Category: Cybersecurity News
-
BridgePay Confirms Ransomware Attack Behind Ongoing Payment Gateway Outage
Payment processor BridgePay Network Solutions has confirmed in a status update on their website that a ransomware attack is responsible for a multi-day outage affecting its payment gateway and related services. The company shared updates through its official status page. According to BridgePay, the incident has resulted in widespread service disruptions across its production and
-
Nginx Releases Version 1.29.5 With Security Fix for Upstream Traffic Issue
The nginx project has released nginx 1.29.5, a mainline update that includes a security fix for an SSL upstream injection vulnerability, tracked as CVE-2026-1642. The patched vulnerability affects certain configurations where nginx proxies traffic to upstream servers over TLS. Under specific conditions, an attacker positioned between nginx and its upstream server could potentially inject plaintext
-
Malwarebytes Online Threat Checks Now Available in ChatGPT
Malwarebytes has released a new ChatGPT app that allows users to check suspected scams directly within the chatbot interface. The integration makes Malwarebytes the first cybersecurity company to provide scam analysis and threat intelligence through ChatGPT’s app platform. The feature allows users to submit potentially suspicious content for review during an active conversation, without switching
-
One-Click Security Flaw Found in Moltbot AI Tool
A high-severity security vulnerability has been disclosed in clawdbot, an npm package used by the Moltbot AI automation platform, according to a recent GitHub Security Advisory. The issue allows attackers to achieve remote code execution (RCE) with a single click by exploiting how the platform’s control interface handles authentication tokens. Moltbot is a locally run
-
Researchers Detail Directory Technique Used to Hijack WordPress Permalinks
Security researchers at Sucuri have identified a WordPress malware technique that allows attackers to inject spam content into search engine results while leaving the website’s visible pages unchanged. The activity was uncovered during a site cleanup after a customer reported seeing gambling-related content appearing in Google search results. According to Sucuri, attackers targeted trusted pages
-
Microsoft to Disable NTLM by Default in Future Windows Releases
Microsoft in a recent blog post has announced that it will disable the legacy NTLM authentication protocol by default in upcoming Windows Server and Windows client releases, citing long-standing security weaknesses. NTLM (New Technology LAN Manager) is an authentication protocol that was introduced in 1993 with Windows NT and was the default for domain-joined systems
-
Thousands of AI Systems Found Openly Accessible Online
As AI tools become easier to run outside of major cloud platforms, a new and largely unseen layer of AI infrastructure is quietly taking shape online. Joint research by SentinelLabs and Censys has revealed that over 170,000 AI systems are now publicly reachable on the open internet and operating without the safeguards, monitoring, or oversight
-
Match Group Reports Data Breach Affecting Multiple Dating Apps
Match Group, the parent company behind Tinder, Hinge, OkCupid, Match.com, and Meetic, has reported a cybersecurity incident that resulted in unauthorized access to user data across several of its platforms. According to Bleepingcomputer, Match Group confirmed the attack traces back to a social engineering effort where attackers compromised an Okta single sign-on account through a
Categories:
Have any comments or suggestions? Feel free to let us know!
