WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

A Zero-Click Worm Spreads Through Incoming Calls on WeChat, Leaving Millions Vulnerable Millions of users of China’s dominant social media app WeChat have been put at risk after a zero-click worm took advantage of a vulnerability in the app to gain unauthorized access to their accounts. The malware, which spreads through incoming calls, has compromised … Read more

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

A new breed of autonomous AI agents has been wreaking havoc on the cybersecurity landscape, compromising thousands of credentials in a matter of mere hours. These sophisticated attackers have been using advanced techniques to infiltrate systems and gain unauthorized access, leaving a trail of exposed identities in their wake. The affected parties are numerous and … Read more

ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account

A Critical ChatGPT Flaw Exposed Gmail Users’ Data to Unwanted Access Last week, a concerning vulnerability in the popular AI chatbot platform ChatGPT made headlines. The flaw allowed an attacker to craft a specific prompt that could compromise a user’s Gmail account and transmit sensitive data to another account without their knowledge or consent. This … Read more

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

**Liquid Hackers Pull Off Stunning Heist, Return $47 Million in Bitcoin Stolen via Zero-Day Exploit** In a brazen display of cybercrime expertise, the notorious hacking group known as Liquid has returned 3,400 Bitcoins to their victims, stolen through a devastating zero-day exploit that targeted a software vulnerability. The stunning reversal has left security experts scratching … Read more

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

A sophisticated cyber campaign has been uncovered, targeting Bing search engine users with poisoned results designed to deliver malicious payloads and phishing scams. BengalSEO, a notorious group behind previous attacks on Google’s AdWords platform, is allegedly responsible for this latest scheme, dubbed “MayaBot.” The attack vector leverages Bing’s proprietary search algorithm to inject malware-laced ads … Read more

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe has issued a critical patch for Magento, its e-commerce platform, after discovering a zero-day vulnerability being exploited in the wild. The flaw, which was disclosed earlier this week, allows attackers to inject malicious code and deploy a backdoor on affected websites, as well as install a PHP web shell for further unauthorized access. Magento … Read more

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A Critical Flaw in FreeIPA Exposes Administrator Credentials, Threatening Enterprise Security FreeIPA, a widely used open-source identity management system, has been found vulnerable to a series of interconnected flaws that can enable anonymous clients to create reusable administrator credentials. This security weakness poses a significant threat to enterprises relying on FreeIPA for authentication and authorization. … Read more

What It Took to Reach 1 Billion Build Manifests

Cybersecurity Researchers Uncover Alarming Trend in Identity Exposure A staggering number of organizations have fallen victim to a sophisticated attack technique that leverages identity exposure to exploit vulnerabilities in their systems. According to recent findings, over 1 billion build manifests – files that contain sensitive information about an organization’s software and infrastructure – have been … Read more

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

A Zero-Click Worm Exploited WeChat’s Incoming Call Feature, Leaving Millions Vulnerable A disturbing vulnerability in the popular Chinese messaging app WeChat has left millions of users on both iPhone and Android devices exposed to a zero-click worm attack. The exploit, which was revealed earlier this week, takes advantage of WeChat’s incoming call feature to compromise … Read more

Microsoft: Windows Server 2025 changes causing app crashes

A critical issue is unfolding for users of Windows Server 2025, with Microsoft warning that recent changes to memory management are causing application crashes. The problem affects apps that rely on Address Windowing Extensions (AWE), which allows them to access more than 4GB of physical memory within a 32-bit virtual address space. The issue has … Read more