Security
-
A new phishing attack has been discovered where hackers use Webflow’s CDN and fake CAPTCHAs to trick users into entering their credit card details. The attackers manipulate search results to lure victims into clicking malicious PDFs that lead to phishing websites.
-
A serious security flaw in YouTube and Google’s Pixel Recorder API allowed hackers to extract users’ email addresses from their anonymous YouTube accounts. Security researchers found a way to convert hidden Google IDs (Gaia IDs) into email addresses, exposing millions of users to privacy risks. Google has now fixed the issue, but it highlights how interconnected services can create security loopholes.
-
North Korean hacking group Kimsuky is using a custom RDP Wrapper and proxy tools to gain persistent, stealthy access to infected computers. This marks a shift in their tactics, moving away from noisy malware to more covert remote access techniques.
-
Cybercriminals are using fake Microsoft Active Directory Federation Services (ADFS) login pages to steal usernames, passwords, and MFA codes from employees in education, healthcare, and government organizations. The stolen credentials allow hackers to access corporate email accounts, send phishing emails, and commit financial fraud.
-
WhatsApp has confirmed a sophisticated cyberattack targeting around 90 journalists and activists across 20 countries. Hackers used zero-click spyware, which can infect phones without the user clicking on anything. Meta has taken action against the attackers and is notifying the victims.
-
Tata Technologies recently faced a ransomware attack that led to the temporary suspension of some IT services. The company has confirmed that all affected services have been restored, and an investigation is underway to strengthen cybersecurity and prevent future incidents.
-
Hackers are actively targeting vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) software to infiltrate networks. These flaws allow attackers to download/upload files and gain admin-level access. While patches are available, unpatched systems remain at risk.
-
Chinese AI startup DeepSeek faced a major cyberattack soon after its successful launch on Wall Street. The attack caused service disruptions, forcing the company to temporarily stop new user registrations. DeepSeek’s popular open-source AI model, DeepSeek-R1, is creating waves in the global market, shaking up the tech industry and affecting major tech stocks.
-
Hackers are using SSH tunnels to secretly access VMware ESXi servers, steal data, and deploy ransomware. These servers, which host multiple virtual machines, are critical to businesses but are often not well-monitored. Attackers take advantage of these gaps to lock down systems and demand ransom payments.
-
A 66-year-old retired serviceman’s wife from Bengaluru was tricked by cybercriminals who posed as police officers. The scammers accused her of money laundering, put her under "digital arrest," and forced her to transfer ₹35 lakh over five days.