IBM discloses critical CVE-2025-13915 vulnerability in API Connect allowing potential remote authentication bypass. Users are advised to apply interim fixes immediately.
Trust Wallet reveals Shai-Hulud supply chain attack compromised Chrome extension, stealing $8.5 million in crypto assets from 2,520 wallets. Users urged to update to version 2.69.
TRM Labs finds stolen encrypted vaults from the 2022 LastPass breach are still being cracked in 2025, enabling crypto theft linked to Russian cybercriminal exchanges.
Researchers uncover a new MacSync macOS stealer variant distributed via a signed and notarized Swift app, abusing Apple trust mechanisms to evade Gatekeeper and deliver malware.
Nomani fraudulent investment scheme surged 62% in 2025, leveraging AI-generated deepfakes and social media ads to target users globally. ESET highlights evolving tactics and law enforcement impact.
Small and medium-sized businesses faced increased cyberattacks in 2025, with millions of records exposed. Experts advise stronger authentication, access control, and secure data storage to reduce breach risks in 2026.
Researchers uncover renewed activity from Iranian threat actor Infy, also known as Prince of Persia, revealing updated malware, resilient C2 infrastructure, and expanded global targeting.
QiAnXin XLab reports Kimwolf botnet has compromised 1.8 million Android-based TVs, set-top boxes, and tablets, executing billions of DDoS commands and leveraging ENS infrastructure.
GhostPoster malware used 17 Mozilla Firefox add-ons to execute affiliate link hijacking, ad fraud, tracking injection, and remote code execution, affecting over 50,000 users.
CISA adds CVE-2018-4063 affecting Sierra Wireless AirLink routers to its KEV catalog after reports of active exploitation targeting industrial and OT environments.
Researchers uncover that Urban VPN browser extension silently collected AI chatbot prompts and responses from millions of users across ChatGPT, Claude, Copilot, Gemini, and other platforms.