TP-Link Network Video Recorder Vulnerability Enables Arbitrary Command Execution
24
Jul
2025

TP-Link Network Video Recorder Vulnerability Enables Arbitrary Command Execution

TP-Link has disclosed critical security vulnerabilities affecting two of its VIGI Network Video Recorder models, potentially allowing attackers to execute…

Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace
24
Jul
2025

Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace

Europol on Monday announced the arrest of the suspected administrator of XSS.is (formerly DaMaGeLaB), a notorious Russian-speaking cybercrime platform. The…

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog
24
Jul
2025

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini July 24, 2025…

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks
24
Jul
2025

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks

CISA has issued an urgent warning about a critical vulnerability in Google Chromium that threat actors are actively exploiting.  The…

AWS Client VPN for Windows Vulnerability Could Allow Privilege Escalation
24
Jul
2025

AWS Client VPN for Windows Vulnerability Could Allow Privilege Escalation

Amazon Web Services has disclosed a critical security vulnerability in its Client VPN software for Windows that could allow non-administrative…

Company Sues Cognizant For $380 Million
24
Jul
2025

Company Sues Cognizant For $380 Million

Clorox, cleaning products giant has filed a lawsuit against IT services provider Cognizant, blaming the company for a massive Clorox…

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset 'root' Passwords
24
Jul
2025

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset ‘root’ Passwords

UNC3944, a financially driven threat organization associated with “0ktapus,” “Octo Tempest,” and “Scattered Spider,” launched a sophisticated cyber campaign that…

Weidmueller Industrial Routers Exposed to Remote Code Execution Flaws
24
Jul
2025

Weidmueller Industrial Routers Exposed to Remote Code Execution Flaws

Multiple high-severity security vulnerabilities have been discovered in Weidmueller Industrial Routers, potentially allowing attackers to execute arbitrary code with root…

Why outsourcing cybersecurity is rising in the Adriatic region
24
Jul
2025

Why outsourcing cybersecurity is rising in the Adriatic region

In this Help Net Security interview, Aleksandar Stančin, Board Member Adriatics, Exclusive Networks, discusses the state of cybersecurity in the…

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access
24
Jul
2025

Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access

Jul 24, 2025Ravie LakshmananCybersecurity / Web Security Cybersecurity researchers have uncovered a new stealthy backdoor concealed within the “mu-plugins” directory…

CISA Alerts on Google Chromium Input Validation Flaw Actively Exploited
24
Jul
2025

CISA Alerts on Google Chromium Input Validation Flaw Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe input validation vulnerability in Google…

Autoswagger: Open-source tool to expose hidden API authorization flaws
24
Jul
2025

Autoswagger: Open-source tool to expose hidden API authorization flaws

Autoswagger is a free, open-source tool that scans OpenAPI-documented APIs for broken authorization vulnerabilities. These flaws are still common, even…