TalkTalk Investigates Data Breach Linked to Third-Party Supplier
UK telecommunications company TalkTalk is investigating a potential data breach involving a third-party supplier after a threat actor began offering alleged customer data for sale on a hacking forum.
Bijay Pokharel,
January 26, 2025
1 min read
UnitedHealth Confirms Ransomware Attack Affected 190 Million Americans, Nearly Doubling Earlier Estimates
UnitedHealth has confirmed that the cyberattack on its subsidiary, Change Healthcare, last February impacted around 190 million people—almost double the initial estimate.
Bijay Pokharel,
January 25, 2025
2 min read
Security Flaw in Subaru’s Starlink Exposed Vehicles to Remote Hijacking
Security researchers uncovered a critical vulnerability in Subaru’s Starlink service that could have allowed attackers to hijack and control vehicles in the U.S., Canada, and Japan using only a license plate number.
Bijay Pokharel,
January 25, 2025
2 min read
Critical Security Flaws Discovered in Popular WordPress Real Estate Tools
Two severe security vulnerabilities have been identified in the RealHome theme and Easy Real Estate plugin for WordPress, which could allow attackers to gain administrative access to websites without authentication.
Bijay Pokharel,
January 23, 2025
2 min read
High-Severity 7-Zip Vulnerability Exposes Users to Malware Attacks
A critical vulnerability in the 7-Zip file archiver (CVE-2025-0411) has been discovered, enabling attackers to bypass the Mark of the Web (MotW) Windows security feature.
Bijay Pokharel,
January 22, 2025
1 min read
Ransomware Gangs Exploit Microsoft Teams and Email Bombing in Sophisticated Attacks
Ransomware groups are adopting advanced techniques that combine email bombing with fake Microsoft Teams IT support calls to infiltrate company networks.
Bijay Pokharel,
January 22, 2025
1 min read
Cloudflare Mitigates Record-Breaking 5.6 Tbps DDoS Attack Amid Surge in Hyper-Volumetric Assaults
The largest DDoS attack ever recorded reached a colossal 5.6 terabits per second (Tbps), originating from a Mirai-based botnet comprising 13,000 compromised devices.
Bijay Pokharel,
January 22, 2025
2 min read
Russian Hackers Target WhatsApp Accounts in New Spear-Phishing Campaign
A Russian nation-state actor known as Star Blizzard has launched a new spear-phishing campaign aimed at compromising WhatsApp accounts of individuals in key sectors, including government, diplomacy, defense policy, international relations, and Ukraine aid organizations.
Bijay Pokharel,
January 20, 2025
1 min read
FTC Orders GoDaddy to Strengthen Security Measures After Multiple Breaches
The Federal Trade Commission (FTC) has mandated that web hosting giant GoDaddy implement stronger security protections following years of inadequate safeguards.
Bijay Pokharel,
January 17, 2025
1 min read
U.S. Sanctions North Korean IT Networks Funding Weapons Programs
The U.S. Treasury Department has imposed sanctions on a network of individuals and front companies linked to North Korea’s Ministry of National Defense.
Bijay Pokharel,
January 17, 2025
1 min read
Critical Flaw in W3 Total Cache Plugin Threatens Over One Million WordPress Sites
A critical security vulnerability in the W3 Total Cache plugin poses serious risks by potentially exposing sensitive information, including metadata from cloud-based applications.
Bijay Pokharel,
January 17, 2025
1 min read
TikTok, SHEIN, and More Face Legal Complaints Over EU Data Privacy Breaches
Non-profit privacy group None of Your Business (noyb) has filed formal complaints against six major companies—TikTok, AliExpress, SHEIN, Temu, WeChat, and Xiaomi—accusing them of illegally transferring European user data to China.
Bijay Pokharel,
January 17, 2025
2 min read
Cybercriminals Exploit Google Ads to Launch Sophisticated Phishing Scams
Cybercriminals are now leveraging Google search advertisements to promote phishing sites designed to steal advertisers’ credentials for the Google Ads platform.
Bijay Pokharel,
January 16, 2025
2 min read
Willow Pays Data Breach Exposes Over 240,000 Records Online
Cybersecurity researcher Jeremiah Fowle uncovered a major data breach involving Willow Pays, a fintech company specializing in AI-powered payment solutions.
Bijay Pokharel,
January 15, 2025
1 min read
US SEC Files Lawsuit Against Musk Ahead of Trump Inauguration
Just days ahead of Donald Trump’s inauguration as the 47th US President, the Securities and Exchange Commission (SEC) has filed a lawsuit against his best ally, Elon Musk, over an alleged securities violation related to his acquisition of Twitter (now called X) in 2022.
Bijay Pokharel,
January 15, 2025
2 min read
FBI Eliminates PlugX Malware from Over 4,200 U.S. Computers in Major Takedown
The U.S. Department of Justice has revealed that the FBI successfully removed the Chinese PlugX malware from over 4,200 infected computers across the United States.
Bijay Pokharel,
January 15, 2025
2 min read
5,000+ WordPress Sites Compromised in New Malware Campaign
A new malware campaign has compromised over 5,000 WordPress websites, allowing attackers to create unauthorized admin accounts, install malicious plugins, and steal sensitive data.
Bijay Pokharel,
January 15, 2025
1 min read
North Korean Hackers Stole $659 Million in Cryptocurrency in 2024, Report Reveals
A joint report by the United States, Japan, and South Korea has revealed that North Korean hackers stole $659 million in cryptocurrency through multiple heists in 2024.
Bijay Pokharel,
January 15, 2025
1 min read
Nominet Confirms Network Breach via Ivanti VPN Zero-Day Exploit
Nominet, the official registry for .UK domains and one of the largest country code registries globally, have confirmed a network breach linked to a zero-day vulnerability in Ivanti VPN software.
Bijay Pokharel,
January 14, 2025
1 min read
Apple Fixes macOS SIP Vulnerability That Could Allow Kernel Driver Attacks
Apple has patched a significant macOS vulnerability that allowed attackers to bypass System Integrity Protection (SIP) and install malicious kernel drivers.
Bijay Pokharel,
January 14, 2025
1 min read
Recent Posts
Subscribe
Cybersecurity Newsletter
You have Successfully Subscribed!
Sign up for cybersecurity newsletter and get latest news updates delivered straight to your inbox. You are also consenting to our Privacy Policy and Terms of Use.