HackRead

Years-Old Vulnerable Apache Struts 2 Versions See 387K Weekly Downloads

A critical vulnerability, CVE-2025-68493, has been identified in Apache Struts 2, affecting versions 2.0.0 through 6.1.0. This flaw, discovered by Zast AI, involves unsafe XML parsing in the XWork component, which can lead to system crashes.

GhostPoster Browser Malware Hid for 5 Years With 840,000 Installs

The GhostPoster malware campaign has been active for five years, affecting over 840,000 users through browser extensions on Chrome, Firefox, and Edge. The malware uses hidden payloads within PNG images to evade detection.

New PayPal Scam Sends Verified Invoices With Fake Support Numbers

A sophisticated phishing scam is leveraging PayPal's legitimate invoice system to deceive users by sending verified invoices with fake support numbers. This scam bypasses traditional email security filters, posing a significant threat to users.

Major Data Breach Hits Company Operating 150 Gas Stations in the US

A major data breach has impacted Gulshan Management Services, a Texas-based company operating over 150 gas stations under the Handi Plus and Handi Stop brands. The breach exposed sensitive personal information of more than 377,000 individuals

Researchers Warn of Data Exposure Risks in Claude Chrome Extension

The Claude Chrome extension, developed by Anthropic, poses significant data exposure risks. This extension allows AI to browse and interact with websites on behalf of users, potentially bypassing traditional web security measures.

FBI Seizes Fake ID Template Domains Operating from Bangladesh

The FBI has successfully dismantled an online marketplace operated by Zahid Hasan from Bangladesh, which sold fake ID templates. This operation, known as TechTreek, involved the sale of digital templates for fraudulent identification documents.

Hackers Abuse Popular Monitoring Tool Nezha as a Stealth Trojan

Hackers have been using Nezha with scripts containing Simplified Chinese messages, and their command center is hosted on Alibaba Cloud services in Japan. This activity is part of a broader trend of digital warfare.

Frogblight Malware Targets Android Users With Fake Court and Aid Apps

Frogblight is a newly identified Android malware targeting users in Turkiye. It spreads through smishing attacks, masquerading as legitimate court and aid applications. The malware uses the Turkish name 'Davalar?m' to appear legitimate.

New PyStoreRAT Malware Targets OSINT Researchers Through GitHub

PyStoreRAT is a newly identified malware targeting OSINT researchers and IT professionals through GitHub. It is distributed via fake OSINT tools and other software, leveraging AI to build trust and evade detection.

ChrimeraWire Trojan Fakes Chrome Activity to Manipulate Search Rankings

ChrimeraWire trojan manipulates search engine rankings by simulating user activity through Chrome. Unlike traditional malware, it focuses on boosting the visibility of specific websites in search results rather than stealing data or encrypting files.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags