Cybersecurity News
-
Critical OneLogin Vulnerability Exposed Enterprise App Secrets via API Endpoint
A newly disclosed security vulnerability in OneLogin’s platform could have exposed sensitive authentication credentials for hundreds of thousands of enterprise applications. The flaw, identified and responsibly reported by cybersecurity firm Clutch Security,…
-
Apple Issues Critical Security Update to Fix Font Handling Bug Across Multiple Devices
Apple has released an important security update addressing a vulnerability in its font parsing system that affects several of its operating systems, including iOS, iPadOS, macOS, and visionOS. This update is crucial…
-
Researchers Find Security Flaws in Tile Bluetooth Trackers
A research team from the Georgia Institute of Technology has discovered several security vulnerabilities in Tile, the Bluetooth tracking device used to locate lost personal items, as recently highlighted in a Malwarebytes…
-
Broadcom Releases Important Security Updates for VMware Aria Operations, Tools, vCenter, and NSX
Broadcom have recently released new security advisories detailing multiple vulnerabilities affecting VMware Aria Operations, VMware Tools, VMware vCenter, NSX, and related products. The advisories warn of several high-severity flaws including local privilege…
-
Popular npm Email Tool Compromised to Steal Emails
Cybersecurity firm Koi Security has identified a malicious version of an npm package used for automated email handling, which was silently forwarding outbound messages to an external domain controlled by the developer.…
-
Drupal Releases Security Fixes for Vulnerabilities Across Multiple Modules
Drupal, the widely-used content management system powering millions of websites globally, has issued important security updates addressing vulnerabilities in six popular contributed modules. Among these, a critical flaw demands immediate attention from…
-
Infostealer Malware Disguised as Fake Versions of Popular Apps Targeting Macs
Security researchers at Malwarebytes have uncovered a widespread campaign using fake GitHub pages to distribute macOS information-stealing malware. The operation impersonates legitimate software projects and tricks users into installing a strain of…
-
Fortra Patches Critical Command Injection Flaw in GoAnywhere MFT
A critical vulnerability has been discovered in Fortra’s GoAnywhere MFT software that demands urgent attention from IT administrators and security teams. On September 18th, 2025, Fortra released a security advisory detailing a…
-
Vulnerability in OpenAI’s ChatGPT Could Leak Sensitive Gmail Data
A new zero-click vulnerability, dubbed ShadowLeak, has been discovered in OpenAI’s ChatGPT Deep Research agent, according to a report by The Hacker News. The flaw has the potential to expose Gmail inbox…
