n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

A Critical Flaw in n8n Token Exchange System Puts Users at Risk of Account Takeover A severe security vulnerability has been discovered in the token exchange system of n8n, an open-source workflow automation platform widely used by developers and organizations. The flaw allows attackers to hijack user accounts from other issuers, compromising sensitive data and … Read more

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

A new wave of sophisticated threats is sweeping through the online landscape, targeting gamers, consumers, and businesses alike with increasingly cunning tactics. This month’s crop of security breaches highlights the growing importance of staying vigilant against AI-powered attacks, from game cheat spyware to high-stakes 24-hour ransomware demands. At the heart of these developments lies a … Read more

20+ Hijacked Government Websites Became
an Attack Channel

**Multiple Government Websites Hijacked, Used for Malicious Activities** In a disturbing revelation, over 20 government websites across the globe have been compromised and used as attack channels by malicious actors. These hacked sites, which include official portals of state governments, ministries, and other public institutions, were exploited to spread malware, phishing attacks, and other types … Read more

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

A highly aggressive macOS malware, dubbed ClickLock, is wreaking havoc on Apple users worldwide, forcing them to constantly re-enter their password credentials every 210 milliseconds until they comply. This ruthless stealer app has been quietly spreading its tentacles across various countries, targeting individuals and organizations alike. ClickLock’s modus operandi revolves around exploiting a critical vulnerability … Read more

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

A Sophisticated Malware Threat Emerges, Exploiting ClickFix’s Popularity Malware known as TELEPUZ is spreading rapidly across the globe, with reported incidents affecting organizations and individuals alike. The threat leverages ClickFix, a popular software update tool that has unwittingly become a conduit for cyberattacks. This malicious exploit highlights the importance of vigilance in the digital landscape. … Read more

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Cybersecurity experts are sounding the alarm about a critical vulnerability discovered in n8n, an open-source workflow automation platform widely used by developers and organizations around the world. The flaw, which affects all versions of n8n, could allow attackers to log in as users from another issuer, effectively bypassing authentication controls. The issue lies in how … Read more

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

A recent wave of sophisticated cyber threats is sweeping across the globe, leaving a trail of compromised systems and stolen data in its wake. At the forefront of this malicious onslaught are game cheat spyware, 24-hour ransomware, and Chrome sync stalking, each exploiting vulnerabilities that even the most security-conscious users may not be aware of. … Read more

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

Taiwanese Tech Firms Caught Off Guard as Daxin Malware Resurfaces with Stealthy Backdoor A new wave of malware infections is sweeping through Taiwan’s tech industry, leaving IT security teams scrambling to contain the damage. Dubbed “Daxin,” this highly sophisticated piece of malware has been linked to a previously unknown backdoor, codenamed “Stupig Pre-Login SYSTEM.” The … Read more

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

A new and highly sophisticated data injection attack, designed to manipulate artificial intelligence (AI) agents into making unintended decisions or executing malicious commands, has been discovered. Dubbed “Agent Data Injection,” this assault leverages AI’s own capabilities against it by training the system to commit errors or carry out unauthorized actions. The Agent Data Injection attack … Read more

20+ Hijacked Government Websites Became
an Attack Channel

A wave of malicious activity has swept through government websites worldwide, with over 20 high-profile sites compromised and repurposed as attack channels for cyber threats. The affected governments have taken swift action to contain the issue, but not before hackers exploited the vulnerabilities to spread malware and steal sensitive data. At the heart of this … Read more