
Elvis Emeka Ikeji
MongoBleed Exploitation Escalates, Allowing Attackers to Access Database Secrets
The cybersecurity community is facing what experts call a “Heartbleed moment” for the NoSQL era. A critical flaw in MongoDB, the world’s most...
China-Aligned APT Evasive Panda Leveraged DNS Hijacking to Spread MgBot
China-Linked APT Uses DNS Poisoning to Deploy MgBot Backdoor in Targeted Espionage Campaign. A China-aligned advanced persistent threat (APT) grou...
CISA Flags Actively Exploited RCE Flaw in Digiever NVRs
CISA Adds Digiever NVR Vulnerability to Known Exploited Vulnerabilities Catalog Amid Active Attacks
The U.S. Cybersecurity and Infrastructure Se...
Operation PCPcat Breaches 59,000 React and Next.js Servers
Operation PCPcat: Massive Cyber Espionage Campaign Compromises Over 59,000 Servers in 48 Hours
A large-scale cyber espionage campaign, dubbed Op...
Security Researchers Targeted by WebRAT via Fake GitHub PoC Exploits
Cybercriminals are using fake GitHub repositories to distribute WebRAT, a backdoor and information stealer, by posing as security researchers shari...
Major Cyberattack Disrupts French Postal and Banking Services During Christmas Holiday Season
France’s national postal service, La Poste, and its banking subsidiary were hit by a major network disruption on Monday following a suspected cyb...
Two Chrome Extensions Steal User Credentials Across Over 170 Target Domains
Security researchers have identified two malicious Google Chrome extensions operating under the name Phantom Shuttle that intercept web traffic and...
WatchGuard Firebox Vulnerability Leaves Over 117,000 Devices Exposed to Active Attacks
Nearly 120,000 WatchGuard Firebox firewalls remain unpatched and exposed to a critical vulnerability that is already being exploited by hackers, ac...
Fake WhatsApp API Library Siphoning User Messages and Account Credentials
Cybersecurity researchers have uncovered a malicious npm package called lotusbail that poses as a legitimate WhatsApp API library. While the packag...