Security
Bitdefender launches free phone number lookup tool to combat scammers
Bitdefender, a cybersecurity company, has launched a free and unlimited “Reverse Phone Lookup” tool that assesses whether unknown numbers are linked to spam or scams.
Read more about Bitdefender launches free phone number lookup tool to combat scammers
Free spy tool can track 3 billion WhatsApp users, drain batteries and data limits
A tool for tracking over three billion WhatsApp and Signal users has been publicly released. Just by knowing the phone number, attackers can determine when users come home, when they are actively using the phone, when they go to sleep, or when they are offline. They can also drain batteries and data limits without the users noticing anything.
Read more about Free spy tool can track 3 billion WhatsApp users, drain batteries and data limits
Fortinet, Ivanti, SAP release urgent patches for critical security vulnerabilities
Cybersecurity and software companies Fortinet, Ivanti, and SAP have all dropped patches to address critical security flaws in their products that could result in an authentication bypass and code execution if successfully exploited.
Read more about Fortinet, Ivanti, SAP release urgent patches for critical security vulnerabilities
Google fixes GeminiJack zero-click exposing corporate Gmail, Calendar invites, shared Docs
A newly uncovered AI injection prompt vulnerability in the Google Gemini enterprise AI ecosystem – allowing attackers to steal sensitive Gmail, Docs, and Calendar data – has been fixed, but experts say it is just the beginning of AI vulnerabilities to come.
Read more about Google fixes GeminiJack zero-click exposing corporate Gmail, Calendar invites, shared Docs
Aeroflot hack explained: report says infrastructure was nearly destroyed
The Bell, an independent Russian news outlet, has published a deep dive into this July’s major hack of Russia’s national airline Aeroflot. It turns out the company’s entire infrastructure was close to collapsing.
Read more about Aeroflot hack explained: report says infrastructure was nearly destroyed
Attackers exploit React2Shell vulnerability to target home CCTV, smart plugs, and TVs
A critical new flaw in React Server Components has unleashed a global wave of automated attacks hammering thousands of smart devices.
Read more about Attackers exploit React2Shell vulnerability to target home CCTV, smart plugs, and TVs
Sudan’s war-shaken aviation sector receives one more blow: hackers claim to be selling internal documents
A hacker claims to have compromised one of Sudan’s few surviving airlines, dumping its internal manuals and security data onto a cybercrime marketplace.
Read more about Sudan’s war-shaken aviation sector receives one more blow: hackers claim to be selling internal documents
4B+ records, including numerous LinkedIn profiles, exposed in one of the largest lead-generation datasets ever found open
What appears to be 16TB of professional and corporate intelligence data includes LinkedIn URLs and profile handles, alongside other personal information.
Read more about 4B+ records, including numerous LinkedIn profiles, exposed in one of the largest lead-generation datasets ever found open
Notepad++ releases emergency patch as hackers exploit updater to deploy malware
Hackers are abusing Notepad++, a popular text and source code editor, to deliver malware. The app’s updater, WinGUp, can be tricked by an attacker-in-the-middle to pull compromised executables from malicious servers. Patches are now available.
Read more about Notepad++ releases emergency patch as hackers exploit updater to deploy malware
New malware on Microsoft Marketplace steals passwords and screenshots of desktops
Some developers thought they were installing a dark theme and an AI assistant on their VS Code. However, it turned out to be malware that stole their data.
Read more about New malware on Microsoft Marketplace steals passwords and screenshots of desktops
Cheap devices from China may come with hidden sensors and hacking tools
Cheap devices for remotely managing hardware can themselves pose a significant security risk. Dr. Matej Kovačič, a security researcher from Slovenia, found that a popular NanoKVM contained a hidden microphone, together with hacking tools and dangerous exploits that would make exploitation trivial.
Read more about Cheap devices from China may come with hidden sensors and hacking tools
Trump prioritizing trade with China over cyber war, Salt Typhoon goes unpunished
The US President wants the world’s fellow autocrats to like him so much that he seems unwilling to allow nuisances such as cyberattacks against America to get in the way. This means that Salt Typhoon, a complex Chinese cyberespionage group, is being given a pass.
Read more about Trump prioritizing trade with China over cyber war, Salt Typhoon goes unpunished
Cursor vulnerable to “catastrophic budget drain:” vibe coder finds a way to spend $1 million
Developers without admin privileges or attackers with limited access can bankrupt smaller companies simply by raising Cursor and AWS Bedrock spending limits, a report by OX Security has revealed.
Read more about Cursor vulnerable to “catastrophic budget drain:” vibe coder finds a way to spend $1 million
Hackers say Volkswagen dealership’s client list is now for sale
Hackers claim to have breached a Volkswagen dealership. The client's data is allegedly up for sale.
Read more about Hackers say Volkswagen dealership’s client list is now for sale
Check Point links US cyberattacks to global crises in new clash warning
Cyberattacks against the United States are no longer isolated events that cause only temporary technical inconvenience. According to Check Point, a cybersecurity company, they’re now mostly coordinated campaigns aimed at weakening Washington.
Read more about Check Point links US cyberattacks to global crises in new clash warning
Infostealers on the rise: time to take action, Australia recommends
The Australian Cyber Security Centre (ACSC) has been tracking and monitoring an increase in activity related to information-stealing malware, also known as infostealers.
Read more about Infostealers on the rise: time to take action, Australia recommends
Compromised Next.js devices weaponized by attackers: thousands remain vulnerable
Security researchers warn that hundreds of already compromised Next.js devices are hitting honeypots, while tens of thousands of servers remain vulnerable to the critical React vulnerability.
Read more about Compromised Next.js devices weaponized by attackers: thousands remain vulnerable
Russian hackers claim looting of secret big tech hardware designs
Everest Ransomware claims to have stolen over 100,000 sensitive engineering files from Benchmark Electronics, potentially exposing the inner workings of some of the world’s most advanced technology manufacturers.
Read more about Russian hackers claim looting of secret big tech hardware designs
US military contractor breach expose employee data
MAG Aerospace, military contractor for the US military in intelligence, surveillance and reconnaissance, suffered a breach exposing its employee data.
Read more about US military contractor breach expose employee data
Attack on the home of Spam exposes details of thousands
A ransomware attack on Minnesota’s Mower County exposed tens of thousands of its residents, the local government organization revealed in a recent breach notice.
Read more about Attack on the home of Spam exposes details of thousands