Critical zero-day vulnerability in WinRAR is currently being exploited by cybercriminals in targeted attacks.

Critical zero-day vulnerability in WinRAR is currently being exploited by cybercriminals in targeted attacks.

A critical zero-day vulnerability in WinRAR is currently being exploited by cybercriminals in targeted attacks, prompting urgent security warnings and the immediate release of a patched version. The flaw, designated CVE-2025-8088 with a CVSS score of 8.8, represents a significant security threat that requires immediate action from all WinRAR users.
Researchers discover attack method that exploits Gemini AI through Google Calendar invites.

Researchers discover attack method that exploits Gemini AI through Google Calendar invites.

A team of cybersecurity researchers has uncovered a sophisticated attack method that exploits Google's Gemini AI assistant through seemingly innocent calendar invitations, demonstrating how artificial intelligence systems can be weaponized against their own users. The vulnerability, dubbed "Targeted Promptware Attacks," allows malicious actors to hijack Gemini's functionality and perform unauthorized actions ranging from data theft to physical world manipulation.
North Korean ScarCruft Group Shifts Strategy: Adding Ransomware to Espionage Operations.

North Korean ScarCruft Group Shifts Strategy: Adding Ransomware to Espionage Operations.

The North Korean state-backed hacking group ScarCruft has significantly evolved its tactics, moving beyond traditional cyber-espionage to incorporate ransomware attacks—marking a notable strategic shift for the group. This development represents a concerning expansion of capabilities that blends intelligence gathering with financially motivated cybercrime.
Scammers Launch Mass-Mailing Campaigns with Efimer Trojan to Steal Cryptocurrency

Scammers Launch Mass-Mailing Campaigns with Efimer Trojan to Steal Cryptocurrency

In recent months, cybersecurity experts have observed a surge in mass-mailing campaigns designed to spread the Efimer Trojan—a sophisticated and increasingly dangerous type of malware engineered to steal cryptocurrency. This new wave of attacks highlights both the technical skill and global scope of scammers targeting digital assets, underscoring the urgent need for enhanced vigilance among individuals and organizations.
Columbia University Data Breach: Far-Reaching Impacts for 869,000 Individuals

Columbia University Data Breach: Far-Reaching Impacts for 869,000 Individuals

Columbia University recently experienced a significant data breach affecting an estimated 869,000 individuals, including students, alumni, applicants, and employees. Discovered in June 2025 following a major IT outage, the breach resulted from unauthorized access beginning around May 16, 2025, with attackers extracting approximately 460GB of sensitive data prior to detection.
Satellite Cybersecurity Under the Microscope: Lessons from Black Hat Las Vegas

Satellite Cybersecurity Under the Microscope: Lessons from Black Hat Las Vegas

The rapidly expanding domain of satellite technology has brought about unprecedented opportunities for communication, earth observation, and data relay. Yet, as highlighted in a recent briefing at the Black Hat conference in Las Vegas, the race to deploy satellites has outpaced critical advancements in cybersecurity—posing potentially grave risks to both orbital and ground assets.
Supply Chain Attacks Target RubyGems and PyPI, Prompting Major Security Overhauls

Supply Chain Attacks Target RubyGems and PyPI, Prompting Major Security Overhauls

The open-source software landscape recently faced a serious wave of supply chain attacks, impacting two of its most widely used repositories: RubyGems and the Python Package Index (PyPI). These incidents have resulted in significant theft of credentials and cryptocurrency, raising new concerns and prompting urgent security reforms within these ecosystems.
CISA issues emergency directive to patch critical Microsoft Exchange vulnerability CVE-2025-53786 by Monday.

CISA issues emergency directive to patch critical Microsoft Exchange vulnerability CVE-2025-53786 by Monday.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring all Federal Civilian Executive Branch (FCEB) agencies to address a critical vulnerability in Microsoft Exchange hybrid environments, identified as CVE-2025-53786. This action is a direct response to the severe security threat posed by the flaw, with agencies mandated to complete mitigation steps by 9:00 AM EDT on Monday, August 11, 2025, and submit a comprehensive status report to CISA by 5:00 PM EDT the same day.