Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
StealC V2 Infostealer Distributed via Malicious Blender .blend Files on 3D Marketplaces
Security researchers at Morphisec have identified a targeted malware campaign that abuses Blender, a popular open-source 3D creation suite, to ...
Forced Keenetic Router Firmware Update: Critical CWE‑521 Password Vulnerability Explained
Owners of Keenetic routers have reported that their devices upgraded to a new firmware version even though automatic updates were ...
Google patches actively exploited Chrome zero‑day CVE-2025-13223 in V8 and WebAssembly
Google has released an emergency security update for Google Chrome to fix CVE-2025-13223, a critical zero-day vulnerability rated 8.8 on ...
Malicious npm Packages Abuse Adspect Cloaking to Deliver Crypto Scams
Researchers at Socket have identified seven malicious npm packages that weaponized the cloud-based traffic service Adspect to hide their behavior ...
ShadowRay 2.0 Exploits CVE-2023-48022 in Ray to Build Self-Spreading AI Botnet
Attackers are actively abusing a critical remote code execution (RCE) vulnerability CVE-2023-48022 in the popular Ray framework to hijack artificial ...
WrtHug Malware Campaign Hijacks Asus Routers Through AiCloud Vulnerabilities
SecurityScorecard researchers have disclosed a large-scale malware operation dubbed WrtHug, targeting consumer and SOHO Asus routers. The campaign has already ...
Chinese APT24 Uses New BadAudio Malware in Multi‑Year Cyber Espionage Campaign
Google Threat Intelligence Group (GTIG) has detailed a multi‑year cyber espionage operation attributed to the Chinese threat actor APT24 (also ...
Microsoft to Integrate Sysmon Natively into Windows 11 and Windows Server 2025
Microsoft has announced plans to add Sysmon (System Monitor) as a native, installable component in Windows 11 and Windows Server ...
CrowdStrike Insider Leak Exposes SSO Risks and the Evolving Insider Threat Landscape
In the second half of last month, CrowdStrike, one of the leading global cybersecurity vendors, confirmed an insider-driven data leak ...
CVE-2025-41115: Critical SCIM Vulnerability in Grafana Enterprise Enables Admin Account Takeover
A critical security flaw tracked as CVE-2025-41115 has been discovered in the commercial edition of Grafana Enterprise, scoring the maximum ...