Bleeping Computer

Netgear Warns Users to Patch Critical WiFi Router Vulnerabilities

The two critical security vulnerabilities impact multiple WiFi 6 access points (WAX206, WAX214v2, and WAX220) and Nighthawk Pro Gaming router models (XR1000, XR1000v2, XR500).

DeepSeek AI Tools Impersonated by Info-Stealer Malware on PyPI

According to Positive Technologies researchers who discovered the campaign and reported it to PyPI, the packages posing as Python clients for DeepSeek AI were infostealers that stole data from developers who utilized them.

Google Fixes Android Kernel Zero-Day Exploited in Attacks

This high-severity zero-day (tracked as CVE-2024-53104) is a privilege escalation security flaw in the Android Kernel's USB Video Class driver that allows authenticated local threat actors to elevate privileges in low-complexity attacks.

Time Bandit ChatGPT Jailbreak Bypasses Safeguards on Sensitive Topics

A ChatGPT jailbreak flaw, dubbed "Time Bandit," allows you to bypass OpenAI's safety guidelines when asking for detailed instructions on sensitive topics, including the creation of weapons, information on nuclear topics, and malware creation.

FBI Seizes Cracked.io, Nulled.to Hacking Forums in Operation Talent

The FBI has seized the domains for the infamous Cracked.io and Nulled.to hacking forums, which are known for their focus on cybercrime, password theft, cracking, and credential stuffing attacks.

Solana Pump.fun Tool DogWifTool Compromised to Drain Crypto Wallets

Hackers have compromised the Windows version of the DogWifTools software for promoting meme coins on the Solana blockchain in a supply-chain attack that drained users' wallets.

Laravel Admin Package Voyager Vulnerable to One-Click RCE Flaw

Since the three flaws SonarQube discovered remain unpatched, Voyager users should consider restricting access to trusted users only, limiting "browse_media" permissions to prevent unauthorized file uploads, and using RBAC to minimize exposure.

New Aquabotv3 Botnet Malware Targets Mitel Command Injection Flaw

The malware family was introduced in 2023, and a second version that added persistence mechanisms was released later. The third variant, 'Aquabotv3,' introduced a system that detects termination signals and sends the info to the C2 server.

New Apple CPU Side-Channel Attacks Steal Data From Browsers

The FLOP and SLAP side-channel attacks target features aimed at speeding up processing by guessing future instructions instead of waiting for them can leave traces in memory to extract sensitive information.

Apple Fixes This Year’s First Actively Exploited Zero-Day Vulnerability

The zero-day fixed today is tracked as CVE-2025-24085 [iOS/iPadOS, macOS, tvOS, watchOS, visionOS] and is a privilege escalation security flaw in Apple's Core Media framework.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags