Saturday, April 25, 2026
HomeCybersecurity News

Cybersecurity News

Django Hit By Multiple Security Flaws Allowing SQL Injection And DoS Attacks

The Django Software Foundation has urgently released security patches for its popular Python web framework, addressing two critical vulnerabilities that could enable SQL injection attacks and denial-of-service disruptions. These flaws, disclosed on November 5, 2025, affect multiple versions including Django 4.2, 5.1, and 5.2,...

Authorities Dismantle Massive Credit Card Fraud Ring Affecting 4.3 Million Cardholders

Authorities dismantled three sophisticated fraud and money laundering networks that victimized over 4.3 million credit cardholders across 193 countries, causing damages exceeding €300 million. Dubbed Operation Chargeback, the effort was spearheaded by Germany's Cybercrime Department in Koblenz and the Federal Criminal Police Office (BKA),...

Hyundai AutoEver Confirms Data Breach Exposing Personal Data, Including SSNs And License Information

A key subsidiary of the Hyundai Motor Group focused on IT services and software development for automotive operations, has officially confirmed a significant data breach that compromised sensitive personal information of numerous individuals. The incident, disclosed through notification letters sent to affected parties, highlights...

HackedGPT – 7 New GPT-4o And GPT-5 Flaws Open The Door To Zero-Click Exploits

Researchers at Tenable have uncovered seven critical vulnerabilities in OpenAI's ChatGPT, affecting both GPT-4o and the newly launched GPT-5 models. These flaws expose users to sophisticated attacks that can steal private data from chat histories and memories without any user interaction true zero-click exploits....

CISA Warns Of Active Attacks Targeting CentreStack And Triofox Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a urgent alert by adding CVE-2025-11371 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation of a critical flaw in Gladinet's CentreStack and Triofox platforms. This unauthenticated local file inclusion (LFI) vulnerability allows...

Critical RCE Flaw In Popular React Native npm Package Puts Developers At Risk

A critical remote code execution (RCE) vulnerability in a widely used React Native npm package has left developers exposed to potential attacks, according to security researchers at JFrog. Designated CVE-2025-11953, the flaw carries a CVSS score of 9.8, indicating high severity due to its...