FBI seized ‘web3adspanels.org’ hosting stolen logins
https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html
https://securityaffairs.com/186094/cyber-crime/fbi-seized-web3adspanels-org-hosting-stolen-logins.html
Security Affairs
FBI seized ‘web3adspanels.org’ hosting stolen logins
The U.S. seized the 'web3adspanels.org' domain and database used by cybercriminals to store stolen bank login credentials.
Threat landscape for industrial automation systems in Q3 2025
https://securelist.com/industrial-threat-report-q3-2025/118602/
https://securelist.com/industrial-threat-report-q3-2025/118602/
Securelist
Threat landscape for industrial automation systems in Q3 2025
The report contains statistics on various threats detected and blocked on ICS computers in Q3 2025, including miners, ransomware, spyware, etc.
High-severity MongoDB flaw CVE-2025-14847 could lead to server takeover
https://securityaffairs.com/186107/security/high-severity-mongodb-flaw-cve-2025-14847-could-lead-to-server-takeover.html
https://securityaffairs.com/186107/security/high-severity-mongodb-flaw-cve-2025-14847-could-lead-to-server-takeover.html
Security Affairs
High-severity MongoDB flaw CVE-2025-14847 could lead to server takeover
MongoDB addressed a high-severity vulnerability that can be exploited to achieve remote code execution on vulnerable servers.
🔥1
The Inference Coup: NVIDIA’s $20B Groq Deal Swallows the TPU’s Creator
https://securityonline.info/the-inference-coup-nvidias-20b-groq-deal-swallows-the-tpus-creator/
https://securityonline.info/the-inference-coup-nvidias-20b-groq-deal-swallows-the-tpus-creator/
Daily CyberSecurity
The Inference Coup: NVIDIA’s $20B Groq Deal Swallows the TPU’s Creator
NVIDIA pays $20B to license Groq's LPU tech and hires founder Jonathan Ross, neutralizing a top inference rival while dodging antitrust blocks.
The Brazil Breakout: Apple Forced to Unlock iOS for Third-Party App Stores
https://securityonline.info/the-brazil-breakout-apple-forced-to-unlock-ios-for-third-party-app-stores/
https://securityonline.info/the-brazil-breakout-apple-forced-to-unlock-ios-for-third-party-app-stores/
Daily CyberSecurity
The Brazil Breakout: Apple Forced to Unlock iOS for Third-Party App Stores
Apple settles with Brazil's CADE, agreeing to allow third-party app stores and external payments by April 2026. See the new 15% and 5% fee structures.
Microsoft Denies Plans to Rewrite Windows 11 in Rust Despite AI Ambitions
https://securityonline.info/microsoft-denies-plans-to-rewrite-windows-11-in-rust-despite-ai-ambitions/
https://securityonline.info/microsoft-denies-plans-to-rewrite-windows-11-in-rust-despite-ai-ambitions/
Daily CyberSecurity
Microsoft Denies Plans to Rewrite Windows 11 in Rust Despite AI Ambitions
Microsoft clarifies it won’t rewrite Windows 11 in Rust with AI, despite bold claims by a senior engineer about replacing C and C++ by 2030.
“Silver Fox” Unmasked: Chinese APT Group Impersonates Indian Tax Officials in Targeted Cyber Campaign
https://securityonline.info/silver-fox-unmasked-chinese-apt-group-impersonates-indian-tax-officials-in-targeted-cyber-campaign/
https://securityonline.info/silver-fox-unmasked-chinese-apt-group-impersonates-indian-tax-officials-in-targeted-cyber-campaign/
Daily CyberSecurity
"Silver Fox" Unmasked: Chinese APT Group Impersonates Indian Tax Officials in Targeted Cyber Campaign
CloudSEK’s TRIAD unmasks Silver Fox APT, a China-linked group using Valley RAT to target India while hiding behind misattributed tax phishing lures.
Critical Flaw in Livewire Exposes Laravel Apps to Stealthy RCE, PoC Releases
https://securityonline.info/critical-flaw-in-livewire-exposes-laravel-apps-to-stealthy-rce-poc-releases/
https://securityonline.info/critical-flaw-in-livewire-exposes-laravel-apps-to-stealthy-rce-poc-releases/
Daily CyberSecurity
Critical Flaw in Livewire Exposes Laravel Apps to Stealthy RCE, PoC Releases
Synacktiv unmasks CVE-2025-54068, a critical Livewire hydration flaw, and Livepyre, a tool that achieves RCE even if the APP_KEY is known.
The End of Neutrality? OpenAI’s Secret Plan to Embed Ads in ChatGPT’s “Brain”
https://securityonline.info/the-end-of-neutrality-openais-secret-plan-to-embed-ads-in-chatgpts-brain/
https://securityonline.info/the-end-of-neutrality-openais-secret-plan-to-embed-ads-in-chatgpts-brain/
Daily CyberSecurity
The End of Neutrality? OpenAI’s Secret Plan to Embed Ads in ChatGPT’s "Brain"
OpenAI is reportedly developing "conversational ads" for ChatGPT that adjust model weights to prioritize sponsors. Is the era of neutral AI ending?
The Godfather’s Gambit: Why Yoshua Bengio Lies to AI to Get the Truth
https://securityonline.info/the-godfathers-gambit-why-yoshua-bengio-lies-to-ai-to-get-the-truth/
https://securityonline.info/the-godfathers-gambit-why-yoshua-bengio-lies-to-ai-to-get-the-truth/
Daily CyberSecurity
The Godfather’s Gambit: Why Yoshua Bengio Lies to AI to Get the Truth
AI Godfather Yoshua Bengio reveals a "reverse deception" hack: lie to your chatbot to bypass its sycophantic flattery and get honest, critical feedback.
Gmail’s Identity Revolution: How to Change Your Email Address Without Losing Data
https://securityonline.info/gmails-identity-revolution-how-to-change-your-email-address-without-losing-data/
https://securityonline.info/gmails-identity-revolution-how-to-change-your-email-address-without-losing-data/
Daily CyberSecurity
Gmail’s Identity Revolution: How to Change Your Email Address Without Losing Data
Google is finally letting users change their @gmail.com address! Keep your data, photos, and history while updating your username via a new alias system.
The “D” is for Danger: How a Tiny Typo in MAS Activation Hijacks Your PC
https://securityonline.info/the-d-is-for-danger-how-a-tiny-typo-in-mas-activation-hijacks-your-pc/
https://securityonline.info/the-d-is-for-danger-how-a-tiny-typo-in-mas-activation-hijacks-your-pc/
Daily CyberSecurity
The "D" is for Danger: How a Tiny Typo in MAS Activation Hijacks Your PC
Attackers are using a fake MAS domain (get.activate.win) to deploy Cosmali Loader and XWorm RAT via PowerShell. Verify your command before running it!
Five-year-old Fortinet FortiOS SSL VPN vulnerability actively exploited
https://securityaffairs.com/186117/security/five-year-old-fortinet-fortios-ssl-vpn-flaw-actively-exploited.html
https://securityaffairs.com/186117/security/five-year-old-fortinet-fortios-ssl-vpn-flaw-actively-exploited.html
Security Affairs
Five-year-old Fortinet FortiOS SSL VPN vulnerability actively exploited
Fortinet reported active exploitation of a five-year-old FortiOS SSL VPN flaw, abused in the wild under specific configurations.
Spotify cracks down on unlawful scraping of 86 million songs
https://securityaffairs.com/186136/data-breach/spotify-cracks-down-on-unlawful-scraping-of-86-million-songs.html
https://securityaffairs.com/186136/data-breach/spotify-cracks-down-on-unlawful-scraping-of-86-million-songs.html
Security Affairs
Spotify cracks down on unlawful scraping of 86 million songs
Spotify shut down accounts after Anna’s Archive scraped and published data on 86 million songs, confirming action against unlawful scraping.
🔥2❤1
Aflac confirms June data breach affecting over 22 million customers
https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html
https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html
Security Affairs
Aflac confirms June data breach affecting over 22 million customers
A June data breach exposed the personal information of more than 22 million Aflac customers, the company confirmed.
Pro-Russian group Noname057 claims cyberattack on La Poste services
https://securityaffairs.com/186157/hacktivism/pro-russian-group-noname057-claims-cyberattack-on-la-poste-services.html
https://securityaffairs.com/186157/hacktivism/pro-russian-group-noname057-claims-cyberattack-on-la-poste-services.html
Security Affairs
Pro-Russian group Noname057 claims cyberattack on La Poste services
Pro-Russian hacking group Noname057 claimed responsibility for the cyberattack that disrupted La Poste's digital banking and online services
ParrotOS 7 Released with KDE Plasma 6 and Major System Overhaul
https://thecyberexpress.com/parrotos-7-released/
https://thecyberexpress.com/parrotos-7-released/
The Cyber Express
ParrotOS 7 Released: KDE Plasma 6 Operating System
ParrotOS 7 launches with a full operating system rewrite, KDE Plasma 6, Debian 13 base, new security tools, AI categories, and RISC-V support.
Critical Net-SNMP Flaw CVE-2025-68615 Allows Remote Buffer Overflow and Service Crashes
https://thecyberexpress.com/cve-2025-68615-critical-net-snmp-snmptrapd/
https://thecyberexpress.com/cve-2025-68615-critical-net-snmp-snmptrapd/
The Cyber Express
CVE-2025-68615: Critical Net-SNMP Snmptrapd Flaw
CVE-2025-68615 is a critical Net-SNMP snmptrapd vulnerability enabling buffer overflow, service crashes, and potential remote code execution.
Trust Wallet warns users to update Chrome extension after $7M security loss
https://securityaffairs.com/186163/cyber-crime/trust-wallet-warns-users-to-update-chrome-extension-after-7m-security-loss.html
https://securityaffairs.com/186163/cyber-crime/trust-wallet-warns-users-to-update-chrome-extension-after-7m-security-loss.html
Security Affairs
Trust Wallet warns users to update Chrome extension after $7M security loss
Trust Wallet urged users to update its Chrome extension after a security incident caused about $7 million in losses.
NPM package with 56,000 downloads compromises WhatsApp accounts
https://securityaffairs.com/186174/malware/npm-package-with-56000-downloads-compromises-whatsapp-accounts.html
https://securityaffairs.com/186174/malware/npm-package-with-56000-downloads-compromises-whatsapp-accounts.html
Security Affairs
NPM package with 56,000 downloads compromises WhatsApp accounts
An NPM package with over 56,000 downloads stole WhatsApp credentials, hid its activity, and installed a backdoor.