Windows logo
24
Jul
2025

SharePoint servers also targeted in ransomware attacks

A Chinese hacking group is deploying Warlock ransomware on Microsoft SharePoint servers vulnerable to widespread attacks targeting the recently patched…

Chinese Hackers Launch Targeted Campaign to Infect Windows Systems with Ghost RAT and PhantomNet Malware
24
Jul
2025

Chinese Hackers Launch Targeted Campaign to Infect Windows Systems with Ghost RAT and PhantomNet Malware

Zscaler ThreatLabz, in collaboration with TibCERT, has uncovered two linked attack campaigns dubbed Operation GhostChat and Operation PhantomPrayers, attributed with…

AI’s uneven distribution widening diversity divide
24
Jul
2025

AI’s uneven distribution widening diversity divide

Access to artificial intelligence (AI) is not equal, widening the opportunity gap for women and lower paid workers, according to…

Google Introduces OSS Rebuild to Boost Security in Open-Source Package Ecosystems
24
Jul
2025

Google Introduces OSS Rebuild to Boost Security in Open-Source Package Ecosystems

Google has unveiled OSS Rebuild, a pioneering project designed to enhance trust in package registries by independently reproducing upstream artifacts….

Metasploit Module Released to Exploit SharePoint 0-Day Vulnerabilities
24
Jul
2025

Metasploit Module Released to Exploit SharePoint 0-Day Vulnerabilities

Security researchers have released a Metasploit exploitation module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server, marking a significant escalation…

TP-Link Network Video Recorder Vulnerability Enables Arbitrary Command Execution
24
Jul
2025

TP-Link Network Video Recorder Vulnerability Enables Arbitrary Command Execution

TP-Link has disclosed critical security vulnerabilities affecting two of its VIGI Network Video Recorder models, potentially allowing attackers to execute…

Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace
24
Jul
2025

Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace

Europol on Monday announced the arrest of the suspected administrator of XSS.is (formerly DaMaGeLaB), a notorious Russian-speaking cybercrime platform. The…

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog
24
Jul
2025

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini July 24, 2025…

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks
24
Jul
2025

CISA warns of Google Chromium 0-Day Input Validation Vulnerability Exploited in Attacks

CISA has issued an urgent warning about a critical vulnerability in Google Chromium that threat actors are actively exploiting.  The…

AWS Client VPN for Windows Vulnerability Could Allow Privilege Escalation
24
Jul
2025

AWS Client VPN for Windows Vulnerability Could Allow Privilege Escalation

Amazon Web Services has disclosed a critical security vulnerability in its Client VPN software for Windows that could allow non-administrative…

Company Sues Cognizant For $380 Million
24
Jul
2025

Company Sues Cognizant For $380 Million

Clorox, cleaning products giant has filed a lawsuit against IT services provider Cognizant, blaming the company for a massive Clorox…

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset 'root' Passwords
24
Jul
2025

UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset ‘root’ Passwords

UNC3944, a financially driven threat organization associated with “0ktapus,” “Octo Tempest,” and “Scattered Spider,” launched a sophisticated cyber campaign that…