cyber news

Critical Citrix Vulnerability Exploited: 28,000+ Instances at Risk of Remote Code Execution

A critical zero-day remote code execution vulnerability in Citrix NetScaler ADC and Gateway systems is putting thousands of organizations at…

8 months ago

Persistent XSS Vulnerability in IPFire Web Interface via Authenticated Administrator

In a critical security advisory, researchers have disclosed a stored cross-site scripting (XSS) vulnerability in IPFire 2.29’s web-based firewall interface…

8 months ago

New Cache Deception Exploit Circumvents Cache-Server Mismatch

A newly documented cache deception attack exploits subtle discrepancies between caching layers and origin servers to expose sensitive endpoints and…

8 months ago

DOGE Under Fire for Allegedly Storing National Social Security Data in Unsecured Cloud

A whistleblower disclosure filed by the Social Security Administration's Chief Data Officer has raised critical concerns about the Department of…

8 months ago

Critical 0-Day RCE Vulnerability in Citrix NetScaler ADC & Gateway Under Active Exploitation

A critical security bulletin warning that attackers are actively exploiting a zero-day remote code execution vulnerability in NetScaler ADC and…

8 months ago

PhpSpreadsheet Library Vulnerability Allows Injection of Malicious HTML

A critical Server-Side Request Forgery (SSRF) vulnerability has been discovered in the popular PHP library PhpSpreadsheet, allowing attackers to inject…

8 months ago

Maryland Department of Transportation Cybersecurity Breach Under Investigation

In a coordinated statement issued today, the Maryland Transit Administration (MTA) and the Maryland Department of Information Technology (DoIT) confirmed…

8 months ago

Auchan Hit by Cyberattack, Customer Data Compromised

On August 21, 2025, the French retail giant Auchan disclosed a significant cybersecurity breach affecting “several hundred thousand” customer loyalty…

8 months ago

Hackers Scanning Microsoft Remote Desktop Web Access From 1000+ IPs

A massive coordinated campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with nearly 2,000 malicious IP addresses conducting simultaneous reconnaissance…

8 months ago

CISA Alerts on Active Exploitation of Citrix Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on…

8 months ago