CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

A critical vulnerability in a widely-used JavaScript library has left five cryptocurrency wallet apps exposed to potential theft, resulting in an estimated $5.7 million drained from user accounts. The issue lies in CryptoJS’s weak random number generator (RNG), which is used by the affected wallets to securely store and manage users’ cryptographic keys. The vulnerability … Read more

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Cisco has just released patches for a critical batch of vulnerabilities affecting several of its products, including SD-WAN, IOS XE, and FMC. The company has addressed two dozen issues, with some of them being so severe that they could allow attackers to gain root privileges on affected devices. The most concerning vulnerability is in the … Read more

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

A notorious cyber attacker, known for exploiting vulnerabilities in cloud-based databases, has pleaded guilty to multiple breaches affecting at least 100 million individuals worldwide. The hacker, who was arrested last year and identified as “Snowflake,” had a history of targeting companies that use Amazon Web Services (AWS) and other popular cloud platforms. As part of … Read more

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A Critical Vulnerability in TeamCity Exposes Thousands of Organizations to Remote Code Execution Attacks The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited vulnerability in the popular software development platform TeamCity. The flaw, designated as CVE-2026-63077, allows attackers to execute arbitrary code on affected systems, putting thousands of … Read more

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Cybercrime Kingpin Sentenced to 16 Years for Running Ransomware-as-a-Service Empire A major blow has been dealt to the world of cybercrime, as a notorious creator of ransomware-as-a-service (RaaS) platforms has been sentenced to 16 years in prison. The sentencing marks a significant victory for law enforcement and cybersecurity experts, who have long battled against the … Read more

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Chinese-Made Routers Found to Contain Hidden Backdoor, Leaving Users Vulnerable to Attack A disturbing discovery has been made in the world of cybersecurity, as it’s come to light that certain Chinese-made routers are shipping with a hidden backdoor that allows unauthenticated access to root shells. This means that anyone who gains possession of one of … Read more

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A $50,000 Exploit Chain Turns Bixby Against Samsung Phones, Exposing Users to Remote System-Level Compromise Two security researchers have demonstrated a sophisticated exploit chain that can hack into Samsung mobile devices by manipulating the virtual assistant Bixby. Dimitrios Valsamaras and Ken Gannon, who presented their findings at the Black Hat conference, showed how an attacker … Read more

Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

A recently patched vulnerability in JetBrains TeamCity, a widely used continuous integration and continuous delivery platform, is being actively exploited by hackers. According to the US Cybersecurity and Infrastructure Security Agency (CISA), threat actors have started targeting organizations using TeamCity On-Premises versions, putting sensitive data and systems at risk. TeamCity is a central component of … Read more

Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

Critical Flaws in Cisco’s SD-WAN and IOS XE Expose Businesses to Remote Attacks Cisco has just released patches for two dozen vulnerabilities across its products, including critical-severity bugs in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The affected companies should take immediate action to protect their networks from potential attacks. These flaws … Read more

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

New Attack Vector Emerges as Researchers Uncover Flaws in Google’s Agent Development Kit for Python A novel attack vector has been discovered by researchers at Pillar Security, who found a series of flaws in Google’s open-source Agent Development Kit (ADK) for Python. The vulnerabilities, which have since been patched by Google, allowed malicious agents to … Read more