Tag: security

Thousands of businesses at risk worldwide as new data exfiltration technique uncovered – here’s what you need to know

Browsers are the new frontline, but today’s DLP can’t see the real threats Data Splicing Attacks break through enterprise browser security Angry Magpie reveals how fragile the current DLP architecture is in a browser-first world A newly uncovered data exfiltration technique known as Data Splicing Attacks could place thousands of…

Read More

DragonForce ransomware group evolves new cartel business model

DragonForce is selling its ransomware as a service that can be rebranded The group will handle malware development, leak sites, and more RaaS democratizes malware – as if AI hadn’t done enough damage Inspired by drug gangs, ransomware group DragonForce is bringing a new business model to the ransomware scene,…

Read More

Medical software company database may have exposed tens of thousands of health records and PII

A breach has impacted thousands of Carolina Anesthesiology PA patients Sensitive health information and patient data was exposed This leaves anyone affected at risk of identity theft or social engineering Security researcher Jeremiah Fowler has discovered a non password-protected database, believed to be owned by Carolina Anesthesiology PA – a…

Read More

WooCommerce phishing campaign uses fake patch to lure victims into installing backdoors

Patchstack spotted a new phishing campaign targeting WooCommerce users The email warns the users about a “critical vulnerability” that must be fixed The “fix” is actually malware that creates a rogue admin account and drops stage-two malware If you are a WooCommerce user, pay attention, since there is a new…

Read More

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Researchers discovered two critical-severity zero-days in Craft CMS Criminals are allegedly chaining them together to gain access Some 300 sites already fell victim Cybercriminals are abusing two zero-day vulnerabilities in the Craft content management system (CMS) to access flawed servers and run malicious code remotely (RCE). This is according to…

Read More

Largest DDoS attack of 2025 hit an online betting organization with 1Tbps brute force: here’s what we know

A massive DDoS attack was recently detected during a major NHL event Attack grew from 67Gbps to nearly 1Tbps in twenty minutes Multivector strike used UDP, SYN, IP, and TCP flood techniques Cybersecurity firm Qrator Labs has claimed it successfully mitigated the largest DDoS attack so far recorded in 2025.…

Read More