Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple’s Hide My Email feature, designed to protect users’ email addresses from spammers and unwanted solicitations, was found to have a critical vulnerability that exposed real addresses in Mail logs. This flaw allowed malicious actors to gather sensitive information about Apple users, including their true identities. The issue was identified by a security researcher who … Read more

Critical wp2shell WordPress flaws exploited to install webshells

Critical wp2shell Vulnerabilities Allow Hackers to Install Webshells and Malicious Plugins A critical vulnerability suite, known as “wp2shell,” has been exploited by hackers to deploy persistent webshells and install malicious plugins on WordPress installations. The vulnerability, which affects WordPress Core versions prior to 7.0.2, 6.9.5, and 6.8.6, allows remote attackers to execute code without authentication, … Read more

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Anubis Ransomware Gang Claims Responsibility for Coca-Cola Fairlife Attack, Threatens Data Leak In a high-stakes cyberattack, the Anubis ransomware gang has claimed responsibility for breaching Coca-Cola’s Fairlife dairy subsidiary, leaving behind a trail of encrypted files and allegedly stolen corporate data. The attackers have threatened to publish this sensitive information unless the company pays a … Read more

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

Cloud Tenants Unleash New Bit2Watt Attack, Threatening Power Grids Worldwide A shocking discovery has left cybersecurity experts and power grid operators on high alert as researchers revealed a novel attack method that could allow cloud tenants to disrupt entire power grids without exploiting any vulnerabilities in the underlying software. Dubbed “Bit2Watt,” this sophisticated technique leverages … Read more

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google’s latest innovation, Gemini 3.5 Flash Cyber AI, is shaking up the cybersecurity landscape with its groundbreaking approach to identifying and fixing software vulnerabilities. This cutting-edge technology uses artificial intelligence (AI) to scan code and pinpoint weaknesses that could be exploited by hackers. What makes this tool so significant is its ability to not only … Read more

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Amazon Web Services (AWS) users are facing a potentially devastating security flaw that could allow attackers to rewrite configuration files and execute malicious code on their accounts. The vulnerability, dubbed “Kiro,” resides in AWS’s Config service, which is designed to monitor and audit resources within an organization’s cloud infrastructure. The Kiro flaw works by exploiting … Read more

N-day is Becoming N-Hour. Patching Faster Won’t Save You.

As AI-powered vulnerability discovery tools continue to accelerate, software vendors are struggling to keep pace with the rapid identification of new security flaws. The notion of “N-day” – a term used to describe the time between a vulnerability’s discovery and its public disclosure – is being rendered obsolete by the emergence of AI-driven threat detection. … Read more

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Hackers Can Hide Malicious Code in Android AI Agents, Putting Host PCs at Risk A newly discovered vulnerability in open-source Android AI agents has raised alarm bells for security experts and ordinary users alike. This issue allows malicious actors to hide code within seemingly innocuous text on an Android device’s screen, which can then execute … Read more

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Critical Security Flaw Found in Zimbra Collaboration Suite, Patches Issued for Immediate Update A severe security vulnerability affecting millions of users worldwide has been discovered in the popular open-source collaboration software Zimbra. The flaw, identified as a critical SNMP command injection bug, has been patched by the developers, and immediate update is strongly advised to … Read more

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

A Critical PAN-OS Flaw Exposes Organizations to Qilin Ransomware Attacks Qilin ransomware attackers have exploited a previously unknown vulnerability in Palo Alto Networks’ (PAN) PAN-OS operating system, allowing them to bypass authentication and gain initial access to compromised networks. This devastating flaw has already been leveraged by threat actors to wreak havoc on multiple organizations … Read more