Researchers discover vulnerability in ChatGPT that allows attackers to trick AI into leaking data

November 5, 2025Ravi LakshmananArtificial intelligence/vulnerabilities Cybersecurity researchers have uncovered a new vulnerability affecting OpenAI’s ChatGPT artificial intelligence (AI) chatbot. This vulnerability could be exploited by an attacker to steal personal information from a user’s memory or chat history without the user’s knowledge. According to Tenable, seven vulnerabilities and attack techniques were discovered in OpenAI’s GPT-4o […]
Protecting the open Android ecosystem with Samsung Knox

November 5, 2025hacker newsMobile Security/Enterprise IT Raise your hand if you’ve heard the myth that “Android is not secure”. Android smartphones like Samsung Galaxy enable new ways of working. However, IT administrators may be concerned about security. After all, work data is important. However, outdated concerns can prevent your business from reaching its full potential. […]
Mysterious ‘SmudgedSerpent’ hacker targets US policy experts as tensions between Iran and Israel rise

November 5, 2025Ravi LakshmananCybersecurity/cyber espionage A never-before-seen threat activity cluster codenamed UNK_SmudgedSerpent is believed to be behind a series of cyberattacks targeting academics and foreign policy professionals from June to August 2025, coinciding with heightened geopolitical tensions between Iran and Israel. “UNK_SmudgedSerpent took advantage of domestic political temptations, including investigations into social change in Iran […]
US sanctions 10 North Korean companies for laundering $12.7 million in cryptocurrency and IT fraud

November 5, 2025Ravi LakshmananCybercrime/Ransomware The U.S. Treasury Department on Tuesday imposed sanctions on eight individuals and two entities within North Korea’s global financial network for laundering money for a variety of illegal schemes, including cybercrime and information technology (IT) worker fraud. “North Korea’s state-sponsored hackers are stealing and laundering funds to fund the regime’s nuclear […]
Why you can avoid SOC burnout: Practical steps

Behind every alert is an analyst. Tired eyes scanning the dashboard, long nights spent on false positives, and a constant fear of missing something big. It’s no wonder that many SOCs experience burnout before facing their next breach. But this doesn’t have to be the norm. The way out is not by working harder, but […]
CISA adds Gladinet and CWP flaws to KEV catalog amid evidence of active exploitation

November 5, 2025Ravi LakshmananVulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws affecting Gladinet and Control WebPanel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of real-world exploitation. The vulnerabilities in question are as follows. CVE-2025-11371 (CVSS Score: 7.5) – A vulnerability exists in an externally […]
A cybercrime merger like no other – Scattered Spider, LAPSUS$ and ShinyHunters team up

The initial group, which combined three prominent cybercriminal groups: Scattered Spider, LAPSUS$, and ShinyHunters, created 16 Telegram channels since August 8, 2025. “Since its debut, the group’s Telegram channel has been deleted and recreated at least 16 times, with various iterations of its original name. This repeating cycle reflects platform moderation and the operator’s determination […]
Europol and Eurojust dismantle a global €600 million cryptocurrency fraud network

November 4, 2025Ravi LakshmananCybercrime/Money Laundering Nine people have been arrested in connection with a coordinated law enforcement operation targeting a crypto money laundering network that defrauded victims of 600 million euros (approximately $688 million). According to a statement released by Eurojust today, the case took place across Cyprus, Spain and Germany between October 27 and […]
Critical flaw in React Native CLI leaves millions of developers open to remote attacks

November 4, 2025Ravi LakshmananVulnerabilities / Supply Chain Security Details have emerged about a critical security flaw that was patched in the popular @react-native-community/cli npm package. This flaw can be exploited under certain conditions to execute malicious operating system (OS) commands. “This vulnerability allows an unauthenticated, remote attacker to easily cause execution of arbitrary OS commands […]
A bug in Microsoft Teams allows attackers to impersonate colleagues and edit messages without their knowledge

November 4, 2025Ravi Lakshmanan Cybersecurity researchers have detailed four security flaws in Microsoft Teams that could expose users to serious impersonation and social engineering attacks. Check Point said in a report shared with Hacker News that the vulnerability “allowed an attacker to manipulate conversations, impersonate co-workers, and exploit notifications.” After responsible disclosure in March 2024, […]