The Cyber Express

Foxit Releases Security Updates for PDF Editor Cloud XSS Vulnerabilities

Foxit Software has addressed multiple cross-site scripting (XSS) vulnerabilities in Foxit PDF Editor Cloud and Foxit eSign. These vulnerabilities could allow attackers to execute arbitrary JavaScript within a user's browser.

CrossCurve Bridge Hacked for $3M After Smart Contract Validation Vulnerability Exploited

The CrossCurve bridge suffered a cyberattack resulting in a $3 million loss. Attackers exploited a vulnerability in the smart contract infrastructure, specifically a gateway validation bypass within the ReceiverAxelar contract.

Cyble Research Discovers ShadowHS, an In-Memory Linux Framework for Long-Term Access

ShadowHS is an advanced fileless Linux exploitation framework designed for stealthy, in-memory operations. It enables attackers to maintain long-term access to compromised systems without leaving persistent traces.

Security Researcher Finds Exposed Admin Panel for AI Toy

A critical security vulnerability was discovered in the Bondu AI toy, where an exposed admin panel allowed unauthorized access to sensitive data, including children's personal information and conversation transcripts.

Manage My Health Data Breach Sparks Warnings Over Impersonation and Phishing Attempts

Manage My Health, a widely used digital health platform in New Zealand, experienced a cyberattack that compromised documents stored in the "My Health Documents" section. The breach exposed sensitive documents including clinical letters.

Telecommunications Sector Sees a Four-fold Jump in Ransomware Attacks in last 4 Years: Report

The telecommunications sector experienced a four-fold increase in ransomware attacks over the past 4 years. This sector is a critical component of national infrastructure, making it a prime target for both ransomware groups and nation-state actors.

SlowMist Flags Potential Security Risk at HitBTC Exchange

A critical security vulnerability has been identified at the HitBTC Exchange by the blockchain security researchers. Despite attempts to responsibly disclose the issue, HitBTC has not responded.

Crimson Collective Claims Breach of U.S. Fiber Broadband Provider Brightspeed

The hacking group Crimson Collective has claimed responsibility for a significant data breach involving the U.S. fiber broadband provider Brightspeed. The breach reportedly affects over a million residential customers.

Latest Oracle EBS Victims Include Korean Air, University of Phoenix

The CL0P ransomware group has targeted Oracle EBS vulnerabilities, affecting organizations such as Korean Air and the University of Phoenix. The University of Phoenix reported a breach compromising personal data of nearly 3.5 million individuals.

Japan Adopts New Cybersecurity Strategy to Counter Rising Cyber Threats

The new strategy identifies cyber operations linked to China, Russia, and North Korea as significant threats. These attacks have targeted public institutions, private companies, and essential services, leveraging advanced technologies like AI.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags