A critical flaw in Imunify360 allowed attacker code to run during scans, putting millions of websites at risk. The post Imunify360 Zero-Day Leaves Millions of Websites Open to RCE appeared first on eSecurity Planet. This article has been indexed from…
Category: eSecurity Planet
Inside the First AI-Driven Cyber Espionage Campaign
Anthropic uncovered the first large-scale cyber espionage campaign powered largely by autonomous AI. The post Inside the First AI-Driven Cyber Espionage Campaign appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Inside…
5 Key Cybersecurity Trends to Know in 2025
The cybersecurity space is constantly changing. Discover the cybersecurity trends of 2025 — and how security teams are simplifying complexity through clarity, context, and control. The post 5 Key Cybersecurity Trends to Know in 2025 appeared first on eSecurity Planet.…
Multiple GitLab Vulnerabilities Allow Prompt Injection and Data Theft
GitLab has released urgent fixes for vulnerabilities that allow prompt injection and data exposure across its platform. The post Multiple GitLab Vulnerabilities Allow Prompt Injection and Data Theft appeared first on eSecurity Planet. This article has been indexed from eSecurity…
How 43,000 NPM Spam Packages Hid in Plain Sight for Two Years
A two-year campaign quietly flooded npm with 43,000 dormant packages, exposing major supply-chain security gaps. The post How 43,000 NPM Spam Packages Hid in Plain Sight for Two Years appeared first on eSecurity Planet. This article has been indexed from…
SAP Patches Severe Code Injection Flaw Enabling System Takeover
SAP’s latest emergency patches reveal how one critical flaw in core management systems can expose an entire enterprise to takeover. The post SAP Patches Severe Code Injection Flaw Enabling System Takeover appeared first on eSecurity Planet. This article has been…
Dangerous runC Flaws Could Allow Hackers to Escape Docker Containers
New runC vulnerabilities allow potential container escapes and host takeover, putting Docker, Kubernetes, and cloud-native environments at risk. The post Dangerous runC Flaws Could Allow Hackers to Escape Docker Containers appeared first on eSecurity Planet. This article has been indexed…
Operation Endgame Dismantles 1,025 Malware Servers
Europol and Eurojust dismantled major criminal infrastructure powering widespread infostealer, RAT, and botnet operations. The post Operation Endgame Dismantles 1,025 Malware Servers appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Operation…
ChatGPT Exploited Through SSRF Flaw in Custom GPT Actions
A patched SSRF flaw in ChatGPT’s Custom GPTs exposed how AI features can unintentionally reveal sensitive cloud metadata. The post ChatGPT Exploited Through SSRF Flaw in Custom GPT Actions appeared first on eSecurity Planet. This article has been indexed from…
Google Debuts Private AI Compute to Protect Data in Cloud AI
Google’s Private AI Compute delivers powerful cloud AI while keeping user data fully private. The post Google Debuts Private AI Compute to Protect Data in Cloud AI appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet…
U.S. Launches Strike Force to Combat Global Crypto Fraud
The U.S. launched a Strike Force to dismantle global crypto scam networks. The post U.S. Launches Strike Force to Combat Global Crypto Fraud appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article:…
AppleScript Abused to Spread Fake Zoom and Teams macOS Updates
Hackers use AppleScript to disguise macOS malware as fake app updates, bypassing Apple’s protections. The post AppleScript Abused to Spread Fake Zoom and Teams macOS Updates appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…
Phishing Campaign Exploits Meta Business Suite to Target SMBs
Hackers are exploiting Meta Business Suite to launch global phishing attacks. The post Phishing Campaign Exploits Meta Business Suite to Target SMBs appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Phishing…
North Korean APT Uses Remote Wipe to Target Android Users
North Korean hackers are exploiting Google’s Find Hub to wipe Android devices. The post North Korean APT Uses Remote Wipe to Target Android Users appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…
Severe Ivanti Bugs Let Attackers Modify Files and Gain Access
Ivanti patched severe Endpoint Manager flaws that could let attackers gain system access. The post Severe Ivanti Bugs Let Attackers Modify Files and Gain Access appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the…
Holiday Fraud Trends 2025: The Top Cyber Threats to Watch This Season
Holiday fraud in 2025 is evolving faster than ever, as attackers use AI, automation, and stolen data to launch large-scale campaigns. The post Holiday Fraud Trends 2025: The Top Cyber Threats to Watch This Season appeared first on eSecurity Planet.…
BeeStation RCE Zero-Day Puts Synology Devices at High Risk
A critical BeeStation OS flaw lets attackers run remote code on unpatched Synology devices. The post BeeStation RCE Zero-Day Puts Synology Devices at High Risk appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the…
65% of Leading AI Companies Found Leaking Secrets on GitHub
Wiz Security found 65% of top AI companies leaked secrets on GitHub, exposing sensitive data and highlighting critical security gaps. The post 65% of Leading AI Companies Found Leaking Secrets on GitHub appeared first on eSecurity Planet. This article has…
Critical Zoom Vulnerability Exposes Windows Users to Attacks
A new Zoom Workplace flaw (CVE-2025-64740) lets attackers escalate privileges on Windows. The post Critical Zoom Vulnerability Exposes Windows Users to Attacks appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Critical…
Monsta FTP Remote Code Execution Vulnerability (CVE-2025-34299)
Critical flaw in Monsta FTP (CVE-2025-34299) allows remote code execution without authentication, putting thousands of servers at risk. The post Monsta FTP Remote Code Execution Vulnerability (CVE-2025-34299) appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet…