Cybersecurity

npm 12 Disables Risky Scripts by Default

GitHub is introducing major security changes to npm version 12, disabling install scripts by default to counter supply chain attacks.The update, scheduled for release...

China-Linked JDY Botnet Expands, Infects 1,500 Devices

The JDY botnet, used by Chinese state-sponsored hacking groups like Volt Typhoon, has rapidly expanded to over 1,500 compromised SOHO routers and IoT devices.Its...

ServiceNow Flaw Exploited in Cyber Attack

ServiceNow has patched a vulnerability allowing unauthenticated users excessive access to certain customer instances.The company detected "anomalous activity" and evidence of successful queries against...

Meta Expands AI Data Use for Feeds, Chatbots

Meta will now use data from other businesses to personalize user feeds and AI chatbot responses, expanding beyond targeted ads.The company asserts it is...

Russian Hackers Exploit Old WinRAR Flaw Against Ukraine

Two Russian-aligned hacking groups continue to exploit a patched WinRAR vulnerability to target Ukrainian organizations.The flaw, CVE-2025-8088, allows attackers to hide malicious payloads outside...

AI Gateway Flaw Exploited, Added to US List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a severe command injection flaw in BerriAI's LiteLLM software to its Known Exploited Vulnerabilities...

Linux Kernel Flaw Lets Attackers Escalate to Root

A critical Linux kernel vulnerability (CVE-2026-23111) allows local attackers to gain root access and break out of containers.The flaw was patched upstream in February...

Critical Check Point VPN Flaw Actively Exploited

Check Point warns of active exploitation of CVE-2026-50751, a critical VPN authentication bypass vulnerability.The flaw affects Remote Access VPN deployments using the deprecated IKEv1...

Latest news

Palo Alto VPN Flaw Exploited to Bypass Authentication

Palo Alto Networks has confirmed active exploitation of a critical VPN vulnerability, CVE-2026-0257, allowing unauthorized access.The vulnerability, which affects...

SEC Approves T. Rowe Price Active Crypto ETF with SHIB, DOGE

The SEC approved a rule change for T. Rowe Price's Active Crypto ETF, expanding its holdings to 15 digital...

Michael Burry Adds to PayPal Stake Amid AI Frenzy

Famed 'The Big Short' investor Michael Burry announced he increased his stake in Paypal (PYPL) in a post on...