Malicious Developer Extensions Power Sophisticated “Evelyn” Malware Campaign Stealing Credentials and Crypto Assets
In early December 2025, a highly targeted malware campaign was identified that focused on compromising software developers…
continue reading..
Researchers Uncover Global Malvertising Operation Delivering Delayed-Execution Infostealer
In mid-2025, Sophos Managed Detection and Response (MDR) teams discovered a sophisticated malvertising campaign deploying a credential-stealing…
continue reading..
Firefox Joins Chrome and Edge as Malicious “Sleeper” Extensions Spy on Users
Over the past few years, browser extensions have quietly become one of the most overlooked security risks…
continue reading..
“WhisperPair”: Bluetooth Fast Pair Flaw Enabling Eavesdropping and Tracking
CVE-2025-36911, also known by researchers as WhisperPair, is a serious security vulnerability affecting Bluetooth devices that implement…
continue reading..
Australia Warned: Critical Infrastructure Exposed to Emerging Drone-Enabled Cyber Threats
New research from the University of Canberra and Innovation Central Canberra (ICC), supported by defence tech partner…
continue reading..
Critical XSS Vulnerability Discovered in Movary Allows Attackers to Execute Malicious Scripts via Crafted Links
CVE-2026-23841 is a reflected cross-site scripting (XSS) vulnerability affecting Movary versions prior to 0.70.0.The issue arises from…
continue reading..
MyTube Flaw Allows Anyone to Access Protected Settings Without Authentication
CVE-2026-23837 is a critical authorization bypass vulnerability affecting the MyTube application in versions prior to 1.7.66. The…
continue reading..
UK Government Warns of Ongoing Cyber Disruption as Pro-Russian Hacktivists Target Public Services
The UK government has issued a renewed cybersecurity warning highlighting ongoing attacks by Russian-aligned hacktivist groups against…
continue reading..
Critical Apache bRPC Flaw Exposes Servers to Unauthenticated Remote Command Execution (CVE-2025-60021)
CVE-2025-60021 is a critical remote command injection vulnerability in Apache bRPC, a high-performance RPC framework commonly used…
continue reading..
