JetBrains warns of critical TeamCity remote code execution flaw

A critical vulnerability has been discovered in JetBrains’ TeamCity continuous integration and delivery (CI/CD) server, which could allow attackers to execute malicious code on affected systems with elevated privileges. The security issue, tracked as CVE-2026-63077, affects all versions of TeamCity On-Premises, making it a pressing concern for administrators responsible for securing these environments. The vulnerability … Read more

South Korea fines telco giant KT $39 million for customer data breach

South Korea’s largest telecommunications operator, KT Corporation, has been hit with a massive fine of $39 million by the country’s Personal Information Protection Commission (PIPC) for a data breach that exposed sensitive customer information. The incident, which lasted nearly 11 months, highlights the vulnerabilities in modern telecom infrastructure and the need for stricter security measures. … Read more

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

A sophisticated malware campaign linked to North Korean hackers has been discovered targeting macOS users, using fake software updates to deliver cryptocurrency-stealing malware. The attack, which appears to be ongoing, has compromised numerous devices worldwide, highlighting the importance of vigilance in protecting against increasingly complex threats. The malicious campaign relies on a technique known as … Read more

Google says AI helped Chrome fix 1,072 security bugs in two releases

Google’s AI-Powered Chrome Fixes Over 1,000 Security Bugs, Revolutionizing Vulnerability Management In a groundbreaking development, Google has credited its artificial intelligence (AI) systems with identifying and fixing an astonishing 1,072 security bugs in just two recent releases of its popular Chrome browser. This milestone marks a significant shift towards more efficient and effective vulnerability management, … Read more

VMware fixes three critical flaws allowing auth bypass, VM escapes

A trio of critical vulnerabilities has been patched by Broadcom in its recent security update for VMware products. These flaws, present in various versions of vCenter, ESX, Workstation, and Fusion, have the potential to grant unauthorized access to systems, allow malicious code execution, or even facilitate a virtual machine escape to the host. The affected … Read more

Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

A sophisticated cyberespionage campaign, linked to North Korean hackers, has been uncovered by Amazon, targeting some of the most widely used open-source software packages in the Node Package Manager (npm) ecosystem. The attackers, identified as part of the Sapphire Sleet threat actor, have compromised several critical libraries, including typo-crypto, debug, chalk, and axios, affecting an … Read more

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean Hackers Exploit macOS Users with Malvertising Scam, Stealing Cryptocurrency A sophisticated malware campaign linked to North Korea’s cyber espionage efforts has been identified targeting Apple’s macOS operating system. The attackers use a clever malvertising tactic, tricking users into downloading fake software updates that secretly install crypto-stealing malware. The scheme exploits vulnerabilities in the … Read more

Read This Before You Buy That TV Streaming Stick

A Dark Secret Lurking in Your Living Room: TV Streaming Sticks Caught in Massive Ad Fraud Scheme Cybersecurity experts have long warned about the risks of using generic TV boxes for streaming, but a recent investigation has uncovered a shocking twist. These devices not only rent out your internet connection to strangers but also secretly … Read more

VMware fixes three critical flaws allowing auth bypass, VM escapes

VMware’s latest security patches have addressed five vulnerabilities across its product suite, including three critical flaws that enable attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine. The fixes are considered emergency updates by Broadcom, and admins are urged to apply them as soon as possible. The affected products include VMware … Read more