Vulnerabilities, Data Breach News
June 02, 2025
891 views 29 secs 0

0day for vBulletin: PoC is already online, but no one is installing the patch

When criminals note that there is an unpatched vulnerability, expect more attacks to follow. A Russian-language forum recently picked up a report from SecurityLab.ru. It begins (translation): Popular forums on vBulletin have once again been found to have holes through which arbitrary code can be executed directly on the server – without a login and […]

Consumer Alerts, Malware Ransomware, Vulnerabilities
May 18, 2025
402 views 57 secs 0

Be Careful What You Search For — Crypto Hackers Are Watching

Forbes reports: When you think of cybercriminal actors watching you, maybe phishing threats such as Hello Pervert, where the attacker claims to know where you live and has proof to back it up, spring to mind. Or how about the ransomware gang that has been found to install employee monitoring software to watch victims at work? Recent reports […]

Consumer Alerts, Vulnerabilities
April 24, 2025
1140 views 32 secs 0

Millions of KIA cars at serious risk of being hacked – they only need to know the car’s license plate number to open and start the car

All it took was knowing the license plate, and millions of KIA cars could be hacked in a matter of seconds.   Unión Rayo reports that ethical researchers Sam Curry and Neiko Rivera found the vulnerability. It all starts with the portal Kia offers so users can connect their smartphones to the car. From there, they […]

Data Breach News, News, Vendor News, Vulnerabilities
April 19, 2025
1270 views 2 mins 0

100,000 Americans Exposed As Hertz Warns Customers’ Names, Contact Details, Credit Card Information, Social Security Numbers Leaked in Vendor’s Data Breach

The Daily Hodl reports: A car rental giant says sensitive customer data has been exposed in a cybersecurity incident involving one of its vendors. In a notice posted on its website, Hertz says that its vendor, Cleo Communications US, witnessed a zero-day vulnerability exploit late last year that enabled thieves to siphon customer data. Notifications on various […]

Vulnerabilities, News
April 05, 2025
1121 views 49 secs 0

CISA warns of latest Ivanti firewall bug being exploited by suspected Chinese hackers

The Record reports: Another vulnerability impacting firewall products from Ivanti is being exploited by alleged China-based hackers. An Ivanti advisory released on Thursday confirmed that a “limited number of customers” have been attacked through a bug impacting its Connect Secure, Policy Secure & ZTA Gateways tools — which are used by large organizations and government clients to […]

Vulnerabilities, News
February 19, 2025
971 views 3 secs 0

Palo Alto Networks warns of another firewall vulnerability under attack by hackers

TechCrunch reports: U.S. cybersecurity giant Palo Alto Networks has warned that hackers are exploiting another vulnerability in its firewall software to break into unpatched customer networks. Attackers are exploiting a recently disclosed vulnerability in PAN-OS, the operating system that runs Palo Alto Networks firewalls, the California-based company confirmed on Tuesday. Cybersecurity firm Assetnote first discovered the vulnerability, […]

Vulnerabilities
February 18, 2025
885 views 19 secs 0

Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers

GBHackers reports that researchers have uncovered malware targeting WordPress websites, leveraging hidden backdoors to enable remote code execution (RCE): One notable case involved attackers embedding malicious scripts within the Must-Use Plugins (mu-plugins) directory, a special WordPress folder that automatically loads plugins on every page load without requiring activation. By placing obfuscated PHP code in this directory, attackers […]

Data Breach News, Cyberattack, Vulnerabilities
February 16, 2025
931 views 0 secs 0

China-linked APT Salt Typhoon has breached more U.S. telecommunications providers via unpatched Cisco IOS XE network devices.

Security Affairs reports: China-linked APT group Salt Typhoon is still targeting telecommunications providers worldwide, and according to a new report published by Recorded Future’s Insikt Group, the threat actors has breached more U.S. telecommunications providers by exploiting unpatched Cisco IOS XE network devices. Insikt Group researchers reported that the Chinese hacked have exploited two Cisco flaws, tracked […]