FortiWeb CVE-2025-64446 PoC: a critical weapon now widely available
The cybersecurity landscape has shifted once again, driven by the public release of a proof-of-concept exploit targeting the critical vulnerability CVE-2025-64446 within FortiWeb devices. This disclosure, originating from...
SmartApeSG: the persistent evolution of a ClickFix-based RAT campaign
The SmartApeSG campaign, previously identified by aliases like ZPHP and HANEY MANEY, continues to demonstrate a remarkable capacity for adaptation, moving beyond initial tactics of deceptive browser update...
NVIDIA NeMo Framework: a critical cascade of vulnerabilities
The NVIDIA NeMo Framework, a cornerstone of conversational AI development, has recently revealed a significant and frankly concerning weakness. The disclosure, detailed in a critical security update, centers...
New Bridgestone cyberattack: summary
Bridgestone Americas (BSA) is the North American division of Bridgestone, the world’s largest tire manufacturer by production volume. Attack Details Actions Taken Background
Silk Road’s Ross Ulbricht receives $31 Million in Bitcoin from AlphaBay-linked source after release
The libertarian and crypto communities recently celebrated the release of Ross Ulbricht, the infamous founder of the Silk Road darknet marketplace. But the festivities took an unexpected turn...
Critical Roundcube vulnerability (CVE-2025-49113): exploit sold in Darknet as “Email Armageddon” looms
A decade-old Remote Code Execution (RCE) flaw in Roundcube, the widely used open-source email client, has escalated into a global cybersecurity emergency. Designated CVE-2025-49113 with a near-maximum CVSS...
Meta and Yandex Android apps exploit Localhost to track users
A recent investigation has uncovered that native Android apps from Meta (including Facebook and Instagram) and Yandex have been covertly tracking billions of users by exploiting localhost communications—a...
Sophos exposes massive GitHub campaign distributing backdoored malware
A sophisticated malware campaign targeting hackers, gamers, and cybersecurity researchers has been uncovered on GitHub, leveraging fake exploits, game cheats, and open-source tools to distribute backdoors. The operation,...