Several hacker groups have weaponized the Balochistan Police online portal as part of coordinated espionage campaigns. The attacks target government and security infrastructure in the region, exploiting vulnerabilities to steal sensitive data. This highlights growing cyber threats to law enforcement systems in politically volatile areas.
A critical security flaw in Zimbra Collaboration Suite enables attackers to execute arbitrary code by sending specially crafted emails to user sessions. This vulnerability could lead to full compromise of email accounts and server access. Users are urged to apply security patches immediately.
Injective Labs' GitHub repository was compromised, leading to the publication of malicious npm packages that steal cryptocurrency wallet private keys. Users who installed these packages risk losing access to their funds. The incident underscores persistent supply-chain security risks in the blockchain ecosystem.
Progress Software has instructed customers of its ShareFile product to immediately shut down their Storage Zone Controllers following the discovery of a critical security vulnerability. The company warns that the flaw could be actively exploited, posing a significant risk to data security. This urgent advisory follows a pattern of recent supply chain attacks targeting file transfer solutions.
Researchers found six new security flaws in the U-Boot bootloader used by many embedded devices. An attacker could exploit these bugs by using malicious boot images to crash devices or execute arbitrary code at startup. This affects a wide range of systems and requires prompt patching.
Researchers demonstrated a laser fault injection attack that resets passwords on Tangem hardware wallets, bypassing security. The vulnerability affects older cards that cannot receive firmware updates, leaving users' funds at risk. This highlights the physical security limitations of unchangeable hardware devices.
A critical vulnerability in XQUIC, an implementation of the QUIC transport protocol, remains unpatched. It allows remote clients to crash HTTP/3 servers via a specially crafted request, potentially causing widespread denial-of-service conditions. With HTTP/3 adoption increasing, this flaw poses significant risk to affected systems.
A study of 281 free Android VPN apps found that many leak network traffic, leave data unencrypted, and contain trackers. This undermines the privacy protection users expect from a VPN, exposing them to surveillance and data theft. The findings highlight the risks of relying on free VPN services.
Attackers leveraged a vulnerability dubbed "Ill Bloom" to drain over $5 million from cryptocurrency wallets. The exploit targeted a flaw in wallet infrastructure, enabling unauthorized fund transfers. This incident underscores ongoing security risks in the crypto ecosystem and potential for further large-scale thefts.