ErrTraffic Tool Automates ClickFix Cyber Attacks
Cybercrime activity is increasingly shaped by automation and repeatable services. Researchers at Hudson Rock have identified ErrTraffic v2, a platform designed to operationalize ClickFix attacks at scale by packaging social-engineering [...]
GlassWorm malware uses malicious VS Code extensions to attack macOS systems
GlassWorm has returned with a dangerous new evolution, shifting its focus entirely to macOS. First discovered in October, the malware originally spread through malicious VS Code extensions that used invisible [...]
IBM API Connect Flaw Enables Authentication Bypass
IBM has disclosed a critical security flaw in its API Connect platform that allows attackers to bypass authentication entirely. The vulnerability is tracked as CVE-2025-13915 and has been assigned a [...]
Magecart Attack Uses 50+ Scripts to Steal Payments
A newly uncovered Magecart operation shows how web-based attacks on online stores are becoming more advanced. Magecart Campaign Overview The attackers are running a wide campaign that relies on more [...]
CISA Warns: MongoDB (CVE-2025-14847) Flaw
CISA has flagged a serious security issue affecting MongoDB Server and confirmed that it is being actively abused by attackers. The flaw has now been added to CISA’s Known Exploited [...]