Latest Cybersecurity News and Articles
11 July 2025
Two vulnerabilities in an internal API allowed unauthorized access to contacts and chats, exposing the information of 64 million McDonald’s applicants.
The post McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications appeared first on SecurityWeek.
11 July 2025
Wing FTP Server vulnerability CVE-2025-47812 can be exploited for arbitrary command execution with root or system privileges.
The post Critical Wing FTP Server Vulnerability Exploited appeared first on SecurityWeek.
11 July 2025
The Irish Data Privacy Commission announced that TikTok is facing a new European Union privacy investigation into user data sent to China.
The post TikTok Faces Fresh European Privacy Investigation Over China Data Transfers appeared first on SecurityWeek.
11 July 2025
Since August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025.
The post July 2025 Breaks a Decade of Monthly Android Patches appeared first on SecurityWeek.
11 July 2025
Researchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models.
The post Rowhammer Attack Demonstrated Against Nvidia GPU appeared first on SecurityWeek.
11 July 2025
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog, officially confirming the vulnerability has been weaponized in the wild.
The shortcoming in question is CVE-2025-5777 (CVSS score: 9.3), an instance of insufficient input validation that
10 July 2025
Authorities in the United Kingdom this week arrested four alleged members of "Scattered Spider," a prolific data theft and extortion group whose recent victims include multiple airlines and the U.K. retail chain Marks & Spencer.
10 July 2025
Cybersecurity researchers have discovered a critical vulnerability in the open-source mcp-remote project that could result in the execution of arbitrary operating system (OS) commands.
The vulnerability, tracked as CVE-2025-6514, carries a CVSS score of 9.6 out of 10.0.
"The vulnerability allows attackers to trigger arbitrary OS command execution on the machine running mcp-remote when it
10 July 2025
Cryptocurrency users are the target of an ongoing social engineering campaign that employs fake startup companies to trick users into downloading malware that can drain digital assets from both Windows and macOS systems.
"These malicious operations impersonate AI, gaming, and Web3 firms using spoofed social media accounts and project documentation hosted on legitimate platforms like Notion and
10 July 2025
Details have been disclosed for an eSIM hacking method that could impact many, but the industry is taking action.
The post eSIM Hack Allows for Cloning, Spying appeared first on SecurityWeek.
10 July 2025
Ingram Micro has restored operations across all countries and regions after disconnecting systems to contain a ransomware attack.
The post Ingram Micro Restores Systems Impacted by Ransomware appeared first on SecurityWeek.
10 July 2025
Three teens and a woman have been arrested by the UK’s NCA over the hacking of M&S, Co-op and Harrods.
The post Four Arrested in UK Over M&S, Co-op Cyberattacks appeared first on SecurityWeek.
10 July 2025
Hackers compromised names, addresses, email address, phone numbers, and other information pertaining to Qantas customers.
The post Qantas Confirms 5.7 Million Impacted by Data Breach appeared first on SecurityWeek.
10 July 2025
Secretary of State Marco Rubio was recently impersonated via text messages and AI voice messages.
10 July 2025
The U.K. National Crime Agency (NCA) on Thursday announced that four people have been arrested in connection with cyber attacks targeting major retailers Marks & Spencer, Co-op, and Harrods.
The arrested individuals include two men aged 19, a third aged 17, and a 20-year-old woman. They were apprehended in the West Midlands and London on suspicion of Computer Misuse Act offenses, blackmail,
10 July 2025
‘Machine identities’, often used interchangeably with ‘non-human identities’ (NHIs), have been increasing rapidly since the start of digital transformation.
The post Booz Allen Invests in Machine Identity Firm Corsha appeared first on SecurityWeek.
10 July 2025
PCA Cyber Security has discovered critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.
The post Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack appeared first on SecurityWeek.
10 July 2025
Generative AI is not arriving with a bang, it’s slowly creeping into the software that companies already use on a daily basis. Whether it is video conferencing or CRM, vendors are scrambling to integrate AI copilots and assistants into their SaaS applications. Slack can now provide AI summaries of chat threads, Zoom can provide meeting summaries, and office suites such as Microsoft 365 contain
10 July 2025
AI-made decisions are in many ways shaping and governing human lives. Companies have a moral, social, and fiduciary duty to responsibly lead its take-up.
The post What Can Businesses Do About Ethical Dilemmas Posed by AI? appeared first on SecurityWeek.
10 July 2025
Cybersecurity researchers have discovered new artifacts associated with an Apple macOS malware called ZuRu, which is known to propagate via trojanized versions of legitimate software.
SentinelOne, in a new report shared with The Hacker News, said the malware has been observed masquerading as the cross‑platform SSH client and server‑management tool Termius in late May 2025.
"ZuRu malware