Critical exploit allows hackers to bypass authentication in WordPress Service Finder themes

October 9, 2025Ravi LakshmananVulnerabilities / Website Security Threat actors are actively exploiting a critical security flaw affecting the Service Finder WordPress theme that allows them to gain unauthorized access to any account, including administrators, and take control of susceptible sites. The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects Service Finder Bookings, a […]
Hackers exploit WordPress sites to power next-generation ClickFix phishing attacks

Cybersecurity researchers are warning of malicious campaigns targeting WordPress sites with malicious JavaScript injections designed to redirect users to sketchy sites. “Site visitors are injected with content that is drive-by malware, such as a fake Cloudflare verification,” Sucuri researcher Puja Srivastava said in an analysis published last week. A website security company said it launched […]
Chinese hackers weaponize open source Nezha tools in new wave of attacks

October 8, 2025Ravi LakshmananMalware/Threat Intelligence Attackers with suspected ties to China turned a legitimate open source monitoring tool called Nezha into an attack weapon and used it to deliver known malware called Gh0st RAT to their targets. The activity, observed by cybersecurity firm Huntress in August 2025, features the use of an unusual technique called […]
LockBit, Qilin and DragonForce join forces to control the ransomware ecosystem

Three prominent ransomware groups, DragonForce, LockBit and Qilin, have announced a new strategic ransomware partnership that highlights ongoing changes in the cyberthreat landscape. In a report shared with The Hacker News, ReliaQuest said the coalition is seen as an attempt by the part of a financial attacker to carry out a more effective ransomware attack. […]
Step into Password Cemetery… if you dare (and join a live session)

October 8, 2025Hacker NewsPassword security/Cyber attacks Every year, weak passwords result in millions of losses. Many of these violations could have been stopped. Attackers do not need advanced tools. You only need one careless login. For IT teams, it means an endless reset, a struggle for compliance, and a sleepless night worrying about your next […]
Figma MCP serious vulnerability allows hackers to execute code remotely – patch now

October 8, 2025Ravi LakshmananVulnerability/Software Security Cybersecurity researchers have revealed details of a patched vulnerability on the popular figma-developer-mcp Model Context Protocol (MCP) server. This vulnerability could allow an attacker to execute code. Tracked as CVE-2025-53967 (CVSS score: 7.5), the vulnerability is a command injection bug caused by the unsanitized use of user input, opening the […]
Openai disrupts hackers in Russia, North Korea and China.

Openai said on Tuesday that it disrupted three activity clusters due to misuse of ChatGPT artificial intelligence (AI) tools to promote malware development. This includes the threat actors in Russian. The Russian threat actor is said to have used chatbots to help develop and improve the Trojan horse (rat), a qualified thief intended to avoid […]
Batshadow Group hunts job seekers using the new GO-based “Vampire Bot” malware

October 7, 2025Ravi LakshmananMalware/Threat Intelligence The Vietnamese threat actor named Batshadow is attributed to a new campaign that calls previously undocumented malware vampirebots, leveraging social engineering tactics to deceive job seekers and digital marketing experts. “Attacks will pos as recruiters and distribute malicious files disguised as job descriptions and corporate documents,” Aryaka Threat Research Laborers […]
Google’s new AI not only finds vulnerabilities, but also rewrites and patches the code

October 7, 2025Ravi LakshmananArtificial Intelligence/Software Security Google’s Deepmind division announced on Monday an agent powered by artificial intelligence (AI) called CodeMender, which automatically detects, patches and rewrites vulnerable code to prevent future exploits. This effort adds to the company’s ongoing efforts to improve the discovery of AI-powered vulnerabilities, such as Big Sleep and OSS-Fuzz. According […]
AI is already the #1 data exfiltation channel in the enterprise

For years, security leaders have treated artificial intelligence as an “emerging” technology. The new Enterprise AI and SaaS Data Security Report from AI & Browser Security Company Rayerx proves how obsolete the way that thinking has become. Far from future concerns, AI is already the largest uncontrolled channel for corporate data removal, rather than Shadow […]