Security News

NSO Group fined $167M for spyware attacks on 1,400 WhatsApp users
2025-05-07 14:09

A U.S. federal jury has ordered Israeli spyware vendor NSO Group to pay WhatsApp $167,254,000 in punitive damages and $444,719 in compensatory damages for a 2019 campaign that targeted 1,400 users...

Doubling down: How Universal 2nd Factor (U2F) boosts online security
2025-05-07 14:02

Passwords alone aren't cutting it—31% of breaches involve stolen credentials. Learn from Specops Software about how Universal 2nd Factor (U2F) and strong password policies can work together to...

Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks
2025-05-07 13:54

Europol has announced the takedown of distributed denial of service (DDoS)-for-hire services that were used to launch thousands of cyber-attacks across the world. In connection with the operation,...

OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws
2025-05-07 13:44

A second security flaw impacting the OttoKit (formerly SureTriggers) WordPress plugin has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-27007 (CVSS score:...

Medical device maker Masimo warns of cyberattack, manufacturing delays
2025-05-07 13:39

Medical device company Masimo Corporation warns that a cyberattack is impacting production operations and causing delays in fulfilling customers' orders. [...]

CISA warns of hackers targeting critical oil infrastructure
2025-05-07 13:17

CISA warned critical infrastructure organizations of "unsophisticated" threat actors actively targeting the U.S. oil and natural gas sectors. [...]

PoC exploit for SysAid pre-auth RCE released, upgrade quickly!
2025-05-07 12:20

WatchTowr researchers have released a proof-of-concept (PoC) exploit that chains two vulnerabilities in SysAid On-Prem – the self-hosted version of the platform behind SysAid’s popular IT service...

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
2025-05-07 11:31

Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution...

Police takes down six DDoS-for-hire services, arrests admins
2025-05-07 11:23

​Polish authorities have detained four suspects linked to six DDoS-for-hire platforms, believed to have facilitated thousands of attacks targeting schools, government services, businesses, and...

Chinese AI Submersible
2025-05-07 11:03

A Chinese company has developed an AI-piloted submersible that can reach speeds “similar to a destroyer or a US Navy torpedo,” dive “up to 60 metres underwater,” and “remain static for more than a...