Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely — Patch Now

08/10/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a now-patched vulnerability in the popular figma-developer-mcp Model Context Protocol (MCP) server that could allow attackers to achieve code execution. The vulnerability, tracked as

Step Into the Password Graveyard… If You Dare (and Join the Live Session)

08/10/2025 0 Comments 0 tags

Every year, weak passwords lead to millions in losses — and many of those breaches could have been stopped. Attackers don’t need advanced tools; they just need one careless login.

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks

08/10/2025 0 Comments 0 tags

OpenAI on Tuesday said it disrupted three activity clusters for misusing its ChatGPT artificial intelligence (AI) tool to facilitate malware development. This includes a Russian‑language threat actor, who is said

BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers

07/10/2025 0 Comments 0 tags

A Vietnamese threat actor named BatShadow has been attributed to a new campaign that leverages social engineering tactics to deceive job seekers and digital marketing professionals to deliver a previously

Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them

07/10/2025 0 Comments 0 tags

Google’s DeepMind division on Monday announced an artificial intelligence (AI)-powered agent called CodeMender that automatically detects, patches, and rewrites vulnerable code to prevent future exploits. The efforts add to the

XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities

07/10/2025 0 Comments 0 tags

Cybersecurity researchers have charted the evolution of XWorm malware, turning it into a versatile tool for supporting a wide range of malicious actions on compromised hosts. “XWorm’s modular design is

New Research: AI Is Already the #1 Data Exfiltration Channel in the Enterprise

07/10/2025 0 Comments 0 tags

For years, security leaders have treated artificial intelligence as an “emerging” technology, something to keep an eye on but not yet mission-critical. A new Enterprise AI and SaaS Data Security

Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware

07/10/2025 0 Comments 0 tags

Microsoft on Monday attributed a threat actor it tracks as Storm-1175 to the exploitation of a critical security flaw in Fortra GoAnywhere software to facilitate the deployment of Medusa ransomware.

13-Year Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

07/10/2025 0 Comments 0 tags

Redis has disclosed details of a maximum-severity security flaw in its in-memory database software that could result in remote code execution under certain circumstances. The vulnerability, tracked as CVE-2025-49844 (aka

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks

07/10/2025 0 Comments 0 tags

CrowdStrike on Monday said it’s attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a threat actor it tracks as Graceful Spider