News
Entertainment
Science & Technology
Sport
Business & Money
Life
Culture & Art
Hobbies
8 | Follower
Security Affairs
03.02.2025
U.S. and Dutch authorities seized 39 domains and servers linked to the HeartSender cybercrime group based in Pakistan.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free.
Meta announced the disruption of a malware campaign via WhatsApp that targeted journalists with the Paragon spyware.
Texas bans DeepSeek and RedNote on government devices to block Chinese data-harvesting AI, citing security risks.
02.02.2025
The New York Blood Center faced a ransomware attack on Sunday, forcing the healthcare organization to reschedule appointments.
Indian multinational technology company Tata Technologies suspended some IT services following a ransomware attack.
01.02.2025
Italy's data protection authority Garante blocked the DeepSeek AI service due to insufficient transparency regarding user data process.
Broadcom patched 5 flaws in VMware Aria Operations and Aria Operations for Logs that could lead to privilege escalation and credential theft.
Community Health Center (CHC) data breach impacted over 1 million patients in Connecticut, the healthcare provider started notifying them.
The U.S. CISA and the FDA warned of a hidden backdoor in Contec CMS8000 and Epsimed MN-120 patient monitors.
31.01.2025
Chinese AI platform DeepSeek has publicly exposed two databases containing highly sensitive user and backend details.
Open-source PHP package Voyager is affected by three vulnerabilities that could be exploited to achieve one-click RCE on affected instances
TeamViewer has patched a high-severity privilege escalation vulnerability affecting its Windows client and host applications.
An international law enforcement operation targeted several major cybercriminals sites, including Cracked, Nulled, Sellix, and StarkRDP.
Italy’s data privacy regulator Garante has requested information from Chinese AI company DeepSeek regarding its data practices.
30.01.2025
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple products' flaw to its Known Exploited Vulnerabilities catalog.
A new variant of the Mirai-based botnet Aquabot targets vulnerable Mitel SIP phones to recruit them into a DDoS botnet.
A critical flaw in Cacti open-source network monitoring and fault management framework that could allow remote code execution.
Experts warn that threat actors are actively exploiting critical zero-day, tracked as CVE-2024-40891, in Zyxel CPE Series devices.
29.01.2025
ENGlobal reported to the SEC that personal information was compromised in a ransomware attack that took place in November 2024.
Threat actors exploit recently fixed SimpleHelp RMM software vulnerabilities to breach targeted networks, experts warn.
The EU sanctioned three members of Russia's GRU Unit 29155 for cyberattacks on Estonia's government agencies in 2020.
VMware fixed a high-risk blind SQL injection vulnerability in Avi Load Balancer, allowing attackers to exploit databases via crafted queries.
28.01.2025
Threat actors behind ESXi ransomware attacks target virtualized environments using SSH tunneling to avoid detection.
Crooks stole at least $69 million from Singapore-based cryptocurrency platform Phemex in an alleged cyberattack.
A threat actor called GamaCopy mimics Russia-linked Gamaredon APT in attacks on Russian-speaking targets.....
Apple addressed the first zero-day vulnerability of 2025, which is actively exploited in attacks in the wild aimed at iPhone users.
UK telecommunications firm TalkTalk disclosed a data breach after a threat actor announced the hack on a cybercrime forum.
Chinese AI company DeepSeek has disabled registrations for its DeepSeek-V3 chat platform following a "large-scale" cyberattack.
Vulnerabilities in the Git credential retrieval protocol could have allowed threat actors to access user credentials.
27.01.2025
The Change Healthcare data breach is worse than initially estimated: approximately 190 million people have been affected.
26.01.2025
Cisco fixed a ClamAV denial-of-service (DoS) vulnerability, and experts warn of the availability of a proof-of-concept (PoC) exploit code.
A flaw in Subaru's Starlink connected vehicle service left cars and customer accounts in the US, Canada, and Japan exposed to remote attacks
The Pwn2Own Automotive 2025 hacking contest has ended, and participants earned $886,250 after demonstrating 49 zero-day flaws.
25.01.2025
U.S. CISA added SonicWall SMA1000 AMC and CMC vulnerability to its Known Exploited Vulnerabilities catalog.
Threat actors are targeting Juniper routers with a custom backdoor in a campaign tracked as named "J-magic."
SonicWall warns customers of a critical zero-day vulnerability in SMA 1000 Series appliances, likely exploited in the wild.