cybersecurity

GhostFrame Phishing Kit Unleashes Stealthy Attacks On Millions Of Users Globally

Cybersecurity researchers at Barracuda uncovered GhostFrame, a slick phishing-as-a-service (PhaaS) kit, back in September 2025. By early December, it powered…

4 months ago

Hackers Can Exploit Delivery Receipts On Instant Messengers To Access User Private Data

Hackers have found a way to secretly track users on popular messaging apps like WhatsApp and Signal using delivery receipts.…

4 months ago

CISA Includes React2Shell Vulnerability In KEV Catalog Due To Ongoing Exploitation

CISA has added CVE-2025-55182, dubbed React2Shell, to its Known Exploited Vulnerabilities (KEV) catalog due to confirmed active exploitation. This critical…

4 months ago

Severe Cal.com Vulnerability Lets Attackers Bypass Authentication with Fake TOTP Codes

Cal.com, a popular open-source scheduling platform, faces a critical authentication flaw that allows attackers to bypass password checks by using…

4 months ago

Zero-Day Vulnerabilities In PickleScan Allow Arbitrary Code Execution Through Malicious PyTorch Models

Security researchers at JFrog uncovered three critical zero-day flaws in PickleScan, a key tool for detecting malware in Python pickle-based…

5 months ago

New Tool For Scanning Exposed ReactJS and Next.js RSC Endpoints

Security researchers have released React Server Components Surface Exposure Scanner, a free tool to detect exposed endpoints vulnerable to CVE-2025-55182.…

5 months ago

Freedom Mobile Data Breach Exposes Customers’ Personal Information

Freedom Mobile, a primary Canadian wireless provider, disclosed a data breach on December 3, 2025, affecting a limited number of…

5 months ago

Marquis Data Breach Exposes Dozens Of U.S. Banks and Credit Unions

A significant data breach at Marquis Software Solutions has exposed sensitive customer information from dozens of U.S. banks and credit…

5 months ago

K7 Antivirus Vulnerability Lets Attackers Gain SYSTEM-level Privileges

Security researcher Lucas Laise from Quarkslab discovered a serious privilege escalation vulnerability in K7 Ultimate Security, an antivirus software from…

5 months ago

Critical Vulnerability In React and Next.js Allows Remote Attackers To Execute Malicious Code

A critical remote code execution flaw, tracked as CVE-2025-55182 and dubbed React2Shell, affects React Server Components in the React 19…

5 months ago