Category: Cyber Security


  • UNC6671 Linked to Vishing Attacks on Hedge Funds and Private Equity Firms

    A wave of cyberattacks targeting hedge funds, private-equity companies and other financial organisations has been linked to the UNC6671 extortion group. Recent reports said attackers targeted Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several private-equity firms. The campaigns reportedly relied on voice phishing, or vishing, to trick employees into giving attackers access…

  • Germany Urges Website Operators to Publish security.txt Files

    Germany’s federal cybersecurity agency is calling on businesses, public bodies and website administrators to publish a security.txt file on their websites. The Bundesamt für Sicherheit in der Informationstechnik, better known as BSI, says the simple measure can make responsible vulnerability reporting much faster. It also gives organisations less time to react before attackers discover and…

  • WebKit IP Leaks Can Expose iOS and macOS Users Behind Private Relay and Tor

    Security researchers have found WebKit IP leaks that can reveal the real network addresses of iOS and macOS users, even when they use browser-level proxies, iCloud Private Relay, or some Tor-based browsers. The findings come from Mysk, a privacy-focused development team that investigated reports of DNS leaks in its Psylo browser. According to the researchers,…

  • Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison

    Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in attacks against at least 18 companies worldwide. The US Department of Justice announced the sentence on August 5. The 40-year-old Belarusian national was convicted of conspiracy to commit offences against the…

  • Hackers Hide Khunt Toolkit Inside Oracle Database After SQL Injection Attack

    Researchers have uncovered an Oracle database attack in which hackers used a SQL injection flaw to install a post-exploitation toolkit directly inside a database. The incident shows how attackers can turn a vulnerable public-facing application into a path for deeper network access. Instead of dropping standard malware files on the server, the group stored Java…

  • CISA Warns of Active Exploits Targeting Langflow, N-central and Tomcat

    The US Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities affecting IBM Langflow, N-able N-central, and Apache Tomcat to its Known Exploited Vulnerabilities catalog. Federal agencies have been given three days to apply available mitigations. The vulnerabilities could allow attackers to run code remotely, hijack administrative accounts, or gain a foothold…

  • Tails Linux Fixes Critical Flaw That Could Deanonymize Users

    Tails has released an emergency update for a critical Linux kernel flaw that could allow a malicious website to take control of a user’s system and expose their identity. The privacy-focused operating system urges users to upgrade to Tails 7.10.1 immediately. Earlier versions remain vulnerable to CVE-2026-64560, a flaw that could give Tor Browser administrator-level…

  • Zbtlink Routers Contain Backdoor, Researchers Warn

    More than 20 models of Zbtlink routers reportedly contain a hidden backdoor that could allow remote access to the networks they serve, cybersecurity researchers have warned. The affected devices are sold worldwide under the Zbtlink and Wiflyer brands. VulnCheck estimates that at least 100,000 of the routers have been deployed in homes, small businesses, and…

  • Windows 11 Service Sparks Spying Fears, Microsoft Responds

    A Windows 11 service has sparked online concerns after a viral post claimed it monitors users’ PCs and regularly sends information to Microsoft. The service, called Windows Health and Optimized Experiences, runs in the background and checks for local performance, power, and heat issues. However, Microsoft says the diagnostic information stays on the device unless…

  • npm Worm Infects 444 Packages With 2 Billion Monthly Downloads

    A new npm worm has infected at least 444 software packages and more than 2,000 package versions, putting applications with over two billion combined monthly installs at risk. The malware is spreading through stolen developer credentials and automatically poisoning additional packages. Security researchers warn that affected organisations should assume their systems and secrets may have…