Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Google Refutes Gmail Breach Claims and Mass Password Reset Rumors
Google has clarified that it did not issue a broad-based alert or force a mass password reset for Gmail users. ...
Android September 2025 Security Update Fixes 120 Flaws; Two Zero‑Days Already Exploited
Google has released the September 2025 Android Security Bulletin, addressing 120 vulnerabilities across the OS and ecosystem components. The company ...
Microsoft Tightens UAC for MSI Repair to Mitigate CVE-2025-50173, Impacting Silent Installs and Per‑User Setups
Microsoft’s August 2025 cumulative security update for Windows (KB5063878) and subsequent releases introduced stricter User Account Control (UAC) enforcement for ...
PromptLock: AI-Powered Ransomware Prototype Validates LLM-Orchestrated Attack Model
ESET has verified that samples of PromptLock uploaded to VirusTotal in late August 2025 were not part of an in-the-wild ...
Salesloft Shuts Down Drift After OAuth Token Theft Exposes SaaS-to-SaaS Risk
Salesloft has temporarily disabled the Drift platform effective September 5 following a large-scale supply chain intrusion in which attackers stole ...
Apple Opens Applications for SRDP 2026: Research iPhones and High-Value Bug Bounties
Apple has opened applications for the Security Research Device Program (SRDP) 2026, its flagship initiative that provides vetted researchers with ...
Phantom Papa phishing campaign delivers Phantom stealer via RAR→IMG/ISO, adds webcam extortion module
In June 2025, researchers documented a new phishing wave dubbed Phantom Papa that distributes the Phantom information stealer. The campaign ...
Drift OAuth Token Theft Expands Beyond Salesforce, Impacts Google Workspace; Mandiant Ties Activity to UNC6395
Google Threat Intelligence (Mandiant) has linked a wave of intrusions to the theft and reuse of OAuth and refresh tokens ...
FreePBX Zero‑Day (CVE-2025-57819) Exploited in the Wild: What to Do Now
Sangoma Technologies has confirmed in-the-wild exploitation of a critical zero‑day in FreePBX, the open-source PBX platform built on Asterisk and ...
Critical Vulnerabilities in Pudu Robotics’ Service Robots Exposed and Remediated
An independent security researcher known as BobDaHacker disclosed critical weaknesses in the Pudu Robotics ecosystem that could allow attackers to ...