In a significant move to counter cyber threats, the United States and the United Kingdom have imposed sanctions on a group of China-linked hackers accused of targeting critical infrastructure in …
Best Practices for Email Security Headers – 2024
Email hacking and fraud have become common these days. Cybercriminals can easily break into and take control of mail accounts if they are not protected. They can do so through …
2 Firefox Zero-Days Exploited At Pwn2Own : Patch Now
Mozilla addresses two zero-day vulnerabilities that were recently exploited at the Pwn2Own Vancouver 2024 hacking contest in the Firefox web browser. The Pwn2Own Vancouver 2024 hacking competition was held this …
Critical OpenVPN Flaw Let Attackers Escalate Privilege
OpenVPN has released their new version 2.6.10 in which there have been several bug fixes and improvements specifically to the Windows Platform of the VPN application. Four vulnerabilities were also …
Threat Actor Claims to Have 600,000 Passenger Data of Kuwait Airways
A threat actor has claimed responsibility for a massive data breach affecting Kuwait Airways. According to the hacker’s statement on a popular social media platform, the breach has compromised the …
Beware of Ramadan & Eid Fitr Online Scams that Steal your Financial Data
As the holy month of Ramadan approaches, bringing a surge in online shopping and charitable giving, cybercriminals are ramping up their efforts to exploit the festive spirit. A recent study …
Hackers Transform Raspberry Pi Into A Hacking Tool
GEOBOX is specialized software designed for Raspberry Pi devices that have been observed on the Dark Web being marketed as the next major development in fraud and anonymity technologies. Cybercriminals …
MobSF Pen-Testing Tool Input Validation Flaw Leads to SSRF
The Mobile Security Framework (MobSF), a widely used pen-testing, malware analysis, and security assessment framework, has been found to contain a critical input validation flaw that could lead to server-side …
XSS Vulnerability in Google Subdomain Let Hackers Hijacks the User Sessions
Security researcher Henry N. Caga has identified a significant cross-site scripting (XSS) vulnerability within a Google sub-domain that allows hackers to perform various attacks, including session hijacking, phishing attacks, malware …
Unsaflok Flaw Let Attackers Open Million of Doors in Seconds
Unsaflok, in Dormakaba’s Saflok electronic RFID locks used in hotels and multi-family housing, allows attackers to forge a master keycard by exploiting weaknesses in the system and then using it …


