US federal agency breached by hackers using GeoServer exploit

In mid-July 2024, a threat actor managed to break into a US Federal Civilian Executive Branch (FCEB) agency by exploiting a critical remote code execution (RCE) vulnerability in GeoServer, the government has confirmed. In an in-depth report detailing the incident, Read More …

UK: Man arrested in connection with cyber-attack on airports

A person has been arrested in connection with a cyber-attack which has caused days of disruption at several European airports including Heathrow. The National Crime Agency (NCA) said a man in his forties was arrested in West Sussex “as part Read More …

Top auto insurance firm leaked over 5 million records

ClaimPix, a company which streamlines car insurance claims, was leaking sensitive customer data on the clearweb, including people’s phone numbers, and email addresses, an expert has warned. Security researcher Jeremiah Fowler, known for hunting down misconfigured and unprotected databases, recently Read More …

This Is How Your LLM Gets Compromised

Plainly speaking, Artificial intelligence is no longer a fringe technology. It has become a core component of modern business, from customer service chatbots to complex data analysis. We often treat the Large Language Models (LLMs) that are at the core Read More …

Serious Microsoft Entra flaw could have let hackers infiltrate any user – patch now

Security researchers have found a critical vulnerability in Microsoft Entra ID which could have allowed threat actors to gain Global Administrator access to virtually anyone’s tenant – without being detected in any way. The vulnerability consists of two things – Read More …

EU says ransomware to blame for attack which caused chaos at airports

Hundreds of flights across Europe were cancelled and delayed after a ‘cyber-related disruption’ meant electronic customer check-in and baggage drop was taken offline. The EU’s cybersecurity agency ENISA has confirmed the disruption was linked to a ransomware incident, but did Read More …

Stellantis detects breach at third-party provider for North American customers

Stellantis detected unauthorized access to a third-party service provider’s platform that supports its North American customer service operations, the company said in a statement on Sunday. The automaker said the incident, which is under investigation, exposed only basic contact information Read More …

Cyber-attack causes delays at Heathrow and other European airports

Heathrow is among several European airports hit by a cyber-attack affecting an electronic check-in and baggage system. The airport warned of possible delays due to a “technical issue” affecting software provided by Collins Aerospace to several airlines. Brussels Airport said Read More …

WatchGuard warns users Firebox firewalls may have a critical issue

WatchGuard has fixed a critical-severity vulnerability affecting its Firebox firewalls and is urging users to apply the newly released patch without hesitation. In a security advisory, the company said it addressed an out-of-bounds write vulnerability in the WatchGuard Fireware OS Read More …

CVE-2025-10035 – Critical unauthenticated RCE in GoAnywhere MFT

On September 18, 2025, Fortra published an advisory for CVE-2025-10035. This new vulnerability affects GoAnywhere MFT, an enterprise managed file transfer solution, and allows an attacker to achieve unauthenticated remote code execution. GoAnywhere MFT is a file transfer solution that Read More …