Category: TheHackerNews

Critical Dahua Camera Flaws
30
Jul
2025

Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits

Jul 30, 2025Ravie LakshmananFirmware Security / Vulnerability Cybersecurity researchers have disclosed now-patched critical security flaws in the firmware of Dahua…

Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools
30
Jul
2025

Chinese Firms Linked to Silk Typhoon Filed 15+ Patents for Cyber Espionage Tools

Jul 30, 2025Ravie LakshmananEndpoint Security / Cyber Espionage Chinese companies linked to the state-sponsored hacking group known as Silk Typhoon…

Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero
30
Jul
2025

Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero

Jul 30, 2025Ravie LakshmananDevice Security / AI Security Google has announced that it’s making a security feature called Device Bound…

Scattered Spider
30
Jul
2025

Scattered Spider Hacker Arrests Halt Attacks, But Copycat Threats Sustain Security Pressure

Jul 30, 2025Ravie Lakshmanan Google Cloud’s Mandiant Consulting has revealed that it has witnessed a drop in activity from the…

Hackers Exploit SAP Vulnerability
30
Jul
2025

Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware

Jul 30, 2025Ravie LakshmananVulnerability / Threat Intelligence Threat actors have been observed exploiting a now-patched critical SAP NetWeaver flaw to…

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain
29
Jul
2025

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

Jul 29, 2025Ravie LakshmananPhishing / Developer Security The maintainers of the Python Package Index (PyPI) repository have issued a warning…

AI-Powered Vibe Coding Platform Base44
29
Jul
2025

Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

Jul 29, 2025Ravie LakshmananLLM Security / Vulnerability Cybersecurity researchers have disclosed a now-patched critical security flaw in a popular vibe…

29
Jul
2025

Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

Jul 29, 2025Ravie LakshmananLLM Security / Vulnerability Cybersecurity researchers have disclosed a now-patched critical security flaw in a popular vibe…

Chaos RaaS
29
Jul
2025

Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew, as…

The New JavaScript Injection Playbook
29
Jul
2025

The New JavaScript Injection Playbook

React conquered XSS? Think again. That’s the reality facing JavaScript developers in 2025, where attackers have quietly evolved their injection…

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia's Mobile Networks
29
Jul
2025

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks

Cybersecurity researchers have discovered a new, large-scale mobile malware campaign that’s targeting Android and iOS platforms with fake dating, social…

Cyber Battleground
29
Jul
2025

How the Browser Became the Main Cyber Battleground

Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:…