Beware of Fake Chinese E-Commerce Sites Imitating Apple, Wrangler, and Exploiting Payment Services like MasterCard and PayPal
03
Jul
2025

Beware of Fake Chinese E-Commerce Sites Imitating Apple, Wrangler, and Exploiting Payment Services like MasterCard and PayPal

A sophisticated phishing campaign, initially spotlighted by Mexican journalist Ignacio Gómez Villaseñor, has evolved into a sprawling global threat, as…

Grafana releases critical security update for Image Renderer plugin
03
Jul
2025

Grafana releases critical security update for Image Renderer plugin

Grafana Labs has addressed four Chromium vulnerabilities in critical security updates for the Grafana Image Renderer plugin and Synthetic Monitoring…

Citrix Warns Authentication Failures Following The Update of NetScaler to Fix Auth Vulnerability
03
Jul
2025

Citrix Warns Authentication Failures Following The Update of NetScaler to Fix Auth Vulnerability

Citrix has issued an urgent advisory warning customers of widespread authentication failures following recent updates to NetScaler builds 14.1.47.46 and…

Big Tech’s Mixed Response to U.S. Treasury Sanctions – Krebs on Security
03
Jul
2025

Big Tech’s Mixed Response to U.S. Treasury Sanctions – Krebs on Security

In May 2025, the U.S. government sanctioned a Chinese national for operating a cloud provider linked to the majority of…

New Hpingbot Exploits Pastebin for Payload Delivery and Uses Hping3 for DDoS Attacks
03
Jul
2025

New Hpingbot Exploits Pastebin for Payload Delivery and Uses Hping3 for DDoS Attacks

NSFOCUS Fuying Lab’s Global Threat Hunting System has discovered a new botnet family called “hpingbot” that has been quickly expanding…

Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams
03
Jul
2025

Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams

A mobile ad fraud operation dubbed IconAds that consisted of 352 Android apps has been disrupted, according to a new…

Questions mount as Ivanti tackles another round of zero-days
03
Jul
2025

China-linked attacker hit France’s critical infrastructure via trio of Ivanti zero-days last year

Multiple critical infrastructure sectors were hit last year during an attack spree in France via a trio of zero-day vulnerabilities…

Microsoft SharePoint
03
Jul
2025

Microsoft investigates ongoing SharePoint Online access issues

​Microsoft is investigating an ongoing incident causing intermittent issues for users attempting to access SharePoint Online sites. Part of the…

AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones
03
Jul
2025

AI Tools Like GPT Direct Users to Phishing Sites Instead of Legitimate Ones

The popular artificial intelligence tools, including GPT models and Perplexity AI, are inadvertently directing users to phishing websites instead of…

Threat Actors Exploit .COM TLD to Host Widespread Credential Phishing Sites
03
Jul
2025

Threat Actors Exploit .COM TLD to Host Widespread Credential Phishing Sites

Threat actors have dramatically increased their exploitation of the cybersecurity sector, which is a disturbing development. Spain’s country code TLD,…

Google open-sources privacy tech for age verification
03
Jul
2025

Google open-sources privacy tech for age verification

Age verification is becoming more common across websites and online services. But many current methods require users to share personal…

[tl;dr sec] #286 - Securing Vibe Coding, Finding Secrets "Oops Commits", Backdooring IDE Extensions
03
Jul
2025

[tl;dr sec] #286 – Securing Vibe Coding, Finding Secrets “Oops Commits”, Backdooring IDE Extensions

Rules files to vibe securely, earning $25K from dangling commits, compromising the extension marketplace of Cursor, Windsurf, and other VS…