When you click on the Studios patch, password state authentication bypass vulnerability on emergency access page

August 29, 2025Ravi LakshmananVulnerability/Enterprise Security Click Studios, developer of the enterprise-centric password management solution PasswordState, said it has released a security update to address a software authentication bypass vulnerability. An issue that has not yet been assigned a CVE identifier has been addressed in PasswordState 9.9 (Build 9972), released on August 28, 2025. The Australian […]

Emergency patches are now available for FreePBX server targeting zero-day defects

August 29, 2025Ravi LakshmananZero Day/Vulnerability The Sangoma FreepBX Security team has issued an advisory warning about actively exploited FreepBX Zero Day vulnerabilities affecting systems through the Administrator Control Panel (ACP) exposed to the public Internet. FreepBX is an open source private branch exchange (PBX) platform widely used by businesses, call centres and service providers to […]

The federal government seizes $6.4 million veriftools fake-id marketplace, but operators reboot new domains

August 29, 2025Ravi LakshmananCryptocurrency/Cybercrime Dutch and US authorities have announced that they have used fraudulent identity documents to cybercriminals around the world to demolish illegal markets called Veriftools. To do this, two marketplace domains (Verif)[.]Tools and Veriftools[.]Net) and one blog have been deleted and redirected to a splash page where visitors to the site say […]

TamperedChef malware disguised as a fake PDF editor steals credentials and cookies

August 29, 2025Ravi LakshmananMalware/Windows Security Cybersecurity researchers have discovered a cybercrime campaign that uses tricks to direct victims to fraudulent sites to provide a new information steeler called TamperedChef. “The goal is to invite victims to download and install the Trojanized PDF editor, including information-stolen malware called TamperedChef.” “Malware is designed to harvest sensitive data […]

Researchers find code flaws and code flaws that allow attackers to reissue deleted extensions with the same name

August 28, 2025Ravi LakshmananMalware/Ransomware Cybersecurity researchers have discovered a loophole in the Visual Studio Code Marketplace that allows threat actors to reuse names of previously deleted extensions. Software Supply Chain Security Costume ReverSingLabs said it had discovered after identifying a malicious extension named “Ahbanc.shiba,” which works similarly to two other extensions flagged in early March […]

Salt Typhoon exploits defects in Cisco, Ivanti and Palo Alto infringing 600 organizations around the world

The China-related Advanced Persistent Threat (APT) actor known as Salt Typhoon continues attacks targeting networks around the world, including organizations in the telecommunications, government, transportation, accommodation and military infrastructure sectors. “These actors focus on major telecommunications providers’ large backbone routers, as well as provider edge (PE) and customer edge (CE) routers, but refer to other […]

Why Top Teams Prioritize Code-to-Cloud Mapping in 2025 AppSec

August 28, 2025Hacker NewsCloud Security/Generated AI Imagine this: your team has deployed some new code and thinks everything is fine. However, there are small flaws hidden there, and when hit in the cloud it explodes into a big problem. The next thing you know is that there are hackers and your company deals with millions […]