Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

A sophisticated Linux botnet, dubbed Evooo1Bot, has been discovered exploiting known vulnerabilities to hijack edge devices and turn them into SOCKS5 proxies. This malicious network is capable of bypassing traditional security measures and could be used for a wide range of nefarious activities, from data exfiltration to DDoS attacks. Evooo1Bot specifically targets Linux-based systems, including … Read more

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A critical vulnerability has been discovered in the VoLTE (Voice over LTE) implementation of Unisoc’s Android-based chipsets, allowing attackers to gain full kernel access and potentially seize control of affected devices. This exploit chain, which affects a wide range of devices, has significant implications for users’ security and privacy. The vulnerability, revealed by researchers, lies … Read more

How MCP Servers Can Expose Enterprise Secrets

A recent investigation has revealed that a significant number of enterprise organizations are unwittingly exposing sensitive information and creating potential attack paths through their Microsoft Clustered Server (MCS) environments. What’s particularly concerning is that this vulnerability can be exploited without requiring any prior access to the network or systems, making it an attractive target for … Read more

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft Scrambles to Patch ShieldBreak Zero-Day Vulnerability in Windows Defender A serious security vulnerability has been discovered in Microsoft’s Defender antivirus software, allowing attackers with limited permissions to gain SYSTEM privileges on fully patched Windows systems. The flaw, dubbed “ShieldBreak,” was disclosed by a security researcher known as “Nightmare Eclipse” after Microsoft released its August … Read more

French tax authority data breach affects 678,000 individuals

A massive data breach has struck the French tax authority, exposing sensitive information belonging to nearly 700,000 individuals. The attack, which was only recently disclosed by the authorities, raises serious concerns about the security of government databases and the potential consequences for those affected. According to a statement from the French Finance Ministry, an attacker … Read more

Philips and GE investigating Clop ransomware data theft claims

Two global tech giants, General Electric (GE) and Philips, have joined oil giant Shell in investigating claims that their systems were breached by the notorious Clop ransomware gang. The alleged data theft incident has sparked concerns about the security of enterprise software platforms widely used across various industries. According to reports, the Clop hacking group … Read more

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A China-Nexus Actor Exploits VMware vCenter Flaw, Deploying Babuk-Derived Ransomware Cybersecurity researchers have uncovered a sophisticated cyberattack that leverages a previously unknown vulnerability in VMware’s vCenter management software to deploy a custom-built ransomware variant derived from the infamous Babuk strain. The attack is suspected to be linked to China-based threat actors, who have been known … Read more

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

A new and highly sophisticated botnet, dubbed “Evooo1Bot,” has been discovered compromising Linux-based edge devices worldwide. This botnet exploits known vulnerabilities in various software applications, turning compromised machines into SOCKS5 proxies that can be controlled remotely by attackers. The implications are far-reaching, with potentially millions of devices at risk. At the heart of this issue … Read more

Fortune 500 Companies Hit in Azure Data Theft Campaign

A massive data theft campaign has targeted several Fortune 500 companies, exposing millions of sensitive records that could be used in sophisticated social engineering attacks. The threat actor, known as “TheHatman,” claims to have stolen over 5 million records from the Azure tenants of prominent brands like McDonald’s Corporation, Tata Consultancy Services (TCS), Vodafone, and … Read more

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

A critical vulnerability in SAP Commerce Cloud has been exploited just three days after its public disclosure, highlighting the urgent need for organizations to prioritize patching and monitoring their systems. The vulnerability, tracked as CVE-2026-58231, is a serious issue that allows attackers to execute arbitrary code and compromise internal components. It was publicly disclosed on … Read more