Latest Articles

Malicious Twitch Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

A browser extension marketed as a Twitch enhancement tool has been found forwarding live OAuth session tokens belonging to more than 30,000 users to proxy...

Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution

A critical vulnerability in vBulletin lets unauthenticated remote attackers execute arbitrary PHP code on a vulnerable forum server, creating a direct path to server compromise....

WhatsApp Tests Restricted Chat Feature to Block Linked Devices From Accessing Private Conversations

WhatsApp has introduced a new privacy control called Restricted Chat for Android that keeps selected conversations accessible only on a user’s primary mobile device, blocking...

Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials

A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal...

GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push

GitHub has reportedly awarded a $100,000 bug bounty to security researcher Saif Ghani for identifying a critical remote code execution vulnerability that could be triggered...

Critical Check Point VPN Flaws Could Face Large-Scale Exploitation, NCSC Warns

The Netherlands’ National Cyber Security Center (NCSC) has warned organizations to urgently patch two critical vulnerabilities in Check Point VPN products, saying widespread exploitation attempts...

Revolut Data Breach Exposes Passport Copies, KYC Selfies and Full Transaction Histories

Revolut has disclosed a data-security incident in which sensitive customer information was released after the fintech company responded to a fraudulent request masquerading as a...

Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials

A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage malware, and steal browser credentials. According to...

Cyber Attack News

Threats

Peer2Profit AstroProxy Residential Proxy Network Exposes Internal Network Resources

Residential proxy networks are often hard for security teams to detect, but new research shows they can create serious enterprise risks. Silent Push found that PEER2PROFIT, a bandwidth-sharing application,...

New C++ Abyssos RAT Gives Attackers Remote Shell, VNC and File-System Control

Security researchers have identified a new modular remote access trojan (RAT) named Abyssos, a C++ malware family that gives attackers broad control over infected Windows systems. Zscaler ThreatLabz first observed...

Vulnerabilities