Covenant Health data breach after ransomware attack impacted over 478,000 people
https://securityaffairs.com/186439/data-breach/covenant-health-data-breach-after-ransomware-attack-impacted-over-478000-people.html
https://securityaffairs.com/186439/data-breach/covenant-health-data-breach-after-ransomware-attack-impacted-over-478000-people.html
Security Affairs
Covenant Health data breach after ransomware attack impacted over 478,000 people
Covenant Health suffered a ransomware attack by the Qilin group in May 2025, compromising data of over 478,000 individuals.
❤1
Treasury removes Intellexa spyware-linked trio from sanctions list
https://cyberscoop.com/treasury-removes-intellexa-spyware-linked-trio-from-sanctions-list/
https://cyberscoop.com/treasury-removes-intellexa-spyware-linked-trio-from-sanctions-list/
CyberScoop
Treasury removes Intellexa spyware-linked trio from sanctions list
The three Iranians had only just been added to the list in 2024, but a U.S. official said they had separated themselves from the company.
The Mainstream Master: Why MediaTek’s Dimensity 7100 is the Secret Weapon for 2026 Mid-Rangers
https://securityonline.info/the-mainstream-master-why-mediateks-dimensity-7100-is-the-secret-weapon-for-2026-mid-rangers/
https://securityonline.info/the-mainstream-master-why-mediateks-dimensity-7100-is-the-secret-weapon-for-2026-mid-rangers/
Daily CyberSecurity
The Mainstream Master: Why MediaTek’s Dimensity 7100 is the Secret Weapon for 2026 Mid-Rangers
MediaTek's Dimensity 7100 debuts with a powerful 4+4 CPU layout and native 45W fast charging, targeting a smoother 5G experience for 2026 mid-range phones.
Beyond the Screen: OpenAI’s Secret “Gumdrop” AI Pen Aims for the “iPhone Moment”
https://securityonline.info/beyond-the-screen-openais-secret-gumdrop-ai-pen-aims-for-the-iphone-moment/
https://securityonline.info/beyond-the-screen-openais-secret-gumdrop-ai-pen-aims-for-the-iphone-moment/
Daily CyberSecurity
Beyond the Screen: OpenAI’s Secret "Gumdrop" AI Pen Aims for the "iPhone Moment"
OpenAI is prepping "Gumdrop," an AI-integrated pen designed by Jony Ive. Launching in 2027, it promises zero-latency, "audio-first" companion intelligence.
Two U.S. cybersecurity professionals plead guilty in BlackCat/Alphv ransomware case
https://securityaffairs.com/186446/cyber-crime/two-u-s-cybersecurity-professionals-plead-guilty-in-blackcat-alphv-ransomware-case.html
https://securityaffairs.com/186446/cyber-crime/two-u-s-cybersecurity-professionals-plead-guilty-in-blackcat-alphv-ransomware-case.html
Security Affairs
Two U.S. cybersecurity professionals plead guilty in BlackCat/Alphv ransomware case
Two U.S. cybersecurity professionals pleaded guilty to charges tied to their roles in BlackCat/Alphv ransomware attacks.
Thousands of ColdFusion exploit attempts spotted during Christmas holiday
https://securityaffairs.com/186450/uncategorized/thousands-of-coldfusion-exploit-attempts-spotted-during-christmas-holiday.html
https://securityaffairs.com/186450/uncategorized/thousands-of-coldfusion-exploit-attempts-spotted-during-christmas-holiday.html
Security Affairs
Thousands of ColdFusion exploit attempts spotted during Christmas holiday
GreyNoise observed thousands of attacks targeting about a dozen Adobe ColdFusion vulnerabilities during the Christmas 2025 holiday.
French authorities investigate AI ‘undressing’ deepfakes on X
https://securityaffairs.com/186460/ai/french-authorities-investigate-ai-undressing-deepfakes-on-x.html
https://securityaffairs.com/186460/ai/french-authorities-investigate-ai-undressing-deepfakes-on-x.html
Security Affairs
French authorities investigate AI ‘undressing’ deepfakes on X
France will probe AI-generated sexual deepfakes made with Grok after hundreds of women and teens reported “undressed” images shared online
President Trump blocks $2.9M Emcore chip sale over security concerns
https://securityaffairs.com/186473/security/president-trump-blocks-2-9m-emcore-chip-sale-over-security-concerns.html
https://securityaffairs.com/186473/security/president-trump-blocks-2-9m-emcore-chip-sale-over-security-concerns.html
Security Affairs
President Trump blocks $2.9M Emcore chip sale over security concerns
Trump ordered the divestment of a $2.9M chip deal, citing U.S. national security risks if HieFo retained control of Emcore’s technology.
Security Affairs newsletter Round 557 by Pierluigi Paganini – INTERNATIONAL EDITION
https://securityaffairs.com/186485/breaking-news/security-affairs-newsletter-round-557-by-pierluigi-paganini-international-edition.html
https://securityaffairs.com/186485/breaking-news/security-affairs-newsletter-round-557-by-pierluigi-paganini-international-edition.html
Security Affairs
Security Affairs newsletter Round 557 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs in your email box
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 78
https://securityaffairs.com/186497/malware/security-affairs-malware-newsletter-round-78.html
https://securityaffairs.com/186497/malware/security-affairs-malware-newsletter-round-78.html
Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 78
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape
What is happening to the Internet in Venezuela? Did the U.S. use cyber capabilities?
https://securityaffairs.com/186509/intelligence/what-is-happening-to-the-internet-in-venezuela.html
https://securityaffairs.com/186509/intelligence/what-is-happening-to-the-internet-in-venezuela.html
Security Affairs
What is happening to the Internet in Venezuela? Did the U.S. use cyber capabilities?
In light of the tragic events that occurred in Venezuela, what is happening to the Internet in the country, and how are users accessing it?
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
https://securityonline.info/qnap-patches-high-severity-sql-injection-and-path-traversal-flaws/
https://securityonline.info/qnap-patches-high-severity-sql-injection-and-path-traversal-flaws/
Daily CyberSecurity
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
QNAP patches high-severity flaws (CVSS 8.1) in Qfiling and MARS that allow data theft and code injection. Secure your NAS by updating to the latest versions!
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
https://securityonline.info/zero-click-hijack-the-prestashop-checkout-flaw-that-turns-emails-into-full-account-access-poc-publishes/
https://securityonline.info/zero-click-hijack-the-prestashop-checkout-flaw-that-turns-emails-into-full-account-access-poc-publishes/
Daily CyberSecurity
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
PrestaShop patches a 9.1 critical flaw (CVE-2025-61922) in the Checkout module. Attackers can hijack accounts via email. PoC available.
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
https://securityonline.info/the-sleeper-in-your-browser-how-darkspectre-turned-8-8-million-extensions-into-state-aligned-spies/
https://securityonline.info/the-sleeper-in-your-browser-how-darkspectre-turned-8-8-million-extensions-into-state-aligned-spies/
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
https://securityonline.info/eaton-ups-software-flaws-expose-systems-to-high-risk-code-execution/
https://securityonline.info/eaton-ups-software-flaws-expose-systems-to-high-risk-code-execution/
Daily CyberSecurity
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
Eaton warns of critical 8.6 severity flaws in UPS Companion software (CVE-2025-59887 & 59888). Upgrade to v3.0 now to prevent hijacking!
New WordPress Phishing Scam Steals Credit Cards via Telegram
https://securityonline.info/new-wordpress-phishing-scam-steals-credit-cards-via-telegram/
https://securityonline.info/new-wordpress-phishing-scam-steals-credit-cards-via-telegram/
Daily CyberSecurity
New WordPress Phishing Scam Steals Credit Cards via Telegram
Researcher Anurag uncovers a WordPress phishing campaign that steals credit cards and 3-D Secure OTPs, exfiltrating data directly via Telegram bots.
Transparent Tribe Weaponizes “JLPT” Tests in New Cyber-Espionage Campaign Against India
https://securityonline.info/transparent-tribe-weaponizes-jlpt-tests-in-new-cyber-espionage-campaign-against-india/
https://securityonline.info/transparent-tribe-weaponizes-jlpt-tests-in-new-cyber-espionage-campaign-against-india/
Daily CyberSecurity
Transparent Tribe Weaponizes "JLPT" Tests in New Cyber-Espionage Campaign Against India
CYFIRMA unmasks APT36's latest campaign: a fake JLPT exam lure using fileless LNK malware to evade antivirus and spy on Indian government targets.
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
https://securityonline.info/cve-2025-66848-critical-flaw-in-jd-cloud-routers-grants-hackers-root-access/
https://securityonline.info/cve-2025-66848-critical-flaw-in-jd-cloud-routers-grants-hackers-root-access/
Daily CyberSecurity
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
JD Cloud alerts users to CVE-2025-66848, a 9.8 critical flaw allowing remote attackers to bypass auth and gain root access on NAS routers.
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
https://securityonline.info/the-invisible-predator-how-vvs-stealer-abuses-pyarmor-to-ghost-discord-accounts/
https://securityonline.info/the-invisible-predator-how-vvs-stealer-abuses-pyarmor-to-ghost-discord-accounts/
Daily CyberSecurity
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
Unit 42 unmasks VVS Stealer, a Python-based threat using Pyarmor obfuscation to bypass AV, hijack Discord sessions, and steal browser credentials.
“Sliver” in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
https://securityonline.info/sliver-in-the-stack-exposed-logs-reveal-targeted-fortiweb-exploitation-campaign/
https://securityonline.info/sliver-in-the-stack-exposed-logs-reveal-targeted-fortiweb-exploitation-campaign/
Daily CyberSecurity
"Sliver" in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
Threat actor uses React2Shell to deploy Sliver C2 on FortiWeb devices, using a Bangladesh Airforce decoy to target govt and financial sectors.
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
https://securityonline.info/cve-2026-21440-new-adonisjs-9-2-critical-flaw-allows-arbitrary-file-writes-and-rce/
https://securityonline.info/cve-2026-21440-new-adonisjs-9-2-critical-flaw-allows-arbitrary-file-writes-and-rce/
Daily CyberSecurity
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
CVE-2026-21440: A critical 9.2 flaw in AdonisJS file uploads allows attackers to overwrite system files and gain RCE. Update to v10.1.2 immediately!
❤1