Sunday, April 26, 2026
HomeUncategorized

Uncategorized

Bloomberg Comdb2 Vulnerabilities Allows Attackers to Initiate DoS Attack via Malicious Packet

Five critical security vulnerabilities in Bloomberg's open-source Comdb2 database that could allow attackers to launch denial-of-service attacks through specially crafted network packets. The vulnerabilities, affecting version 8.1 of the high-availability database system, have been successfully patched by Bloomberg following responsible disclosure practices. Three severe null...

New VOIP Botnet Targets Routers Using Default Passwords

A sophisticated global botnet campaign targeting Voice over Internet Protocol (VOIP) devices with default credentials, beginning with an unusual concentration of malicious activity in rural New Mexico. The investigation, published on July 24, 2025, reveals how approximately 500 compromised devices worldwide are participating in...

Fire Ant Hackers Target VMware ESXi and vCenter Vulnerabilities to Breach Organizations

An advanced espionage campaign designated "Fire Ant" that has been targeting virtualization and networking infrastructure since early 2025. The sophisticated threat actors demonstrated exceptional persistence and operational resilience, adapting in real-time to eradication efforts while maintaining prolonged access to compromised systems. The campaign's techniques...

Hackers Infiltrate Amazon’s AI Coding Agent with Destructive System Commands

A sophisticated supply chain attack targeting Amazon's Q extension for Visual Studio Code successfully embedded malicious system prompts designed to wipe users' local files and AWS cloud resources, exposing critical vulnerabilities in AI development tool security. The compromised version 1.84.0 briefly contained destructive commands...

BlackSuit Ransomware’s Data Leak Platform and Negotiation Portal Taken Down

A significant victory against cybercrime this week through Operation Checkmate, a coordinated effort that successfully seized the primary infrastructure used by the BlackSuit ransomware group. The operation has effectively dismantled the gang's ability to communicate with victims and distribute stolen data, marking a major...

CISA Alerts About Hackers Targeting SysAid Vulnerabilities in Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent warnings about two critical vulnerabilities in SysAid On-Prem systems that are being actively exploited by threat actors in the wild. The agency has added CVE-2025-2776 and CVE-2025-2775 to its Known Exploited Vulnerabilities (KEV) catalog,...