Category: Cybersecurity News
-
Researchers Find Cross-Platform Malware Targeting Sensitive Data and Crypto Wallets
Cybersecurity researchers at Mosyle, a device management and security provider, have discovered a new and highly stealthy malware strain, according to a report first shared with 9to5Mac. Called ModStealer that has been evading detection by all major antivirus tools for nearly a month. This discovery is particularly alarming for users on macOS, Linux and Windows
-
Critical Security Update Released for Adobe Commerce
Recently, a significant security flaw was identified in Adobe Commerce involving the Commerce REST API (CVE-2025-54236). This vulnerability could potentially allow attackers to take over customer accounts. While there are no reports of active exploitation at this time, it’s crucial to apply the hotfix to prevent any risks. The vulnerability affects how API requests are
-
Malicious Facebook Ads Distribute Fake “Meta Verified” Browser Extensions
A recent report by security researchers at Bitdefender details a malicious campaign spreading through Facebook ads that promote fake “Meta Verified” browser extensions. The campaign targets Facebook users, especially content creators and small businesses, by offering tools that claim to unlock verification features, but in reality are designed to steal account credentials and session data.
-
Report Shows Over Half of Enterprise Web Assets Lack WAF Protection
A new report from CyCognito, a cybersecurity exposure platform, has uncovered a significant blind spot in enterprise web security: more than half of internet-facing enterprise assets are not protected by Web Application Firewalls (WAFs) — including many that collect sensitive user data. The research analyzed over 500,000 external-facing assets from Fortune 2000 and Fortune 500
-
Plex Confirms Security Incident Involving User Account Data
Plex, a popular personal media server and streaming platform, has disclosed a recent security incident that exposed limited user account data. In an official announcement, the company stated that an unauthorized third party accessed one of its internal databases. While the breach was contained quickly, the affected data includes usernames, email addresses, hashed passwords, and
-
Wiz Discovers Nx Supply Chain Attack Involving AI Malware
Researchers at Wiz, a cloud security software company, have released new findings on the recent compromise of the Nx JavaScript framework, revealing a multi-phase supply chain attack that affected thousands of users and involved experimental use of AI-assisted malware. The incident began with the compromise of an npm publishing token through a vulnerable GitHub Action.
-
VirusTotal’s AI Code Insight Finds Hidden Malware Campaign in SVG Files
A recent cybersecurity report from VirusTotal, a leading online malware detection and analysis platform, reveals a sophisticated malware campaign delivered through seemingly harmless SVG files. These malicious files utilized advanced phishing techniques and malware delivery that had evaded traditional antivirus detection. Even long after Adobe discontinued Flash support, SWF files continue to circulate and sometimes
Categories:
Have any comments or suggestions? Feel free to let us know!
