Cybersecurity News

Burp Suite Supercharges Its Scanning Capabilities With React2Shell Vulnerability Detection

PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version 2.0.9, released on December 16,…

3 months ago

Malicious MCP Servers Enable New Prompt Injection Attack To Drain Resources

Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol (MCP) sampling feature used in…

3 months ago

Law Enforcement Detains Hackers Equipped With Specialized Flipper Hacking Tools

Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of advanced hacking equipment that could…

3 months ago

Hackers Abuse AWS IAM Eventual Consistency To Maintain Persistent Access

Attackers can keep access to AWS accounts even after admins delete compromised keys. New research from OffensAI shows how AWS…

3 months ago

Hundreds Of Porsche Cars Rendered Inoperable After Satellite Security System Failure

Owners of hundreds of Porsche cars in Russia cannot drive their vehicles after a significant failure in the factory-installed satellite…

3 months ago

Next.js Unveils Scanner To Detect and Patch Apps Vulnerable To react2shell

Vercel has released a new command-line tool, fix-react2shell-next, to help developers quickly detect and patch CVE-2025-66478, a critical remote code…

3 months ago

LockBit 5.0 Infrastructure Exposed In Major Leak Of Servers, IPs, and Domains

LockBit 5.0, the ransomware group's latest variant, has suffered a paramount operational security (opsec) breach. Researchers exposed key infrastructure, including…

3 months ago

Android Introduces In-Call Scam Shield That Pauses Calls For 30 Seconds During Financial App Use

Google is rolling out a new defense against phone scams on Android devices. Called in-call scam protection, this feature pauses…

3 months ago

SageMaker Vulnerability Enables Privilege Escalation By Attackers

AWS SageMaker provides managed Jupyter notebook instances for data science tasks. These instances link to IAM execution roles with broad…

3 months ago

NCSC Launches Proactive Notification Service To Alert System Owners Of Vulnerabilities

The UK's National Cyber Security Centre (NCSC) has rolled out its Proactive Notification Service, partnering with internet monitoring firm Netcraft…

3 months ago