Browsing: Cyber Incidents
Introduction: Vatican Click to Pray API Flaw — Why It Matters The Vatican Click to Pray API Flaw has reportedly exposed the personal information of more than 700,000 users through an unauthenticated API vulnerability. The issue affected the Vatican’s official Click to Pray platform n what has become known as the Vatican Click to Pray API Flaw, which offers daily prayers and spiritual content to users worldwide. According to security reports, the vulnerability stemmed from an Insecure Direct Object Reference (IDOR) issue that allowed anyone to retrieve user records without logging in. Although the incident was not caused by malware…
Introduction: Bank of Baroda Data Breach — Why It Matters India’s banking sector is facing renewed cybersecurity concerns after reports emerged about the Bank of Baroda Data Breach, an alleged incident involving a claimed 1TB database published on the dark web. At the time of writing, Bank of Baroda is investigating the authenticity of the reported leak, and no official confirmation has been issued by the bank, CERT-In, or the Reserve Bank of India (RBI). If verified, the incident could become one of the largest alleged data exposure events involving an Indian public-sector bank, raising significant concerns over customer privacy,…
Introduction: TELESHIM Malware Campaign — Why It Matters A newly discovered cyber espionage operation has brought sophisticated malware techniques back into the spotlight. According to Zscaler ThreatLabz, the TELESHIM Malware Campaign targets government entities across the Middle East by abusing Telegram’s API for stealthy command-and-control (C2) communications. Unlike conventional malware that relies on dedicated attacker-controlled servers, TELESHIM Malware Campaign leverages a trusted messaging platform to blend malicious traffic with legitimate network activity. Combined with multiple defense evasion techniques and carefully staged payload deployment, the campaign demonstrates the growing sophistication of modern cyber-espionage operations. The discovery also highlights a broader industry…
Introduction: GitLab RCE Vulnerability — Why It Matters A newly disclosed GitLab RCE Vulnerability has revealed that two long-hidden flaws in the Oj Ruby JSON parser can be chained together to achieve remote code execution (RCE) on default GitLab installations. The vulnerabilities affect GitLab’s processing of Jupyter Notebook (.ipynb) file differences, allowing specially crafted JSON payloads to trigger arbitrary command execution. The GitLab RCE Vulnerability primarily impacts self-managed GitLab deployments. Since attackers only require authenticated repository access with permission to push code and view diffs, organizations relying on vulnerable versions face significant risks if they delay patching. What is GitLab?…
Introduction: Bing Images RCE Vulnerability — Why It Matters Microsoft has patched three critical security vulnerabilities collectively referred to as the Bing Images RCE Vulnerability, including two severe Remote Code Execution (RCE) flaws that affected Bing Images. The vulnerabilities, each carrying a CVSS score of 9.8, were discovered by AI security researcher XBOW and could have allowed attackers to execute arbitrary commands on Microsoft’s backend servers using specially crafted SVG image files. The Bing Images RCE Vulnerability targeted Bing’s Search by Image upload feature and its reverse image search crawler, demonstrating how seemingly harmless image uploads can become powerful attack…
Introduction: Why ChonkyChicken Malware Matters Security researchers have identified ChonkyChicken Malware, a sophisticated Remote Access Trojan (RAT) linked to the well-known TAG-195 threat ecosystem, also tracked as Golden Chickens or Venom Spider. The malware introduces advanced capabilities that allow attackers to steal browser credentials, hijack authenticated sessions, move laterally across enterprise networks, and continuously monitor victim activity. Unlike conventional credential stealers that depend solely on extracting saved passwords, ChonkyChicken reportedly targets active browser sessions and system information, making it particularly dangerous for organizations that rely on browser-based cloud services. The discovery highlights how modern malware campaigns are evolving beyond simple…
Introduction: Why Next.js Security Flaws Matter Vercel has released important security updates addressing Next.js Security Flaws, fixing nine vulnerabilities that could allow attackers to perform Server-Side Request Forgery (SSRF), bypass authentication, trigger Denial-of-Service (DoS) attacks, expose sensitive information, and cause cache-related issues. The vulnerabilities were responsibly disclosed by security researcher KarimPwnz and affect multiple components of the widely used React framework. The fixes for the Next.js Security Flaws are available in Next.js versions 15.5.21 and 16.2.11, while older 13.x and 14.x releases will not receive security updates. Organizations using unsupported versions are strongly encouraged to upgrade immediately to reduce their…
Introduction: Suno AI Training Data Leak — Why It Matters The Suno AI Training Data Leak has reignited concerns surrounding artificial intelligence, copyright law, and user data security. According to reports, a hacker who allegedly accessed Suno’s internal systems revealed source code suggesting the AI music company collected training data from several online platforms, including YouTube Music, Deezer, Genius, podcast RSS feeds, and stock music libraries. The Suno AI Training Data Leak also reportedly exposed customer information during a November 2025 supply chain attack. While Suno has acknowledged a limited security incident, the company disputes several allegations regarding the leaked…
Introduction: X Security Alert Phishing Scam — Why It Matters The X Security Alert Phishing Scam is targeting users with convincing fake security emails designed to steal account credentials. According to reports, cybercriminals are impersonating X by sending login alerts that claim an unknown device has accessed a user’s account. The emails urge recipients to click a link immediately to reset their password or review app access. However, instead of leading to the official X platform, the link redirects victims to a fake login page where attackers can capture usernames, passwords, and potentially one-time passwords (OTPs). According to The Guardian,…
Introduction: Apple Hide My Email Vulnerability — Why It Matters Apple has released a security update to address the Apple Hide My Email Vulnerability, a privacy issue that reportedly allowed attackers to reveal a user’s real email address from an anonymized Hide My Email alias. The flaw affected one of iCloud+’s most privacy-focused features and raised concerns about how effectively email aliases protected user identities. The issue was responsibly disclosed by security researcher Tyler Murphy in June 2025, but according to reports, the vulnerability remained unresolved for more than a year before Apple issued a fix on July 3, 2026.…