Critical flaw in n8n (CVSS 9.9) allows arbitrary code execution across thousands of instances

December 23, 2025Ravi LakshmananVulnerability/Workflow Automation A critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could lead to arbitrary code execution under certain circumstances. This vulnerability is tracked as CVE-2025-68613 and has a CVSS score of 9.9 out of a maximum of 10.0. According to npm statistics, this […]

FCC bans foreign-made drones and key components due to US national security risks

December 23, 2025Ravi LakshmananCybersecurity/Surveillance The Federal Communications Commission (FCC) on Monday announced a ban on all foreign-made drones and critical components, citing national security concerns. To this end, the agency has added foreign-manufactured unmanned aircraft systems (UAS) and critical components of UAS, as well as all communications and video surveillance equipment and services, to the […]

Defining proactive cloud security with new layers of defense

One thing remains constant when it comes to cybersecurity. That means the threat landscape continues to evolve rapidly. To strengthen organizational resiliency, defenders need proactive visibility and tools across endpoints, developer environments, and cryptographic stacks to stay several steps ahead of attackers. In this webinar, experts from the Zscaler Internet Access Product team discuss the […]

The hidden threat of security vendor acquisitions

Imagine this. wake up call On January 2, the phone rang. They are the DevSecOps group and the AppSec group. Critical security vulnerabilities are negatively impacting your business, and your team is desperately trying to find and fix them to protect your data. You probably have scars going back to Log4j, as well as hearing […]

The hidden threat of security vendor acquisitions

Imagine this. wake up call On January 2, the phone rang. They are the DevSecOps group and the AppSec group. Critical security vulnerabilities are negatively impacting your business, and your team is desperately trying to find and fix them to protect your data. You probably have scars going back to Log4j, as well as hearing […]

Fake WhatsApp API package on npm steals messages, contacts, and login tokens

Cybersecurity researchers have revealed details of a new malicious package on the npm repository. This package serves as a fully functional WhatsApp API, but also includes the ability to intercept all messages and link the attacker’s device to the victim’s WhatsApp account. The package named ‘lotusbail’ has been downloaded more than 56,000 times since it […]

Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

Dec 22, 2025Ravie LakshmananHacking News / Cybersecurity Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious breaches. The real danger now isn’t just one major […]

How to browse the web more sustainably with a green browser

As the Internet becomes an indispensable part of daily life, its environmental impact continues to increase. Data centers, constant connectivity, and resource-intensive browsing habits all contribute to energy consumption and digital waste. Although individual users may not feel this impact directly, the collective impact of daily browsing is significant. Choosing a browser designed with sustainability […]

Android malware operations massively merge dropper, SMS theft, and RAT capabilities

In a mobile attack targeting users in Uzbekistan, attackers were observed leveraging a malicious dropper app disguised as a legitimate application to deliver an Android SMS stealer called Wonderland. “Until now, users received ‘pure’ Trojan APKs that functioned as malware as soon as they were installed,” Group-IB said in an analysis published last week. “Attackers […]