Uncategorized

Surveillance Firm Exploits SS7 Vulnerabilities to Track User Locations

A sophisticated new SS7 bypass attack that enables surveillance companies to circumvent mobile network security defenses and illegally track user…

9 months ago

CoinDCX Hack Leads to $44.2 Million Loss

Indian cryptocurrency exchange CoinDCX confirmed a major security breach on Saturday (July 19, 2025) that resulted in hackers stealing $44…

9 months ago

Microsoft AppLocker Vulnerability Allows Malicious Apps to Bypass Restrictions

A configuration vulnerability in Microsoft's AppLocker security feature that could potentially allow certain applications to bypass system restrictions. The discovery…

9 months ago

Critical Livewire Vulnerability Puts Millions of Laravel Applications at Risk of Remote Code Execution

A critical security vulnerability has been discovered in Livewire v3, a popular full-stack framework for Laravel that enables developers to…

9 months ago

Microsoft SharePoint Server 0-Day RCE Actively Exploited, CISA Issues Urgent Warning

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical zero-day vulnerability in Microsoft SharePoint…

9 months ago

New 7-Zip Vulnerability Lets RAR5 Files Crash Systems

A critical vulnerability in the popular 7-Zip file archiver has been discovered and patched, allowing malicious actors to craft weaponized…

9 months ago

PoisonSeed Attack Exploits MFA by Tricking Users into Scanning Malicious QR Codes

A sophisticated new attack technique that exploits FIDO key authentication systems by tricking users into scanning malicious QR codes with…

9 months ago

SharePoint 0-Day RCE Vulnerability Allowing Full Server Compromise

A critical zero-day vulnerability in Microsoft SharePoint servers, designated CVE-2025-53770, that allows attackers to achieve remote code execution without authentication.…

9 months ago

Active Exploitation of New CrushFTP 0-Day Vulnerability Grants Attackers Server Access

A critical zero-day vulnerability in CrushFTP servers has been actively exploited by attackers since July 18th, 2025, with security researchers…

9 months ago

Critical Vulnerabilities in Sophos Intercept X for Windows Allow Arbitrary Code Execution

Sophos has disclosed three high-severity security vulnerabilities in its Intercept X for Windows endpoint protection software that could allow local…

9 months ago