Tracked as CVE-2020-12812, the exploited FortiOS flaw allows threat actors to bypass two-factor authentication.
Hi, what are you looking for?
Tracked as CVE-2020-12812, the exploited FortiOS flaw allows threat actors to bypass two-factor authentication.
The ecommerce giant will provide purchase vouchers to the 33.7 million individuals impacted by the incident.
Hackers stole names, addresses, Social Security numbers, ID numbers, and medical and health insurance information from Aflac’s systems.
Dubbed MongoBleed, the high-severity flaw allows unauthenticated, remote attackers to leak sensitive information from MongoDB servers.
The personal information of 21,000 customers was stolen after hackers compromised Red Hat’s GitLab instances.
The package provides legitimate functionality to evade detection, while stealing users’ data and deploying a backdoor.
Authorities in Senegal, Ghana, Benin, and Cameroon dismantled BEC, ransomware, and other cyber-fraud networks.
A recent MacSync Stealer version no longer requires users to directly interact with the terminal for execution.
The cybersecurity startup will use the funds to accelerate platform improvements, global expansion, and partnerships.
The critical-severity bug in the Fireware OS’s iked process leads to unauthenticated remote code execution.
The startup’s solution captures, verifies, and governs all AI interactions within an enterprise’s environment.
The hacking group has been using Group Policy to deploy cyberespionage tools on governmental networks.
The exchange has been allegedly involved in laundering money for ransomware groups and other transnational cybercriminal organizations.
Downloaded from a code library, the information pertains to current and former staff and affiliates, and to alumni and students.
Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity.
Tracked as CVE-2025-37164, the critical flaw could allow unauthenticated, remote attackers to execute arbitrary code.
Tracked as CVE-2025-59374, the issue is a software backdoor implanted in Asus Live Update in a supply chain attack.
Threat actors stole names, Social Security numbers, and financial and health information, and deployed ransomware on RBHA’s systems.
The medium-severity flaw has been exploited in combination with a critical bug for remote code execution.
The malware provides full device control and real-time surveillance capabilities like those of advanced spyware.