🚨 Critical cPanel Flaw Exposes Servers to Potential Takeover — Immediate Action Required

Cpanel logo

A serious security vulnerability in cPanel is raising alarm across the web hosting industry, with attackers potentially able to bypass authentication and gain unauthorized access to control panel systems. In an alert issued Tuesday, cPanel confirmed the flaw affects all currently supported versions, urging administrators to update immediately. The company has already pushed patches in … Read more

Google to Verify All Android Developers: Major Security Shift Coming in 2026

Introduction Google has announced a sweeping new security initiative: Google to Verify All Android Developers before they can distribute apps, both inside and outside the Play Store. This bold move aims to block malicious apps, prevent developer impersonation, and establish a consistent standard of accountability across the Android ecosystem. Starting September 2026, the rules will … Read more

PathWiper: New Data-Wiping Malware Targets Ukrainian Infrastructure

A previously undocumented malware strain named PathWiper has been deployed against a critical infrastructure entity in Ukraine, according to a report by Cisco Talos. The attack leveraged a legitimate endpoint administration framework, suggesting that the threat actor had direct access to the internal management console. Researchers Jacob Finn, Dmytro Korzhevin, and Asheer Malhotra revealed that … Read more

Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency

Moldovan authorities have detained a 45-year-old foreign national linked to a 2021 ransomware attack on Dutch organizations, including a €4.5 million assault on the Netherlands Organization for Scientific Research (NWO). The suspect, accused of cybercrimes such as ransomware, blackmail, and money laundering, was arrested following a search of his Moldova residence. Police seized €84,000 in … Read more

New TCESB Malware Exploits ESET Security Scanner in Active Cyberattacks

New TCESB Malware Exploits ESET Security Scanner in Active Cyberattacks A Chinese-affiliated hacking group, known as ToddyCat, has been caught exploiting a vulnerability in ESET’s security software to deploy a newly discovered malware dubbed TCESB. This sophisticated threat, previously undocumented in ToddyCat’s campaigns, targets organizations across Asia, showcasing the group’s evolving tactics. According to an … Read more

Mozilla’s Bold Move: Entering the Email Hosting Market with Thundermail

Mozilla, the organization renowned for its Firefox browser and commitment to open-source software, is making waves in the tech world once again. On April 2, 2025, news broke that Mozilla is launching Thundermail, a new email hosting service designed to compete with industry giants like Gmail and Microsoft 365. This move marks a significant expansion … Read more

New ‘Rules File Backdoor’ Attack Exploits AI Code Editors to Inject Malicious Code

Cybersecurity researchers have uncovered a novel supply chain attack vector known as the “Rules File Backdoor,” targeting artificial intelligence (AI)-powered code editors such as GitHub Copilot and Cursor. This sophisticated technique allows hackers to covertly inject malicious code into software projects by manipulating the AI tools developers rely on daily. The discovery highlights a growing … Read more

Newly Discovered Linux Backdoor “Auto-color” Targets Universities and Government Offices

A sophisticated new Linux backdoor named “Auto-color” has been identified as a significant threat targeting universities and government institutions across North America and Asia, according to cybersecurity experts. In early November 2024, researchers from Palo Alto Networks’ Unit 42 uncovered this elusive malware, noting its ability to evade detection and its resistance to removal without … Read more

Hackers Exploit Signal’s Linked Devices Feature to Hijack Accounts with Malicious QR Codes

Cybercriminals aligned with Russian threat groups are actively exploiting Signal’s linked devices feature to gain unauthorized access to user accounts. This attack method, observed by Google’s Threat Intelligence Group (GTIG), leverages malicious QR codes to hijack Signal accounts and intercept messages in real time. How the Attack Works The attackers take advantage of Signal’s legitimate … Read more

New XCSSET Variant Targets macOS Users with Advanced Stealth Techniques

In a recent alert, Microsoft has unveiled a new version of the XCSSET infostealer, a notorious macOS malware known for its sophisticated attacks. This latest iteration introduces enhanced obfuscation, infection, and persistence techniques, posing a renewed threat to macOS users. What is XCSSET? XCSSET is primarily an infostealer that targets macOS users through compromised Xcode … Read more