Fortinet warns of active exploitation of FortiOS SSL VPN 2FA bypass vulnerability

December 25, 2025Ravi LakshmananVulnerabilities / Enterprise Security Fortinet announced Wednesday that it has seen “recent exploitation” of a five-year-old security flaw in FortiOS SSL VPN under certain configurations. The vulnerability in question, CVE-2020-12812 (CVSS score: 5.2), is an improper authentication vulnerability in SSL VPN in FortiOS that could allow a user to successfully log in […]

CISA reports remote code execution vulnerability in Digiever NVR is being actively exploited

December 25, 2025Ravi LakshmananVulnerabilities / Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw affecting the Digiever DS-2105 Pro network video recorder (NVR) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. This vulnerability is tracked as CVE-2023-52163 (CVSS score: 8.8) and is related to a […]

New MacSync macOS stealer uses signed apps to bypass Apple gatekeeper

December 24, 2025Ravi LakshmananMalware/Endpoint Security Cybersecurity researchers have discovered a new variant of the macOS information stealer called MacSync, which is delivered by digitally signed and notarized Swift applications disguised as messaging app installers that bypass Apple’s Gatekeeper checks. “Unlike previous MacSync Stealer variants that primarily rely on device dragging and ClickFix-style techniques, this sample […]

Nomani investment scams using AI deepfake ads on social media soar to 62%

December 24, 2025Ravi LakshmananOnline fraud/artificial intelligence According to ESET data, the fraudulent investment scheme known as Nomani has increased by 62%, and campaigns distributing this threat have expanded beyond Facebook to other social media platforms such as YouTube. A Slovak cybersecurity company said it has blocked more than 64,000 unique URLs related to the threat […]

3 ways to protect your business in 2026

December 24, 2025hacker newsPassword management/access control Every year, cybercriminals discover new ways to steal money and data from businesses. Breaking into business networks, extracting sensitive data, and selling it on the dark web has become a reliable source of income. But in 2025, data breaches affecting small and medium-sized businesses (SMBs) challenged our conventional wisdom […]

SEC charges more than $14 million in crypto fraud using fake AI-themed investment tips

December 24, 2025Ravi LakshmananArtificial intelligence/virtual currency The U.S. Securities and Exchange Commission (SEC) has charged multiple companies with engaging in an elaborate cryptocurrency scam that defrauded retail investors of more than $14 million. The complaint also charges crypto trading platforms Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc., as well as investment […]

Italy fines Apple €98.6 million over ATT rules restricting App Store competition

December 24, 2025Ravi LakshmananPrivacy/Antitrust Law Apple has been fined €98.6 million ($116 million) by Italian antitrust authorities after its App Tracking Transparency (ATT) privacy framework was found to be restricting competition on the App Store. The Italian competition authority (Autorità Garante della Concorrenza e del Mercato, or AGCM) said the company’s “absolute dominant position” in […]

Two Chrome extensions discovered to be secretly stealing credentials from over 170 sites

Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that have the ability to intercept traffic and capture user credentials. The extension is advertised as a “multi-location network speed test plugin” for developers and trade professionals. At the time of writing, both browser add-ons are […]

Interpol arrests 574 people in Africa. Ukrainian ransomware company pleads guilty

A law enforcement operation coordinated by Interpol led to the recovery of $3 million and the arrest of 574 suspects by authorities in 19 countries as the crackdown on cybercrime networks continues in Africa. The coordinated effort, named Operation Sentinel, ran from October 27 to November 27, 2025, and primarily focused on business email compromise […]

Google Workspace password manager tutorial

Passwd is specifically designed for organizations operating within Google Workspace. Rather than competing as a consumer password manager, its purpose is narrow and business-focused, including secure credential storage, controlled sharing, and seamless Workspace integration. The platform emphasizes practicality over feature plethora, and aims to provide a reliable system for teams that already rely on Google […]