Skip to main content
← All Tags

Cyber Security

75 articles in this category (Page 2 of 4)

AI NewsCyber SecurityAI Ethics

Five 2025 Web Security Threats Redefining Cyber Defense

AI-driven attacks and supply chain breaches in 2025 forced a 156% surge in malicious packages and 70% cookie non-compliance, reshaping web security protocols.

Read more
AI NewsCyber SecuritySoftware Vulnerability

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

39% of cloud environments face unauthenticated RCE risks from React/Next.js RSC flaws (CVE-2025-55182, CVSS 10.0).

Read more
AI NewsCyber SecurityWordPress

WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

Critical WordPress plugin flaw (CVE-2025-8489, CVSS 9.8) allows unauthenticated admin account creation, with 48,400+ exploit attempts blocked by Wordfence.

Read more
AI NewsCyber SecuritySoftware Vulnerability

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Malicious npm package with 18,988 downloads evades AI security tools using deceptive prompts.

Read more
AI NewsCyber SecuritySoftware Vulnerability

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

Grafana addresses a critical CVSS 10.0 vulnerability in SCIM allowing user impersonation and privilege escalation in versions 12.x.

Read more
AI NewsCyber SecurityWhatsApp

CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat

Thousands of malicious URLs drive WhatsApp account hijacking via session theft and social engineering, per CTM360's 2025 report.

Read more
AI NewsCyber SecurityThreat Intelligence

Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

Iranian threat actors used cyber operations, including mapping ship AIS data, to support a failed missile strike, demonstrating ‘cyber-enabled kinetic targeting’.

Read more
AI NewsCyber SecurityZero Trust

Ringfencing: Securing Trusted Applications Against Weaponization

Ringfencing reduces SOC alerts by up to 90% by containing trusted applications.

Read more
AI NewsCyber SecuritySoftware Development

Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time

Google reports Android memory safety bugs fall below 20% due to Rust adoption, marking a 1000x reduction in vulnerability density.

Read more
AI NewsCyber SecurityNetwork Security

CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks

CISA warns 54,300+ WatchGuard firewalls risk remote code execution via CVE-2025-9242, with patches due by December 3.

Read more
AI NewsCyber SecurityNetwork Security

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Amazon detects zero-day exploits in Cisco ISE (CVE-2025-20337, CVSS 10.0) and Citrix ADC (CVE-2025-5777, CVSS 9.3) used to deploy custom malware.

Read more
AI NewsCyber SecurityAI Ethics

Google Launches 'Private AI Compute' — Secure AI Processing with On-Device-Level Privacy

Google’s Private AI Compute enables encrypted AI processing in the cloud with zero-access privacy, leveraging AMD-based TEEs and Gemini models.

Read more
AI NewsCyber SecurityVulnerability Management

Microsoft Patches 63 Security Flaws, Including Critical Windows Kernel Zero-Day Under Active Attack

Microsoft patches 63 security flaws, including a critical Windows Kernel zero-day under active exploitation (CVE-2025-62215).

Read more
AI NewsCyber SecurityWebinar

Dynamic Attack Surface Reduction (DASR): A Smarter Way to Stay Safe

Bitdefender's DASR automates real-time risk reduction, closing security gaps before attackers exploit them.

Read more
AI NewsCyber SecurityData Breach

Enterprise Credentials at Risk: The Lifecycle and Impact of Stolen Login Data

Stolen enterprise credentials, sold for as little as $15, enable ransomware, data theft, and significant financial losses. This article explores the lifecycle of credential compromise, common attack vectors, and mitigation strategies.

Read more
AI NewsCyber SecurityEspionage

China-Linked Hackers Exploit Legacy Vulnerabilities for Global Espionage Campaigns

A China-linked threat actor exploited multiple CVEs in April 2025 to target a U.S. non-profit organization, establishing long-term persistence. Other Chinese hacking groups have also launched campaigns across global sectors using advanced techniques like AitM attacks and IIS server compromises.

Read more
AI NewsCyber SecurityVulnerability Exploits

Samsung Zero-Day Flaw Exploited to Deploy LANDFALL Android Spyware in Middle East

A critical Samsung Galaxy vulnerability (CVE-2025-21042) was exploited as a zero-day to deploy the LANDFALL spyware via WhatsApp images, targeting users in the Middle East before a patch in April 2025.

Read more
AI NewsCyber SecuritySoftware Vulnerability

AI-Driven Malware Exploits Open-Source Trust: VS Code Extension and npm Packages

A malicious VS Code extension with ransomware capabilities and 17 npm packages distributing Vidar Infostealer highlight AI's role in modern supply chain attacks, exploiting open-source ecosystems.

Read more
AI NewsCyber SecurityNetwork Security

Cisco Warns of Critical Firewall Vulnerabilities Exploited in Zero-Day Attacks

Cisco has disclosed new firewall vulnerabilities (CVE-2025-20333 and CVE-2025-20362) exploited as zero-days, enabling denial-of-service attacks and unauthorized access. Learn about the risks and recommended mitigations.

Read more
AI NewsCyber SecurityData Breach

SonicWall Confirms State-Sponsored Hackers Behind September Cloud Backup Breach

SonicWall attributes a cloud backup breach to state-sponsored hackers, exposing under 5% of users’ firewall data.

Read more
AI NewsCyber SecuritySoftware Vulnerability

CISA Adds Gladinet and CWP Vulnerabilities to KEV Catalog Amid Active Exploitation

CISA has added critical vulnerabilities in Gladinet, CWP, and WordPress plugins to its KEV catalog, emphasizing urgent patching due to active exploitation in the wild.

Read more
AI NewsCyber SecurityMalware Analysis

Google Discovers PROMPTFLUX Malware Leveraging Gemini AI for Evasion

Google identifies PROMPTFLUX, a VB Script malware using Gemini AI to rewrite its code hourly for evasion, highlighting rising AI-driven cyber threats and misuse of large language models.

Read more
AI NewsCyber SecurityEnterprise Mobility

Securing the Open Android Ecosystem with Samsung Knox

Debunks the myth that Android isn't secure by highlighting Samsung Knox's role in enterprise security through hardware-software integration and proactive threat management.

Read more
AI Newscyber securitythreat intelligence

Why SOC Burnout Can Be Avoided: Practical Steps

Discover how SOC teams can prevent burnout through real-time analysis, automation, and threat intelligence integration, achieving 3× efficiency and reducing workload by 20%.

Read more