Zoom and GitLab have issued urgent security updates to address multiple vulnerabilities that could allow remote code execution (RCE), denial-of-service (DoS) attacks, and two-factor authentication (2FA)...
LastPass has issued a warning about a new phishing campaign impersonating the password management service, aiming to trick users into revealing their master passwords. The campaign,...
Security researchers have disclosed three vulnerabilities in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic, that could allow attackers to read, overwrite,...
Cybersecurity researchers have disclosed a critical prompt injection vulnerability in Google Gemini that allowed threat actors to bypass privacy controls and exfiltrate private Google Calendar data....
This week’s cybersecurity threats highlight a growing trend: attackers don’t always need new exploits—they leverage ordinary tools, trusted workflows, and routine services in the wrong hands....
Google Threat Intelligence Group (GTIG) has uncovered three new malware families developed by the Russian-linked hacking group COLDRIVER, signaling an accelerated “operations tempo” since May 2025....
The Kimwolf botnet has grown to over 2 million Android devices, largely exploiting residential proxy networks, according to cybersecurity firm Synthient. Active since at least August...
A software supply chain attack involving the self-replicating Shai-Hulud 2.0 worm has been linked to a $8.5 million theft from cryptocurrency wallet Trust Wallet, the company...
A high-severity vulnerability affecting multiple versions of MongoDB is actively being exploited by threat actors worldwide. Dubbed MongoBleed (CVE-2025-14847), the flaw allows unauthenticated attackers to leak...
Dec. 29, 2025 — A critical security flaw in MongoDB, identified as CVE-2025-14847 and nicknamed MongoBleed, is being actively exploited across the globe, with over 87,000...