Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
ChatGPT Atlas Omnibox Vulnerability: Prompt Injection via Pseudo‑URLs
Security researchers at NeuralTrust have disclosed an intent‑spoofing weakness in the ChatGPT Atlas agent browser. The issue stems from the ...
Baohuo Android Backdoor Abuses Telegram X: Stealth, Clipboard Theft, and Redis C2
Security researchers from Dr.Web report a new Android backdoor, dubbed Baohuo (Android.Backdoor.Baohuo.1.origin), that piggybacks on tampered builds of Telegram X. ...
Jingle Thief: Identity‑Centric Attacks on Microsoft 365 Fuel Large‑Scale Gift Card Fraud
Palo Alto Networks has documented a newly tracked criminal cluster dubbed Jingle Thief that systematically compromises cloud identities at retailers ...
Broadcom NetXtreme‑E Firmware Flaws Put Data Centers at Risk of VM Escape and DoS—Patch Now
Two vulnerabilities in Broadcom NetXtreme‑E high‑speed NIC firmware, widely deployed across servers and data‑center infrastructure, have been fixed following disclosure ...
Prosper Data Breach: SSNs Exposed and 17.6M Emails Listed by HIBP
Prosper, one of the oldest U.S. peer‑to‑peer lending platforms, is investigating a significant data breach after detecting unauthorized database queries ...
Windows blocks File Explorer preview for Internet files to curb NTLM hash leakage
Microsoft has changed how the File Explorer preview pane behaves in Windows, closing a low‑interaction path to NTLM credential exposure. ...
AWS Outage Leaves Eight Sleep Smart Beds Stranded, Spotlighting IoT Cloud-Dependency Risks
A widespread incident in AWS’s US-EAST-1 region triggered cascading service disruptions and exposed systemic weaknesses in cloud-dependent consumer IoT. Among ...
Microsoft fixes critical Kestrel flaw (CVE-2025-55315) enabling HTTP request smuggling
Microsoft has shipped fixes for a critical vulnerability in the Kestrel web server used by ASP.NET Core, tracked as CVE-2025-55315 ...
US Court Bans NSO Group From Targeting WhatsApp, Orders Data Deletion, Cuts Damages to $4M
A US federal court in the Northern District of California has issued a permanent injunction against Israeli spyware developer NSO ...
Europol Dismantles SIMCARTEL: Inside the Global SIM-Farm Network Powering OTP Abuse and Fake Accounts
European law enforcement has dismantled a large-scale SIM-farm ecosystem in an operation codenamed SIMCARTEL, disrupting a global pipeline for phishing, ...