Oracle VirtualBox on macOS ARM: Two CVEs Enable VM Escape, Patched in October 2025 CPU

Laptop screen displaying VirtualBox logo with a warning symbol overlay.

Two vulnerabilities in Oracle VirtualBox, tracked as CVE-2025-62592 and CVE-2025-61760, can be chained to escape from a guest virtual machine to the host on macOS ARM. Reported by BI.ZONE, this is the first publicly known VM-escape chain targeting VirtualBox on macOS ARM since VirtualBox 7.1.0 (2024) introduced Apple Silicon support. Technical breakdown: information leak to … Read more

ColdRiver pivots to ClickFix: NoRobot and MaybeRobot replace LostKeys in stealthier social engineering campaigns

Hooded figure typing on a laptop, with eerie portraits and chess pieces nearby.

Google’s Threat Intelligence Group (GTIG) reports a rapid shift in the tradecraft of the Russian‑language threat actor ColdRiver—also tracked as UNC4057, Callisto, and Star Blizzard. Following public analysis of its LostKeys toolset in May 2025, the group abandoned that implant and adopted a new chain built around NoRobot, YesRobot, and MaybeRobot, delivered primarily through ClickFix … Read more

Google Adds “Recovery Contacts” to Gmail: A Human-Assisted, Phishing-Resistant Path to Account Recovery

Phone displaying account recovery screen with a photo and prompt.

Google is expanding Gmail account recovery with a new option called Recovery Contacts, a human-assisted mechanism that lets users designate trusted people to verify their identity when standard recovery factors—such as SMS codes, backup email, or hardware keys—are unavailable. The approach aims to close a long‑standing gap in account recovery without weakening phishing resistance. What … Read more

DNS0.eu Shuts Down: Impact on EU DNS Security and Migration Paths to DNS4EU and NextDNS

** Man looking concerned at a laptop displaying a service discontinued message.

DNS0.eu has ceased operations, replacing its website with a brief notice: “The service is no longer running… maintaining it became impossible in terms of time and resources.” Users are advised to migrate to DNS4EU or NextDNS—privacy-focused, security-aware recursive resolvers. The decision arrives amid escalating DNS-layer attacks and widespread adoption of encrypted DNS protocols, making the … Read more

TP-Link Omada gateways hit by critical unauthenticated RCE; firmware updates available

Professional examining a digital alert about security vulnerabilities in a futuristic setting.

TP-Link has disclosed four security issues affecting Omada series gateways, with two vulnerabilities enabling arbitrary command execution with root privileges. The most serious, CVE-2025-6542, carries a CVSS score of 9.3 and is exploitable remotely without authentication. A second flaw, CVE-2025-6541 (CVSS 8.6), requires an authenticated session to the web management interface. TP-Link has released firmware … Read more

China Alleges NSA Targeted National Time Service Center: What It Means for Critical Infrastructure

Silhouetted figure holding a phone, laptop displaying symbols of security and danger.

China’s Ministry of State Security (MSS) alleges the U.S. National Security Agency conducted targeted cyber operations against the National Time Service Center (NTSC). According to the MSS, attackers exploited vulnerabilities in messaging services on smartphones from a “foreign brand” in 2022 to harvest employee data, then repeatedly accessed NTSC’s internal networks during 2023–2024 using stolen … Read more

PolarEdge Botnet Exploits Cisco CVE-2023-20118 to Build ORB-Style Proxy Network Targeting Cisco, ASUS, QNAP and Synology Devices

Man interacting with a futuristic digital display in a sleek, illuminated setting.

Security researchers have published a technical analysis of the PolarEdge botnet, a campaign actively observed since February 2025 and aimed at networking and NAS gear from Cisco, ASUS, QNAP, and Synology. Infrastructure signals reviewed by Censys in August 2025 suggest the activity may date back to June 2023 and exhibits traits of an Operational Relay … Read more

131 Chrome Extensions Weaponize WhatsApp Web for Bulk Messaging, Socket Warns

Man using a laptop with a visible WhatsApp Web screen against a dramatic backdrop.

Security analytics firm Socket has identified 131 Chrome extensions designed to automate actions in WhatsApp Web and orchestrate bulk messaging. The cluster is primarily aimed at Brazil and collectively accounts for approximately 20,905 active users, pointing to a sustained, commercially motivated operation that has been active for at least nine months and received updates as … Read more

Microsoft tightens IE Mode in Edge after attacks leveraging Chakra zero-day

Rusty padlock with Internet Explorer logo and a keyboard key background.

Microsoft has revised how Internet Explorer (IE) Mode is invoked in Edge following a wave of attacks observed in August 2025. According to the Microsoft Browser Vulnerability Research team, threat actors abused the legacy compatibility pathway, pairing basic social engineering with a zero‑day in the Chakra JavaScript engine to gain unauthorized access to user devices. … Read more