Security News > 2025 > January

Laravel admin package Voyager vulnerable to one-click RCE flaw
2025-01-29 19:27

Three vulnerabilities discovered in the open-source PHP package Voyager for managing Laravel applications could be used for remote code execution attacks. [...]

Microsoft investigates Microsoft 365 outage affecting users, admins
2025-01-29 18:55

Microsoft is investigating an ongoing outage preventing users and admins from accessing some Microsoft 365 services and the admin center. [...]

FBI seizes Cracked.io, Nulled.to hacking forums in Operation Talent
2025-01-29 17:30

The FBI has seized the domains for the infamous Cracked.io and Nulled.to hacking forums, which are known for their focus on cybercrime, password theft, cracking, and credential stuffing attacks. [...]

FBI seizes domains for Cracked.io, Nulled.to hacking forums
2025-01-29 17:30

The FBI has seized the domains for the infamous Cracked.io and Nulled.to hacking forums, which are known for their focus on cybercrime, password theft, cracking, and credential stuffing attacks. [...]

Lazarus Group Uses React-Based Admin Panel to Control Global Cyber Attacks
2025-01-29 16:56

The North Korean threat actor known as the Lazarus Group has been observed leveraging a "web-based administrative platform" to oversee its command-and-control (C2) infrastructure, giving the...

Windows 11's Start menu is getting iPhone and Android integration
2025-01-29 16:54

Windows 11's Start menu is getting a big update with full-fledged Android and iPhone integration. [...]

Zyxel CPE devices under attack via critical vulnerability without a patch (CVE-2024-40891)
2025-01-29 16:23

CVE-2024-40891, a command injection vulnerability in Zyxel CPE Series telecommunications devices that has yet to be fixed by the manufacturer, is being targeted by attackers, cybersecurity company...

Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet
2025-01-29 15:32

And now you won't stop calling me, I'm kinda busy A new variant of the Mirai-based malware Aquabot is actively exploiting a vulnerability in Mitel phones to build a remote-controlled botnet,...

Uncover Hidden Browsing Threats: Get a Free Risk Assessment for GenAI, Identity, Web, and SaaS Risks
2025-01-29 14:59

As GenAI tools and SaaS platforms become a staple component in the employee toolkit, the risks associated with data exposure, identity vulnerabilities, and unmonitored browsing behavior have...

Hackers exploit critical unpatched flaw in Zyxel CPE devices
2025-01-29 14:42

Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July. [...]