A critical security vulnerability in Ivanti Connect Secure VPN appliances has left 2,048 instances worldwide exposed to potential exploitation, with the United States hosting the highest number of vulnerable systems.
The vulnerability tracked as CVE-2025-0282, has been actively exploited since...
A sophisticated credit card skimmer malware had been found hitting WordPress checkout pages, silently injecting malicious JavaScript into database records to obtain sensitive payment details.
Attackers may utilize existing payment fields or inject a fake credit card form to steal...
Microsoft has resolved a persistent issue that caused classic Outlook to freeze or hang when users attempted to copy text using the Ctrl+C shortcut.
The problem, which primarily affected Microsoft 365 customers using Current Channel Version 2409 (Build 18025.20096)...
Critical vulnerabilities in Ecovacs robot vacuums enable hackers to exploit these devices for surveillance and harassment.
The findings, presented at the DEF CON 32 hacking conference by researchers Dennis Giese and Braelynn Luedtke, highlight severe security flaws in Ecovacs' popular...
In a sophisticated phishing campaign, uncovered cybercriminals are exploiting CrowdStrike's recruitment branding to target developers and deploy the XMRig cryptominer.
This deceptive operation leverages fake job offers to lure unsuspecting victims into downloading malicious software disguised as an "employee...
Proton Mail, the renowned privacy-focused email service, experienced a significant global outage today, leaving users worldwide unable to access their email accounts.
The disruption began at approximately 10:00 AM ET, affecting not only Proton Mail but also other Proton services...
The researchers exploited a novel attack vector by hijacking abandoned backdoors within other backdoors, which relied on expired or abandoned infrastructure, such as expired domains.
By acquiring these domains, the researchers gained access to thousands of compromised systems, including those...
Attackers have evolved a sophisticated social engineering scheme to target Middle Eastern banking consumers by posing as government officials and utilizing remote access software to obtain OTP numbers and credit card information.
The fraud primarily targets those who have previously...
The Wireshark Foundation has announced the release of Wireshark 4.4.3, the latest version of the world's most popular network protocol analyzer.
This update brings a host of bug fixes and protocol support improvements, enhancing the tool's capabilities for network...
Ivanti has disclosed actively exploiting a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure VPN appliances.
This vulnerability allows unauthenticated remote code execution and has already been exploited in a limited number of cases.
A second vulnerability, CVE-2025-0283, which enables...