Cybersecurity News
-
Malicious AI Chrome Extensions Steal ChatGPT and DeepSeek Conversations
Security researchers at cybersecurity softare company OX Security have uncovered a widespread malware campaign involving two Chrome extensions that impersonate a legitimate AI sidebar tool while covertly collecting users’ ChatGPT and DeepSeek…
-
IBM API Connect Security Patches Released for Critical Authentication Bypass Flaw
IBM has issued a security alert for a critical authentication bypass vulnerability impacting IBM API Connect, warning that the flaw could let attackers gain access without valid credentials. API Connect is a…
-
LangChain Releases Patch to Resolve Critical Serialization Vulnerability Affecting Multiple Versions
A critical security vulnerability has been disclosed in LangChain that could enable attackers to extract environment secrets and inject unauthorized objects during deserialization. The issue affects LangChain Core versions 1.0.0 to 1.2.4…
-
Critical Remote Code Execution Vulnerability in n8n Fixed
A critical Remote Code Execution (RCE) vulnerability has been disclosed in n8n, a widely used open-source workflow automation platform. The issue affects a large range of versions and could allow attackers to…
-
WordPress E-commerce Plugin WooCommerce Patches Store API Flaw That Could Expose Guest Order Data
A security flaw affecting the online shopping platform WooCommerce has been patched after researchers discovered it could expose certain customer order details under specific conditions. The disclosure and patch details, disclosed in…
-
HPE Releases OneView Update Patching Critical Vulnerability
HPE (Hewlett-Packard Enterprise) has issued a high-severity security advisory for HPE OneView, warning of a vulnerability that could allow remote, unauthenticated attackers to execute arbitrary code on affected systems. HPE OneView is…
-
Researchers Identify WhatsApp Attack Allowing Account Takeover
Security researchers at Gen Digital have recently discovered a newly observed attack technique targeting WhatsApp, which enables attackers to gain persistent access to user accounts by abusing WhatsApp’s legitimate device-linking functionality. The…
-
Millions of AI Conversations Collected by Popular VPN/Privacy Extensions Without Consent
Users aware of their privacy online often turn to browser extensions like VPNs and ad blockers to protect their online activities. But recent research reveals that one of the most popular VPN…
-
Cloudflare’s 2025 Internet Report Highlights AI Crawl Surge, Record DDoS Attacks, and Mobile-First Traffic
Cybersecurity company Cloudflare’s latest analysis , , the 2025 Web Traffic and Security Report, highlights that in 2025 the web continued to grow steadily, while security threats and large-scale outages reached new…
