New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws

Cybersecurity researchers have uncovered a sophisticated exploit kit dubbed “BlueMoon” that has been used by multiple cyber-espionage groups to target Windows and Chrome users. The BlueMoon kit takes advantage of zero-day vulnerabilities in Chromium-based browsers, including Google Chrome, and Windows operating systems, making it a highly effective tool for attackers. The BlueMoon kit is a … Read more

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Cybersecurity authorities have set a September 12 deadline for federal agencies and contractors to patch critical vulnerabilities in Cisco, Citrix, and Fortinet products. The move comes after the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed that these flaws are being exploited by attackers, highlighting the need for swift action to prevent further breaches. The … Read more

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Gigabud’s Android Work Profiles Expose Users to Banking App Malware Checks A disturbing trend has emerged in the world of mobile security, where a company called Gigabud is creating custom Android work profiles that can evade malware detection by banking apps. This revelation poses significant risks for users who rely on these apps for financial … Read more

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A sophisticated cyber attack has been uncovered, involving hundreds of artificial intelligence agents and compromising over 440 instances of a popular print management software, PaperCut. The attackers exploited vulnerabilities in the software’s architecture, leveraging identity exposure to create active attack paths that have left many organizations vulnerable. The attack, which was reportedly carried out using … Read more

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

A Critical Vulnerability in Popular VPN Certificates Exposes Users to Remote Code Execution Attacks Check Point, a leading cybersecurity firm, has disclosed two high-severity vulnerabilities affecting popular virtual private network (VPN) certificates. These flaws, rated 9.8 out of 10 for severity, enable unauthenticated remote code execution (RCE), leaving millions of users vulnerable to cyber attacks. … Read more

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical vulnerability in WatchGuard Firebox firewalls that’s being exploited by ransomware gangs. This flaw, tracked as CVE-2025-14733, allows unauthenticated attackers to remotely execute malicious code with ease, putting countless organizations at risk. The vulnerability affects firewalls running Fireware OS 11.x and … Read more

Microsoft says September updates fix mouse settings reset issues

In a welcome fix, Microsoft has resolved a known issue that reset mouse settings on some Windows 11 systems after installing the August preview update. The problem, which was confirmed by the company just days after its release, caused users to lose custom cursor personalization settings and animations. The issues affected non-English Windows installations, where … Read more

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

A leading artificial intelligence (AI) developer, Anthropic, has disclosed its fourth hacking incident in recent months, with the latest attack targeting its Claude Opus 4.6 system. This vulnerability highlights a growing concern about AI systems being compromised and used as launchpads for sophisticated cyber attacks. The incident involved an unauthorized access to Anthropic’s AI infrastructure, … Read more

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

A Shocking Weakness in LiteLLM Gateways Exposes Thousands of Organizations to Cyber Threats A concerning discovery has been made regarding the security of LiteLLM gateways, a crucial component of many organizations’ infrastructure. It appears that nearly 1 in 10 exposed LiteLLM gateways are vulnerable to unauthorized access due to an easily guessable admin key. The … Read more

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Cybersecurity authorities have issued a stark warning, highlighting the urgent need for patching three critical vulnerabilities in widely used network security products. The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged exploited flaws in Cisco, Citrix, and Fortinet systems, setting a federal deadline of September 12 for affected organizations to apply patches. The problem … Read more