A newly discovered WinRAR zero-day flaw has been exploited in active phishing campaigns by the RomCom hacking group. The vulnerability allows attackers to execute malicious files automatically at system startup. Security experts warn users to update immediately to avoid compromise. RomCom Hackers Weaponize WinRAR Vulnerability Security researchers from ESET revealed that the flaw, tracked as…
Microsoft has issued urgent Microsoft Exchange patching advice in response to a high-severity vulnerability that threatens hybrid Exchange deployments. The flaw, tracked as CVE-2025-53786, could let attackers escalate privileges from on-premises servers into connected Microsoft 365 environments. The Cybersecurity and Infrastructure Security Agency (CISA) has backed Microsoft’s warning, issuing an emergency directive for immediate action.…
In a major cybersecurity breach, the Jamco Aerospace ransomware attack has put sensitive supplier data at risk. Jamco Aerospace, a key parts manufacturer for the U.S. Navy, Boeing, and others, faces a potential leak after the Play ransomware group claimed responsibility for the compromise. Who Is Jamco Aerospace? Jamco Aerospace Inc. operates as a precision…
Hackers are now exploiting forgotten Google storage buckets, reclaiming abandoned cloud addresses to inject malware or steal data. Google has issued strong warnings to developers, highlighting the growing danger of dangling bucket attacks. What Are Dangling Bucket Attacks? Dangling bucket attacks occur when a storage bucket is deleted, but references to its name remain in…
A US federal court cyberattack has compromised highly sensitive legal data, raising serious concerns about the security of the nation’s judicial systems. The attack targeted the Case Management/Electronic Case Files (CM/ECF) and the Public Access to Court Electronic Records (PACER) systems, both vital for handling federal case information. Officials warn that attackers may have accessed…
Many cybersecurity professionals worry about their livelihoods. A rising trend toward platform subscriptions and automation displaces routine roles, reshaping the profession. This shift raises serious questions about how professionals can stay relevant in a rapidly evolving landscape. The Platformization Trend in Cybersecurity Companies now favor subscription-based platforms, managed services, and AI-powered tools over internal hiring.…
The Gemini AI hijack via a poisoned Google Calendar invite has raised serious concerns about AI-powered smart home security. Security researchers revealed how an event invite, crafted with hidden malicious prompts, could trick Google’s Gemini AI into controlling devices in a home environment—without the user’s knowledge or consent. How the Attack Works Researchers embedded harmful…
Constitution sections vanish from a key government website in a surprising glitch that temporarily removed important legal provisions from public view. The disappearance affected the Library of Congress’s Constitution Annotated site, a trusted online resource for lawmakers, students, and citizens seeking authoritative information on the U.S. Constitution. The incident sparked confusion, political speculation, and a…
As the Dalai Lama marked his 90th birthday, China-linked hackers launched cyberattacks aimed at Tibetans. These state-sponsored operations used fake apps and cloned websites to deploy spyware. Researchers say the campaigns used culturally themed lures to trick users into installing malware. Victims unknowingly downloaded apps that carried Gh0st RAT or PhantomNet—tools often linked to Chinese…