Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A sprawling cyberattack campaign, dubbed “Mirage2FA,” has compromised the login credentials of over 4,500 companies across the United States and Europe. The attackers have been exploiting vulnerabilities in Microsoft 365’s authentication flows to gain unauthorized access to corporate networks, raising concerns about the security posture of these organizations. At its core, Mirage2FA involves a sophisticated … Read more

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

A Critical Flaw in Marimo Notebook Exposes Sensitive Data and Privileges, Threatening Millions of Users Marimo Notebook, a popular note-taking app, has been found vulnerable to a critical flaw that could allow attackers to execute malicious commands on users’ devices. The vulnerability, which affects millions of users worldwide, was discovered in the app’s edit mode, … Read more

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp’s Latest Security Upgrade Aims to Protect Users from Sophisticated Phishing Attacks In a significant move to bolster user security, WhatsApp has rolled out an innovative feature that enables users to create multiple passkeys for phishing-resistant sign-ins across both iOS and Android devices. This long-awaited upgrade comes as a response to the growing threat of … Read more

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Critical Vulnerability in NVIDIA’s NemoClaw Exposes Local AI Models to Malicious Webpage Poisoning Researchers have discovered a critical flaw in NVIDIA’s NemoClaw, an open-source framework for building and managing local artificial intelligence (AI) models. The vulnerability allows malicious webpages to inject poisoned data into these models, potentially compromising sensitive information and disrupting AI operations. … Read more

Silent Patches Don’t Stop Attackers – They Blind Defenders

Silent Patches Do More Harm Than Good, Leaving Defenders in the Dark In recent months, several major vendors have chosen to quietly release security patches for critical vulnerabilities without issuing advisories or disclosing the details. This approach may seem like a reasonable way to prevent attackers from exploiting newly discovered bugs, but it’s actually doing … Read more

First Malware Built Specifically for Car Head Units Fuels Botnet

A New Front in Cybercrime: Malware Targets Car Infotainment Systems In a disturbing trend, researchers at Kaspersky have uncovered malware specifically designed for car head units, marking the first time this type of attack has been seen. The malicious code, linked to the notorious BadBox botnet, exploits vulnerabilities in software update systems to deliver stealthy … Read more

Police arrests dozens of suspects in global cybercrime crackdown

In a major blow to global cybercrime networks, law enforcement agencies from 22 countries have joined forces in a coordinated effort to dismantle African crime groups and disrupt their operations. Dubbed “Operation Jackal IV,” this international joint action has led to the arrest of 58 individuals linked to cybercrime networks, with dozens more suspects identified. … Read more

Hackers breached over 270 Zimbra servers in ongoing attacks

Cyber Attackers Breach Hundreds of Email Servers Using Unpatched Vulnerability A sophisticated cyber attack is unfolding on a massive scale, with over 270 email servers compromised using an unpatched vulnerability in the Zimbra Collaboration Suite (ZCS). The attack has been ongoing for weeks, and experts warn that hundreds of thousands of other servers remain vulnerable … Read more

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

A critical vulnerability in the miniOrange SAML (Security Assertion Markup Language) plugin for WordPress has been exploited by attackers, granting them full administrative access to compromised websites. The flaw allows hackers to escalate privileges from a standard user account to a WordPress administrator, effectively giving them control over the entire site. The miniOrange SAML plugin … Read more

Silent Patches Don’t Stop Attackers – They Blind Defenders

A Growing Concern in Cybersecurity: Silent Patches and Their Consequences In recent years, some vendors have adopted a practice known as “silent patching,” where they fix security vulnerabilities without publicly disclosing the issue or providing any information about the patch. This approach may seem reasonable at first glance, but it has serious consequences for defenders … Read more