Security News > 2025 > January

Nuclei flaw lets malicious templates bypass signature verification
2025-01-04 22:59

A now-fixed vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that...

Nuclei flaw bypasses template signature checks to execute commands
2025-01-04 22:59

A new vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that execute on...

Google Chrome is making it easier to share specific parts of long PDFs
2025-01-04 19:18

Google is adding the Text Fragment feature to its PDF reader to make it easier to share specific parts of long PDFs. [...]

New FireScam Android data-theft malware poses as Telegram Premium app
2025-01-04 15:16

A new Android malware named 'FireScam' is being distributed as a premium version of the Telegram app via phishing websites on GitHub that mimick the RuStore, Russia's app market for mobile devices. [...]

New FireScam Android malware poses as RuStore app to steal data
2025-01-04 15:16

A new Android malware named 'FireScam' is being distributed as a premium version of the Telegram app via phishing websites on GitHub that mimick the RuStore, Russia's app market for mobile devices. [...]

Encryption backdoor debate 'done and dusted,' former White House tech advisor says
2025-01-04 14:30

When the FBI urges E2EE, you know it's serious business interview In the wake of the Salt Typhoon hacks, which lawmakers and privacy advocates alike have called the worst telecoms breach in...

Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution
2025-01-04 14:29

A high-severity security flaw has been disclosed in ProjectDiscovery's Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass...

Atos denies Space Bears' ransomware claims – with a 'but'
2025-01-04 08:30

Points finger at third-party infrastructure being breached French tech giant Atos today denied that Space Bears criminals breached its systems - but noted that third-party infrastructure was...

PLAYFULGHOST Delivered via Phishing and SEO Poisoning in Trojanized VPN Apps
2025-01-04 07:52

Cybersecurity researchers have flagged a new malware called PLAYFULGHOST that comes with a wide range of information-gathering features like keylogging, screen capture, audio capture, remote...

U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns
2025-01-04 07:30

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Friday issued sanctions against a Beijing-based cybersecurity company known as Integrity Technology Group, Incorporated...