Arch Linux Freezes AUR Package Adoptions After Attackers Exploit Abandoned Projects
Arch Linux has temporarily disabled the ability to adopt orphaned AUR packages after security teams spotted a wave of hostile takeovers followed by malicious code injected through routine-looking...
How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline
Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...
ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems
Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company...
865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service's long-standing 'no logs' promise. The leaked database reportedly...
FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives
A joint advisory from the U.S. State Department, FBI, and partner nations including Japan, the UK, Germany, Canada, and South Korea warns that North Korean IT workers are...
The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...
SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login
SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...
SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware
Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the...