Category: Uncategorized
-

SaaS Breaches Start with Tokens – What Security Teams Must Watch [email protected] (The Hacker News)
Token theft is a leading cause of SaaS breaches. Discover why OAuth and API tokens are often overlooked and how security teams can strengthen token hygiene to prevent attacks. Most companies in 2025 rely on a whole range of software-as-a-service (SaaS) applications to run their operations. However, the security of these applications depends on small…
-

From Phishing to Malware: AI Becomes Russia’s New Cyber Weapon in War on Ukraine [email protected] (The Hacker News)
Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has reached a new level in the first half of 2025 (H1 2025), the country’s State Service for Special Communications and Information Protection (SSSCIP) said. “Hackers now employ it not only to generate phishing messages, but some of the malware samples we have…
-

Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme [email protected] (The Hacker News)
Threat actors are actively exploiting a critical security flaw impacting the Service Finder WordPress theme that makes it possible to gain unauthorized access to any account, including administrators, and take control of susceptible sites. The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects the Service Finder Bookings, a WordPress plugin bundled with theRead…
-

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks [email protected] (The Hacker News)
Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. “Site visitors get injected content that was drive-by malware like fake Cloudflare verification,” Sucuri researcher Puja Srivastava said in an analysis published last week. The website security companyRead More
-
What CISOs should know about DeepSeek cybersecurity risks
DeepSeek poses significant risks to U.S. enterprises — even those that don’t greenlight it for internal use. CISOs should take steps to reduce the threat.Read More
-

Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave [email protected] (The Hacker News)
Threat actors with suspected ties to China have turned a legitimate open-source monitoring tool called Nezha into an attack weapon, using it to deliver a known malware called Gh0st RAT to targets. The activity, observed by cybersecurity company Huntress in August 2025, is characterized by the use of an unusual technique called log poisoning (aka…
-

LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem [email protected] (The Hacker News)
Three prominent ransomware groups DragonForce, LockBit, and Qilin have announced a new strategic ransomware alliance, once underscoring continued shifts in the cyber threat landscape. The coalition is seen as an attempt on the part of the financially motivated threat actors to conduct more effective ransomware attacks, ReliaQuest said in a report shared with The Hacker…
-

Step Into the Password Graveyard… If You Dare (and Join the Live Session) [email protected] (The Hacker News)
Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t need advanced tools; they just need one careless login. For IT teams, that means endless resets, compliance struggles, and sleepless nights worrying about the next credential leak. This Halloween, The Hacker News and Specops…
-

Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a now-patched vulnerability in the popular figma-developer-mcp Model Context Protocol (MCP) server that could allow attackers to achieve code execution. The vulnerability, tracked as CVE-2025-53967 (CVSS score: 7.5), is a command injection bug stemming from the unsanitized use of user input, opening the door to a scenario where an…
-
Top 15 IT security frameworks and standards explained
Several IT security frameworks and standards exist to help protect company data. Here’s advice for choosing the right ones for your organization.Read More
