Skip to content
No results
  • About
  • Contact
  • CYBERSECURITY TECHNOLOGY BUSINESS
  • Home
  • Home
  • Login
  • Lost Password
  • My Account
  • Privacy Policy
  • Registration
  • Secy247 – Technology, Cybersecurity & Business
Secy247 – Technology, Cybersecurity & Business
Secy247 – Technology, Cybersecurity & Business
  • Cybersecurity
  • Technology
  • Business
  • How-To
  • News
  • About
  • Contact
  • Login
  • Registration
  • Privacy Policy
Sign Up
Secy247 – Technology, Cybersecurity & Business
Secy247 – Technology, Cybersecurity & Business
  • Cybersecurity, News

Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN

Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox…

  • adesesan
  • August 6, 2026
  • Cybersecurity, Vulnerabilities

CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an…

  • adesesan
  • August 6, 2026
  • Cybersecurity, News

New Kali365 Phishing Campaign Targets Microsoft 365 Organizations

A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login…

  • adesesan
  • August 6, 2026
  • Cybersecurity, News, Threats & Attacks

New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers

Cybersecurity researchers have uncovered a new blockchain-based technique that allows attackers to hide malware command-and-control (C2) server addresses in a way that is even more difficult to detect than previous methods. The technique, dubbed NullReceiver, was discovered in two malicious…

  • adesesan
  • August 6, 2026
  • Cybersecurity, Vulnerabilities

Paperclip Security Vulnerabilities Put AI Agent Platforms at Risk

Security researchers have disclosed three serious vulnerabilities in Paperclip, an open-source control platform designed to manage teams of AI agents. Two of the flaws could allow attackers to execute malicious commands on either a server or a developer’s local machine,…

  • adesesan
  • August 6, 2026
  • Cybersecurity, News, Technology

OpenAI Shuts Down ChatGPT Scam Network Linked to Cambodia

OpenAI has dismantled a network of ChatGPT accounts connected to a large-scale scam operation believed to be operating from Poipet, Cambodia. According to the company, the group used generative AI to support multiple fraud campaigns, including investment scams, romance fraud,…

  • adesesan
  • August 6, 2026
  • Cybersecurity, Vulnerabilities

Developers Urged to Patch Critical vm2 Node.js Vulnerabilities Immediately

Security researchers have revealed 12 critical vulnerabilities affecting the popular vm2 Node.js library, exposing applications to sandbox escapes and remote code execution attacks. The vm2 package is widely used by developers to safely run untrusted JavaScript code inside isolated environments.…

  • adesesan
  • May 7, 2026
  • Cybersecurity, Vulnerabilities

Hackers Could Exploit vm2 Flaws to Break Out of JavaScript Sandboxes

Security researchers have disclosed 12 high-severity vulnerabilities affecting the widely used vm2 Node.js library, raising serious concerns for developers and organizations that rely on the package to securely execute untrusted JavaScript code. The open-source vm2 library is commonly used to…

  • adesesan
  • May 7, 2026
  • Cybersecurity, News, Threats & Attacks

Malicious PyPI Packages Discovered Delivering New ZiChatBot Malware on Windows and Linux Systems

Cybersecurity researchers have uncovered a new supply chain attack involving malicious packages uploaded to the Python Package Index (PyPI) repository that secretly install a previously undocumented malware strain called ZiChatBot on both Windows and Linux devices. According to researchers at…

  • adesesan
  • May 7, 2026
  • Cybersecurity, News

The Hidden Incident Response Problems That Slow Down Cyberattack Containment

Many organizations believe that signing an incident response retainer agreement means they are prepared for a cyberattack. Security experts say that assumption is dangerously misleading. A retainer may guarantee that someone answers the phone during a crisis, but it does…

  • adesesan
  • May 7, 2026
  • Cybersecurity, Threats & Attacks

Hackers Exploit AI, Fake Ads, and Malware in Massive Global Cybercrime Surge

ThreatsDay 2026: New Malware, AI-Powered Cyber Threats, Supply Chain Attacks, and Critical Security Flaws Dominate the Week The cybersecurity world had another chaotic week as researchers uncovered new malware campaigns, critical software vulnerabilities, large-scale phishing operations, and growing concerns over…

  • adesesan
  • May 7, 2026
  • Cybersecurity, Vulnerabilities

Critical PAN-OS Security Flaw Allows Root-Level Remote Code Execution

A newly disclosed critical vulnerability affecting Palo Alto Networks PAN-OS software may have been targeted by attackers weeks before public disclosure, according to new findings from the company’s Unit 42 threat intelligence team. The flaw, tracked as CVE-2026-0300, is a…

  • adesesan
  • May 7, 2026
  • News, Threats & Attacks

Attackers Exploit CAPTCHA and PDF Lures in Large-Scale Phishing Campaign

Microsoft has revealed details of a large-scale phishing campaign that tricked tens of thousands of users into handing over their login credentials by using convincing internal-style emails and advanced evasion tactics. The attack, observed between April 14 and April 16,…

  • adesesan
  • May 5, 2026
  • Cybersecurity, Vulnerabilities

ScarCruft Targets Users With Malware Hidden in Gaming Apps

A state-sponsored hacking group tied to North Korea, known as ScarCruft, has been linked to a supply chain attack involving a gaming platform, where attackers secretly embedded spyware into game components to monitor targeted users. Security researchers from ESET say…

  • adesesan
  • May 5, 2026
  • Cybersecurity, News, Technology

Security Warning: Self-Hosted AI Tools Are Leaving Data and Systems Exposed

The rapid adoption of artificial intelligence is creating new security challenges, with recent findings showing that many AI systems are being deployed with serious vulnerabilities. A study by Intruder reveals that modern AI infrastructure is often more exposed and poorly…

  • adesesan
  • May 5, 2026
  • News, Threats & Attacks, Top Stories

Urgent Warning: MetInfo CMS Vulnerability Allows Remote Code Execution

Cybersecurity researchers are warning that attackers are already exploiting a serious flaw in the open-source CMS MetInfo CMS, putting thousands of websites at risk. The vulnerability, tracked as CVE-2026-29014, carries a high severity score of 9.8 and allows attackers to…

  • adesesan
  • May 5, 2026
  • Cybersecurity, News

Unmanaged OAuth Tokens Are a Silent Security Threat in Modern Enterprises

Every time employees connect AI tools, automation platforms, or productivity apps to services like Google or Microsoft, they leave behind something many organizations fail to track, long-lasting OAuth tokens. These tokens often have no expiration, no automatic cleanup, and in…

  • adesesan
  • May 5, 2026
  • Cybersecurity, News

UAT-8302 Deploys Advanced Backdoors in Ongoing Government Cyber Attacks

A highly advanced cyber espionage group with ties to China has been linked to a wave of attacks against government institutions in South America and southeastern Europe, according to new findings from Cisco Talos. The threat group, tracked as UAT-8302,…

  • adesesan
  • May 5, 2026
  • News, Threats & Attacks

Apache HTTP Server Update Fixes Dangerous HTTP/2 Double-Free Bug

The Apache Software Foundation (ASF) has rolled out security updates to fix multiple issues in its HTTP Server, including a high-risk vulnerability that could allow attackers to execute code remotely. The flaw, tracked as CVE-2026-23918 and rated 8.8 on the…

  • adesesan
  • May 5, 2026
  • News, Technology, Threats & Attacks

“Supply Chain Attack Alert: Hidden Malware Discovered in npm, PyPI, Go, and Rust Packages”

A cyber campaign known as Contagious Interview, believed to be linked to North Korean threat actors, is expanding its reach by planting malicious packages across several major developer ecosystems. Security researchers have discovered that the attackers are disguising malware as…

  • adesesan
  • April 9, 2026
1 2 3 4 … 9
Next
Copyright © 2026 - WordPress Theme by CreativeThemes