IBM API Connect Flaw Enables Authentication Bypass
IBM has disclosed a critical security flaw in its API Connect platform that allows attackers to bypass authentication entirely. The vulnerability is tracked as CVE-2025-13915 and has been assigned a [...]
Magecart Attack Uses 50+ Scripts to Steal Payments
A newly uncovered Magecart operation shows how web-based attacks on online stores are becoming more advanced. Magecart Campaign Overview The attackers are running a wide campaign that relies on more [...]
CISA Warns: MongoDB (CVE-2025-14847) Flaw
CISA has flagged a serious security issue affecting MongoDB Server and confirmed that it is being actively abused by attackers. The flaw has now been added to CISA’s Known Exploited [...]
AI-Driven Phishing Kit Targets Microsoft Accounts
Since March 2025, attackers running a Spanish-language phishing campaign have been going after Microsoft Outlook accounts. The phishing tool they use appears advanced and likely built with help from AI. [...]
Windows Kernel and Named Pipe Flaws Enable Privilege Escalation
Windows privilege escalation remains a common technique used by attackers to gain deeper control of a system. By abusing weakly protected components such as kernel drivers and named pipes, a [...]