Category: Cybersecurity News
-
VirusTotal’s AI Code Insight Finds Hidden Malware Campaign in SVG Files
A recent cybersecurity report from VirusTotal, a leading online malware detection and analysis platform, reveals a sophisticated malware campaign delivered through seemingly harmless SVG files. These malicious files utilized advanced phishing techniques and malware delivery that had evaded traditional antivirus detection. Even long after Adobe discontinued Flash support, SWF files continue to circulate and sometimes
-
Shadowserver Highlights Elevated Activity in HTTP-Based Network Scans
The Shadowserver Foundation, a non-profit security organization, has identified a significant uptick in high-severity activities involving hosts performing HTTP-based scans across diverse networks worldwide. These activities often include attempts to detect and potentially exploit vulnerabilities in targeted systems. The report, originally developed as part of the EU Horizon 2020 SISSDEN Project and extended under the
-
Unauthorized TLS Certificates Issued for Cloudflare’s 1.1.1.1 DNS Resolver
Recently, a security incident involving the unauthorized issuance of TLS certificates for 1.1.1.1, a widely used public DNS resolver, has come to light. Over nearly a year and a half, a Certificate Authority (Fina CA) issued twelve certificates for this IP address without proper authorization. While there’s no current evidence these certificates were exploited maliciously,
-
Cloudflare Successfully Blocks Massive 11tb DDoS Attacks
In recent weeks, Cloudflare has been actively protecting its network from a surge of large-scale Distributed Denial of Service (DDoS) attacks. Security systems have autonomously identified and blocked hundreds of these malicious assaults, some reaching unprecedented volumes. One of the most significant attacks peaked at an astonishing 5.1 billion packets per second, and 11.5 terabits
-
Jaguar Land Rover Posts Notice on Cybersecurity Incident Impacting Operations
Jaguar Land Rover (JLR), the British automotive manufacturer known for its luxury vehicles including Range Rover, Discovery, and Jaguar’s line of elegant vehicles, recently disclosed a significant cyber incident affecting its global operations. In a statement on their official website, the company revealed that they proactively shut down their systems to mitigate the impact of
-
Critical SQL Injection Vulnerability Patched in WordPress Membership Plugin
A critical security vulnerability discovered by Patchstack cybersecurity researchers within the widely-used Paid Membership Subscriptions WordPress plugin has recently been patched. This flaw could have allowed cybercriminals to access sensitive website databases without any authentication. The Paid Membership Subscriptions plugin is a popular tool that helps website owners create membership sites and manage recurring subscriptions,
-
Critical Security Update Released for FreePBX Systems
New updates have been released for FreePBX, an open-source VoIP phone system managent platform. These updates include a critical security fix addressing a recently discovered vulnerability impacting certain configurations where the admin interface was exposed to the internet, and could have potentially allowed unauthorized access or control. This vulnerability, tracked as CVE-2025-57819, specifically affects the
Categories:
Have any comments or suggestions? Feel free to let us know!
