Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
RondoDox Botnet Exploits Critical XWiki CVE-2025-24893 RCE Vulnerability
A critical remote code execution (RCE) vulnerability CVE-2025-24893 in XWiki Platform is being actively exploited by the emerging RondoDox botnet, ...
Anthropic’s 90% Automated Cyberespionage Claim Draws Industry Skepticism—and Practical Lessons for Defenders
Anthropic reports it detected and disrupted a large-scale cyberespionage operation attributed to Chinese-linked group GTG-1002, asserting that up to 90% ...
Fortinet warns of active attacks exploiting FortiWeb CVE‑2025‑64446
Fortinet has confirmed broad, in‑the‑wild exploitation of a critical zero‑day vulnerability in the FortiWeb web application firewall (WAF). Tracked as ...
Protei Cyberattack Exposes DPI/SORM Vendor Risks for Global Telecom Operators
An extensive cybersecurity incident has reportedly hit international telecom solutions vendor Protei, with an unknown hacking group claiming to have ...
Aisuru IoT Botnet Hits Microsoft Azure with 15.72 Tbps DDoS Attack
The Microsoft Azure cloud platform has become the target of one of the most powerful distributed denial-of-service (DDoS) attacks reported ...
Cloudflare Outage: How a ClickHouse Permission Change Triggered a Global Bot Management Failure
On 18 November 2025, Cloudflare, one of the world’s largest CDN and network security providers, experienced one of its most ...
CVE-2025-9501: Critical W3 Total Cache Vulnerability Allows Unauthenticated RCE in WordPress
A newly disclosed flaw in the popular WordPress performance plugin W3 Total Cache exposes over a million websites to a ...
WhatsApp Phone Number Enumeration Exposes 3.5 Billion User Accounts
Researchers from the University of Vienna have demonstrated how a legitimate feature in WhatsApp can be turned into a powerful ...
Google Eases Android Developer Verification and Introduces Advanced Mode for Sideloading
Google is revising its planned Android Developer Verification program after community pushback, adding simplified accounts for small developers and an ...
Checkout.com Confirms Data Breach: ShinyHunters Exploit Legacy Cloud Storage
Global payments provider Checkout.com has disclosed a security incident following unauthorized access to a deprecated third‑party cloud file repository. The ...