Beware of hidden costs of penetration testing

Penetration testing helps organizations secure their IT systems, but it shouldn’t be treated with a one-size-fits-all approach. Traditional approaches can be rigid, cost organizations time and money, and produce poor results. The benefits of penetration testing are clear. By allowing “white hat” hackers to attempt to penetrate your system using similar tools and techniques as […]

$15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More

Oct 16, 2025Ravie LakshmananCybersecurity / Hacking News The online world is changing fast. Every week, new scams, hacks, and tricks show how easy it’s become to turn everyday technology into a weapon. Tools made to help us work, connect, and stay safe are now being used to steal, spy, and deceive. Hackers don’t always break […]

CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack

October 16, 2025Ravi LakshmananVulnerability/Data Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting Adobe Experience Manager to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerability in question is CVE-2025-54253 (CVSS score: 10.0), a maximum severity misconfiguration bug that may lead to […]

Chinese threat group Jewelbug secretly infiltrated Russian IT networks for months

Chinese-linked attackers have been implicated in a five-month intrusion targeting IT service providers in Russia, marking the hacker group’s expansion into the country beyond Southeast Asia and South America. The activity, which occurred between January and May 2025, is believed to be the work of a threat actor tracked by Broadcom-owned Symantec as Jewelbug, and […]

F5 breach exposes BIG-IP source code — state hackers behind massive intrusion

October 15, 2025Ravi LakshmananVulnerability/Threat Intelligence US cybersecurity company F5 revealed on Wednesday that unidentified attackers infiltrated its systems and stole files containing portions of BIG-IP’s source code and information related to undisclosed vulnerabilities in the product. The report attributed the activity to a “highly sophisticated nation-state threat actor,” adding that the adversary maintained long-term and […]

Over 100 VS Code extensions expose developers to hidden supply chain risks

A new study has found that more than 100 Visual Studio Code (VS Code) extension publishers have compromised access tokens that can be exploited by malicious actors to update their extensions, posing significant risks to the software supply chain. “Leaked VSCode Marketplace or Open VSX PAT [personal access token] Wiz security researcher Rami McCarthy said […]

How attackers can bypass synced passkeys

October 15, 2025Ravi LakshmananData protection / browser security TLDR Even if you don’t learn anything else from this part, if your organization is evaluating passkey deployment, it’s not safe to deploy synchronized passkeys. Synchronized passkeys inherit risk from cloud accounts and the recovery processes that protect them, posing a significant risk to businesses. Adversary-in-the-middle (AiTM) […]

Two new Windows zero-days exploited – one affecting all versions shipped to date

Microsoft on Tuesday released fixes for as many as 183 security flaws across its products, after the tech giant officially ended support for the Windows 10 operating system unless the PC was enrolled in the Extended Security Updates (ESU) program. This includes three vulnerabilities that are being exploited in the wild. Of the 183 vulnerabilities, […]

Two CVSS 10.0 bugs in Red Lion RTU could allow hackers to gain complete industrial control

October 15, 2025Ravi LakshmananVulnerabilities/Critical Infrastructure Cybersecurity researchers have uncovered two critical security flaws affecting the Red Lion Sixnet remote terminal unit (RTU) product. Successful exploitation could lead to code execution with highest privileges. This flaw is tracked as CVE-2023-40151 and CVE-2023-42770, both rated 10.0 in the CVSS scoring system. “This vulnerability affects Red Lion SixTRAK […]

Hackers exploit cookies to target ICTBroadcast servers and gain remote shell access

October 15, 2025Ravi LakshmananVulnerabilities / Server Security Cybersecurity researchers have revealed that a critical security flaw affecting ICT Innovations’ autodialer software, ICTBroadcast, is being exploited in the wild. The vulnerability, assigned CVE identifier CVE-2025-2611 (CVSS score: 9.3), is related to improper input validation when the call center application does not securely pass session cookie data […]