Latest Cybersecurity News and Articles

Bloomberg Comdb2 null pointer dereference and denial-of-service vulnerabilities

Researchers identified five critical vulnerabilities in Bloomberg’s Comdb2 version 8.1, an open-source clustered database system. These flaws can be exploited remotely to cause denial-of-service (DoS) conditions via specially crafted TCP packets.

New VoIP Botnet Targets Routers Using Default Passwords

A newly discovered botnet campaign is exploiting VoIP-enabled routers by leveraging default password attacks over Telnet. Initially detected in a small New Mexico community, the operation has since expanded globally, compromising over 500 devices.

IR35 advisor Qdos confirms a data leak to techie clients

Qdos, a UK-based business insurance and employment status specialist serving tech contractors, has confirmed a data breach involving unauthorized access to one of its web applications, mygoqdos.com.

Tridium Niagara Framework Flaws Expose Sensitive Network Data

Researchers uncovered 13 critical vulnerabilities in the Niagara Framework, developed by Tridium. These flaws, consolidated into 10 CVEs, affect building management, industrial automation, and smart infrastructure systems globally.

Morgan County 911 emergency services confirms ransomware attack via Qilin

Morgan County 911, based in Decatur, Alabama, confirmed a ransomware attack by the Qilin group in May 2025. While administrative systems were disrupted, critical dispatch operations remained unaffected.

Toptal caught serving malware after GitHub compromise

A recent supply chain attack compromised Toptal’s GitHub account, resulting in the distribution of malware through its Picasso developer toolbox. The attack affected over 5,000 downloads and involved 10 npm packages.

NASCAR notifies data breach victims after cybercriminals demand $4 million ransom

NASCAR experienced a data breach. The Medusa ransomware group claimed responsibility, demanding a $4 million ransom with a deadline around April 19. The breach exposed names and Social Security numbers of an undisclosed number of individuals.

North Providence, RI notifies 1,800 people of data breach, cyber attackers demand $100K

North Providence, Rhode Island, has disclosed a ransomware attack that compromised the personal data of 1,804 individuals. The Medusa ransomware group claimed responsibility and demanded a $100,000 ransom.

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

A sophisticated cyber espionage campaign by Fire Ant has targeted VMware ESXi hosts, vCenter servers, and network appliances. This activity is part of a broader trend of persistent targeting of network edge devices by China-linked threat actors.

Surge in Phishing Attacks Exploiting Spoofed SharePoint Domains and Sneaky 2FA Tactics

A recent wave of phishing campaigns has been observed exploiting spoofed Microsoft SharePoint domains and abusing legitimate hosting platforms to harvest user credentials.hese campaigns employ structured domain naming conventions.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags