
Rockstar Games data stolen in extortion leak
A data breach at third-party vendor Anodot has compromised Rockstar Games, with the stolen information published online by the ShinyHunters extortion gang. The incident highlights the critical vulnerability of digital supply chains and the double-extortion tactic used by cybercriminals to pressur...
Read More » -
Windows Zero-Day "BlueHammer" Leaked by Researcher
A security researcher has publicly released exploit code for a new, unpatched privilege escalation vulnerability in Windows. The flaw allows attackers to gain the highest system-level permissions, turning a limited breach into a full system takeover. The disclosure before a Microsoft patch is ava...
Read More » -
Hackers exploit critical Gitea Docker auth bypass
Hackers are actively exploiting a critical authentication bypass vulnerability (CVE-2023-XXXXX) in the official Docker image for Gitea, allowing attackers to impersonate any user, including administrators, and gain full control over repositories and sensitive data. Active exploitation attempts ta...
Read More » -
Critical SimpleHelp RMM bug CVE-2026-48558 exposes endpoints to takeover
A critical unauthenticated vulnerability (CVE-2026-48558) in the SimpleHelp RMM platform allows attackers to remotely create a "Technician" account, enabling full control over managed networks and endpoints. The flaw requires no authentication or user interaction, and due to SimpleHelp's deep sys...
Read More »