Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks post, juli 21, 2025juli 23, 2025 Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called “ToolShell,” which enabled them to achieve remote code execution in Microsoft SharePoint. These… Continue Reading
3,500 Websites Hijacked to Secretly Mine Crypto Using Stealth JavaScript and WebSocket Tactics post, juli 21, 2025 A new attack campaign has compromised more than 3,500 websites worldwide with JavaScript cryptocurrency miners, marking the return of browser-based cryptojacking attacks once popularized by the likes of CoinHive. Although the service has since shuttered after browser makers took steps to ban miner-related apps and add-ons, researchers from the c/side said they found… Continue Reading
PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse post, juli 21, 2025 Cybersecurity researchers have disclosed a novel attack technique that allows threat actors to bypass Fast IDentity Online (FIDO) key protections by deceiving users into approving authentication requests from spoofed company login portals. FIDO keys are hardware- or software-based authenticators designed to eliminate phishing by binding logins to specific domains using… Continue Reading
Global hack on Microsoft product hits U.S., state agencies, researchers say post, juli 20, 2025juli 21, 2025 Unknown attackers exploited a “significant vulnerability” in Microsoft’s SharePoint collaboration software, hitting targets around the world. Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities,… Continue Reading
National Guard hacked by Chinese ‘Salt Typhoon’ campaign for nearly a year, DHS memo says post, juli 15, 2025juli 24, 2025 An elite Chinese cyberspy group hacked at least one state’s National Guard network for nearly a year, the Department of Defense has found. The hackers, already responsible for one of the most expansive cyberespionage campaigns against the U.S. to date, are alleged to have burrowed even further than previously known… Continue Reading
Israel Says Iran Is Hacking Security Cameras for Spying post, juli 11, 2025 Israeli officials said this week that Iran is compromising private security cameras around Israel to conduct espionage as the two countries exchange missile strikes after an initial Israeli barrage. A former Israeli cybersecurity official warned on public radio this week that Israelis should confirm that their home security cameras are… Continue Reading
Vier jongeren opgepakt voor hacken Britse winkelketens post, juli 10, 2025juli 11, 2025 Vier Britse jongeren zijn gearresteerd voor een cyberaanval op enkele bekende Britse winkelketens. Dat hebben de Britse autoriteiten bekendgemaakt. Het gaat om een vrouw en drie mannen. Ze zijn tussen de 17 en 20 jaar oud. Ze worden verdacht van onder meer chantage en deelname aan georganiseerde criminaliteit. De verdachten… Continue Reading
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’ post, juli 9, 2025juli 11, 2025 If you want a job at McDonald’s today, there’s a good chance you’ll have to talk to Olivia. Olivia is not, in fact, a human being, but instead an AI chatbot that screens applicants, asks for their contact information and résumé, directs them to a personality test, and occasionally makes them “go insane”… Continue Reading
Manufacturing Security: Why Default Passwords Must Go post, juli 7, 2025 If you didn’t hear about Iranian hackers breaching US water facilities, it’s because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn’t its scale, but how easily the hackers gained access — by simply using the manufacturer’s default password “1111.” This narrow escape… Continue Reading
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros post, juli 4, 2025 Cybersecurity researchers have disclosed two security flaws in the Sudo command-line utility for Linux and Unix-like operating systems that could enable local attackers to escalate their privileges to root on susceptible machines. A brief description of the vulnerabilities is below – Continue Reading