cybersecurity

Hackers Exploit Microsoft Windows LNK Vulnerability In The Wild As A 0-Day Attack

Attackers have abused CVE-2025-9491, a flaw in how Windows displays shortcut file properties, since 2017, to hide malicious commands in…

5 months ago

Let’s Encrypt Halves Certificate Validity Period, Moving To 45-Day Lifetimes

Let's Encrypt, a leading nonprofit certificate authority (CA), plans to slash the validity of its TLS certificates from 90 days…

5 months ago

CISA Issues Warning About Iskra iHUB Authentication Flaw Allowing Remote Device Reconfiguration

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory warning of a high-severity authentication flaw in…

5 months ago

Multiple Vulnerabilities In Django Facilitate SQL Injection and Denial-of-Service Attacks

The Django project released security patches on December 2, 2025, addressing two vulnerabilities in versions 5.2.9, 5.1.15, and 4.2.27. Posted…

5 months ago

Researchers Unveil Lazarus Recruitment Tactics In Live Honeypot Operation

ANYRUN and NorthScan have exposed the inner workings of North Korea's Lazarus Group through a bold honeypot operation. Researchers captured…

5 months ago

Rogue: AI-Driven Web App Scanner Leveraging OpenAI For Analysis

Faizan Ahmad, a security expert at Meta, launched Rogue on GitHub under the GPL-3.0 license. This Python-based tool uses OpenAI…

5 months ago

nopCommerce Vulnerability Lets Attackers Access Application Using Captured Cookie

A critical flaw in the popular open-source eCommerce platform nopCommerce exposes users to session hijacking attacks. Security researchers at CERT…

5 months ago

OpenVPN Vulnerabilities Allow Hackers To Trigger DDoS Attacks and Bypass Security Measures

OpenVPN, a popular open-source VPN solution, has patched multiple flaws in its recent releases that expose users to denial-of-service (DoS)…

5 months ago

India Requires All Smartphones To Include Permanent Government Cybersecurity App

India’s Department of Telecommunications (DoT) has mandated that all smartphone makers preload a non-removable government cybersecurity app, Sanchar Saathi, on…

5 months ago

Severe WatchGuard Firebox Vulnerabilities Enable Attackers To Bypass Integrity Checks and Inject Malicious Code

WatchGuard disclosed multiple high-severity vulnerabilities in Firebox appliances on December 4, 2025, including flaws that let privileged attackers execute arbitrary…

5 months ago