Newly Discovered SMM Vulnerabilities in Gigabyte motherboard UEFI Firmware

Newly Discovered SMM Vulnerabilities in Gigabyte motherboard UEFI Firmware

Recent security research has revealed a series of critical vulnerabilities in Gigabyte motherboard firmware. Cybersecurity experts disclosed four severe vulnerabilities (CVE-2025-7026 through CVE-2025-7029) within the System Management Mode (SMM) components of Gigabyte’s UEFI firmware. SMM operates at a privilege level beneath the operating system, making it an attractive target for attackers seeking stealthy, persistent access.
Google Gemini can be exploited through indirect prompt injection to allow embedding of malicious content that directs users to phishing sites.

Google Gemini can be exploited through indirect prompt injection to allow embedding of malicious content that directs users to phishing sites.

Google Gemini for Workspace can be exploited through a technique called indirect prompt injection. This allows attackers to manipulate Gemini’s email summaries, making them appear legitimate while embedding malicious instructions or warnings that direct users to phishing sites—without using traditional attachments or direct links.
14 arrested for defrauding the UK government of 47 million in a sophisticated phishing attack.

14 arrested for defrauding the UK government of 47 million in a sophisticated phishing attack.

A coordinated international law enforcement operation has led to the arrest of 14 individuals suspected of orchestrating a sophisticated phishing attack that defrauded the UK government of an estimated £47 million. The large-scale scam, which targeted His Majesty’s Revenue and Customs (HMRC), compromised over 100,000 taxpayer accounts and stands as one of the most significant tax-related cybercrimes in recent UK history.
Computer hacker holding a video game controller

DOJ seizes several high-profile online marketplaces for distributing pirated video games.

The Department of Justice (DOJ) and the FBI’s Atlanta Field Office have announced the successful seizure and dismantling of several high-profile online marketplaces responsible for distributing pirated video games. This coordinated operation marks a significant victory in the ongoing fight against digital piracy and intellectual property theft.
Popular WordPress plugin Gravity Forms compromised in supply-chain attack.

Popular WordPress plugin Gravity Forms compromised in supply-chain attack.

The popular WordPress plugin Gravity Forms has been compromised in a supply-chain attack. For a brief window in July 2025, attackers managed to infect the manual installer packages available for download from the official Gravity Forms website with a backdoor. This incident did not affect automatic updates or installations performed through the built-in plugin updater, only manual downloads and composer installations.
Computer hacker holding a large metal lock and key

Force Push Scanner technique uncovers thousands of sensitive credentials and tokens in GitHub repositories.

White-hat researchers have recently exploited the Force Push Scanner technique to uncover thousands of active secrets in GitHub repositories. Security researcher Sharon Brizinov used the tool to scan "deleted" (dangling) commits and discovered a trove of sensitive credentials, including admin access tokens for major projects like Istio.
Alarm sounded over a critical vulnerability in Wing FTP Server (CVE-2025-47812) that is currently being exploited in the wild.

Alarm sounded over a critical vulnerability in Wing FTP Server (CVE-2025-47812) that is currently being exploited in the wild.

Security researchers and threat intelligence teams are sounding the alarm over a critical vulnerability in Wing FTP Server, tracked as CVE-2025-47812, which is currently being exploited in the wild. The flaw, which affects all versions up to and including 7.4.3, enables remote attackers to execute arbitrary code on vulnerable servers, potentially leading to full system compromise.
Computer hacker with Android robot on desk

Google dusts off its hands. Its job is done. For the first time in nearly a decade, there will be no monthly security update for Android.

In a notable departure from nearly a decade of routine, July 2025 marks the first month since August 2015 that Google has not released any security updates for Android devices. This pause in the monthly update cycle is unprecedented and has drawn attention from both industry experts and the broader Android community.