Malicious PyPI Package Used by Hackers to Steal Users’ Crypto Information
24
Nov
2025

Malicious PyPI Package Used by Hackers to Steal Users’ Crypto Information

Cybersecurity researchers have uncovered a sophisticated supply-chain attack targeting Python developers through a malicious package distributed via the Python Package…

New ‘IndonesianFoods’ worm floods npm with 100,000 packages
24
Nov
2025

Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub

Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the…

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods
24
Nov
2025

APT35 Hacker Groups Internal Documents Leak Exposes their Targets and Attack Methods

In October 2025, a significant breach exposed the internal workings of APT35, also known as Charming Kitten, a cyber unit…

Amazon Is Using Specialized AI Agents for Deep Bug Hunting
24
Nov
2025

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

As generative AI pushes the speed of software development, it is also enhancing the ability of digital attackers to carry…

PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE
24
Nov
2025

PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE

Security researchers have published a proof-of-concept exploit for a critical remote code execution vulnerability in W3 Total Cache, one of…

True Cybersecurity Story: How FreakyClown Robs Banks
24
Nov
2025

True Cybersecurity Story: How FreakyClown Robs Banks

24 Nov True Cybersecurity Story: How FreakyClown Robs Banks Posted at 08:43h in Blogs by Taylor Fox This week in…

UK digital bank Revolut sees value jump £23bn in a year
24
Nov
2025

UK digital bank Revolut sees value jump £23bn in a year

Digital bank Revolut has been valued at £57bn, just over a decade after it launched as an app that reduced…

Attackers deliver ShadowPad via newly patched WSUS RCE bug
24
Nov
2025

Attackers deliver ShadowPad via newly patched WSUS RCE bug

Attackers deliver ShadowPad via newly patched WSUS RCE bug Pierluigi Paganini November 24, 2025 Attackers exploited a patched WSUS flaw…

Prompt Injection Isn't a Vulnerability · Joseph Thacker
24
Nov
2025

Prompt Injection Isn’t a Vulnerability · Joseph Thacker

OKAY. OKAY. OKAY. It can be a vulnerability. But it’s almost never the root cause. I think we need to…

Windows 11 KB5068861 & KB5068865 cumulative updates released
24
Nov
2025

Microsoft tests File Explorer preloading for faster performance

Microsoft is testing a new optional feature that preloads File Explorer in the background to improve launch times and performance…

Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User
24
Nov
2025

Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User

Tenda N300 wireless routers and 4G03 Pro portable LTE devices face severe security threats from multiple command injection vulnerabilities that…

Iberia Airlines Hit by Data Breach Exposing Customer Personal Details
24
Nov
2025

Iberia Airlines Hit by Data Breach Exposing Customer Personal Details

Iberia Líneas Aéreas de España has disclosed a significant security incident involving unauthorized access to systems operated by an external…