Category: HackRead

BentoML Vulnerability Allows Remote Code Execution on AI Servers
11
Apr
2025

BentoML Vulnerability Allows Remote Code Execution on AI Servers

TL;DR: A critical deserialization vulnerability (CVSS 9.8 – CVE-2025-27520) in BentoML (v1.3.8–1.4.2) lets attackers execute remote code without authentication. Discovered…

npm Malware Targets Atomic and Exodus Wallets to Hijack Crypto Transfers
11
Apr
2025

npm Malware Targets Atomic and Exodus Wallets to Hijack Crypto Transfers

TL;DR – ReversingLabs has identified a malicious npm package, “pdf-to-office,” that targets Atomic and Exodus crypto wallet users by silently…

Google Eyes User Browsing Data Search in New Patent Filing
10
Apr
2025

Google Eyes User Browsing Data Search in New Patent Filing

TL;DR – Google has filed a patent for a system that lets users search their personal digital history, including web…

Protecting Your Business on the Move: A Modern Security Guide
10
Apr
2025

Protecting Your Business on the Move: A Modern Cybersecurity Guide

Stay secure on the move. Protect your devices, data, and privacy with smart habits, reliable gear, updated software and proper…

Smokeloader Users Identified and Arrested in Operation Endgame
10
Apr
2025

Smokeloader Users Identified and Arrested in Operation Endgame

TL;DR: The hammer’s coming down not just on malware creators but the users funding them. If you paid to compromise…

Hacker Claims WooCommerce Data Breach, Selling 4m User Records
10
Apr
2025

Hacker Claims WooCommerce Data Breach, Selling 4m User Records

A hacker using the alias “Satanic” claims a WooCommerce data breach via a third party, selling data on over 4.4…

New AkiraBot Abuses OpenAI API, Spammed 400K Sites with Fake SEO
09
Apr
2025

New AkiraBot Abuses OpenAI API to Spam Website Contact Forms

Cybersecurity researchers have identified a new spam campaign driven by ‘AkiraBot,’ an AI-powered bot that targets small business websites with…

Hackers Claim Magento Breach via Third-Party, Leak CRM Data of 763K Users
09
Apr
2025

Hackers Claim Magento Breach via Third-Party, Leak CRM Data of 700K Users

A hacker using the alias “Satanic” claims Magento breach via third-party, leaks CRM data of more than 700,000 users, including…

Gcore Super Transit Brings Advanced DDoS Protection and Acceleration for Superior Enterprise Security and Speed
09
Apr
2025

Gcore Super Transit Brings Advanced DDoS Protection and Acceleration for Superior Enterprise Security and Speed

Luxembourg, Luxembourg, April 9th, 2025, CyberNewsWire Gcore, the global edge AI, cloud, network, and security solutions provider, has launched Super…

Grandoreiro Strikes Again: Geofenced Phishing Attacks Target LATAM
09
Apr
2025

Geofenced Phishing Attacks Target LATAM

A new phishing campaign is targeting users across Latin America, and at the center of it is Grandoreiro, a banking…

Medusa Ransomware Claims NASCAR Breach in Latest Attack
09
Apr
2025

Medusa Ransomware Claims NASCAR Breach in Latest Attack

The Medusa ransomware gang has added another high-profile name to its growing list of victims. Earlier today, the group listed…

WhatsApp for Windows Flaw Could Let Hackers Sneak In Malicious Files
08
Apr
2025

WhatsApp for Windows Flaw Could Let Hackers Sneak In Malicious Files

A recent security advisory from Facebook Security highlights a spoofing vulnerability tracked as CVE-2025-30401 affecting WhatsApp for Windows. The flaw…