SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

A hardware wallet manufacturer, SafePal, has revealed that a flaw in its system exposed sensitive information for nearly 40,000 of its customers. The vulnerability allowed unauthorized access to user data, including email addresses and private keys. This security lapse highlights the importance of robust encryption and secure storage practices in the cryptocurrency industry. The issue, … Read more

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A highly skilled attacker has been quietly compromising both Salesforce and ServiceNow portals since 2025, exploiting vulnerabilities in these popular cloud platforms to gain unauthorized access to sensitive customer data. The brazen cyber campaign, which has flown under the radar for over a year, raises serious concerns about the security posture of companies that rely … Read more

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

A sophisticated malware campaign has targeted RubyGems, a popular package repository for Ruby developers, resulting in the compromise of 16 packages. The attack, which leverages a technique called typosquatting, has put browser credentials and cryptocurrency wallets at risk. Typosquatted packages are malicious versions of legitimate software that have been created to deceive users into installing … Read more

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

A massive data breach affecting over 1.2 million individuals has come to light, with consumer lender Heights Finance Holdings Co. notifying those whose personal and financial information was stolen by hackers. The incident, which occurred in early May, involved a third-party cloud-based platform used for customer data storage that was accessed by the attackers. The … Read more

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft has finally begun removing a long-abused tool from its latest Windows 11 builds, a move that’s expected to significantly boost the operating system’s security posture. The Windows Management Instrumentation Command-line (WMIC) tool, which has been a favorite among cybercriminals for its ability to interact with Windows systems using text commands, will no longer be … Read more

Microsoft confirms outage affecting search in Microsoft 365 apps

A Search Outage Hits Microsoft 365, Leaving Some Users Stranded Microsoft has confirmed an outage affecting search functionality within its Microsoft 365 suite of apps. The issue has left some users unable to search for content within SharePoint Online, OneDrive, Outlook on the web, and Outlook desktop. While the company hasn’t specified which regions are … Read more

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

A critical vulnerability in a widely used browser plugin has been flagged by US authorities as actively exploited, potentially giving hackers the keys to remote code execution and unleashing devastating attacks on unsuspecting users. The flaw, designated as Ray, resides within an innocuous-looking library that is embedded across multiple applications, including those related to financial … Read more

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

A Vulnerability in SafePal Hardware Wallets Exposed Personal Data of Thousands SafePal, a Singapore-based company that produces hardware wallets for cryptocurrency users, has disclosed a critical security flaw that exposed sensitive information about nearly 40,000 customers. The vulnerability, discovered by an anonymous researcher and reported to SafePal through their bug bounty program, allowed attackers to … Read more

Details emerge on BlackFile’s recent attacks on financial companies

A notorious cybercrime group, BlackFile, has been wreaking havoc on financial companies and other organizations across multiple industries. According to researchers at Google Threat Intelligence Group (GTIG), this threat actor has been active since the start of 2026, targeting victims with ease and extorting them for millions of dollars. BlackFile’s modus operandi is a perfect … Read more

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers on vulnerable systems. The bug, tracked as CVE-2026-65400, is an authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials. The vulnerability has been observed being exploited by threat actors roughly a week after … Read more