25 Sep, 2026

Mobile carrier Cellcom confirms cyberattack behind extended outages

Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. The incident disrupted voice and SMS services for customers across Wisconsin and Upper Michigan, leaving subscribers unable to make phone calls or send text messages. Today, after days […]

2 mins read

Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks

A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites. Developed by StylemixThemes, Motors is one of the top-selling automotive themes for the WordPress platform. It is very popular among automotive businesses such as car dealerships, rental […]

2 mins read

VanHelsing ransomware builder leaked on hacking forum

The VanHelsing ransomware-as-a-service operation published the source code for its affiliate panel, data leak blog, and Windows encryptor builder after an old developer tried to sell it on the RAMP cybercrime forum. VanHelsing is a RaaS operation launched in March 2025, promoting the ability to target Windows, Linux, BSD, ARM, and ESXi systems. Since then, the operation has shown […]

4 mins read

SK Telecom says malware breach lasted 3 years, impacted 27 million numbers

SK Telecom says that a recently disclosed cybersecurity incident in April, first occurred all the way back in 2022, ultimately exposing the USIM data of 27 million subscribers. SK Telecom is the largest mobile network operator in South Korea, holding roughly half of the national market. On April 19, 2025, the company detected malware on its networks and […]

2 mins read

Hazy Hawk gang exploits DNS misconfigs to hijack trusted domains

A threat actor tracked as ‘Hazy Hawk’ is hijacking forgotten DNS CNAME records pointing to abandoned cloud services, taking over trusted subdomains of governments, universities, and Fortune 500 companies to distribute scams, fake apps, and malicious ads. According to Infoblox researchers, Hazy Hawk first scans for domains with CNAME records pointing to abandoned cloud endpoints, which they determine […]

2 mins read

Trojanized RVTools push Bumblebee malware in SEO poisoning campaign

In response to our questions about the attack, Dell states that the malicious RVTools installer was not distributed from its sites but rather from fake typo-squatted domains. The company also states that the Dell-managed sites, Robware.net and RVTools.com, were taken offline as they are being targeted in DDoS attacks. “Dell Technologies operates two websites to distribute our RVTools […]

6 mins read

OpenAI plans to combine multiple models into GPT-5

OpenAI is planning to combine multiple products (features or models) into its next foundational model, which is called GPT-5. ChatGPT currently has too many capable models for different tasks. While the models are powerful, it can be confusing because all models have identical names. In a Reddit AMA thread, Jerry Tworek, who is a VP at […]

1 min read

Fake KeePass password manager leads to ESXi ransomware attack

Threat actors have been distributing trojanized versions of the KeePass password manager for at least eight months to install Cobalt Strike beacons, steal credentials, and ultimately, deploy ransomware on the breached network. WithSecure’s Threat Intelligence team discovered the campaign after they were brought in to investigate a ransomware attack. The researchers found that the attack […]

3 mins read

O2 UK patches bug leaking mobile user location from call metadata

A flaw in O2 UK’s implementation of VoLTE and WiFi Calling technologies could allow anyone to expose the general location of a person and other identifiers by calling the target. The problem was discovered by security researcher Daniel Williams. The flaw likely existed on O2 UK’s network since February 2023, and was resolved yesterday. O2 UK is […]

3 mins read

Windows 10 emergency updates fix BitLocker recovery issues

Microsoft has released out-of-band updates to fix a known issue causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates. To fix systems stuck at a BitLocker recovery prompt, install today’s KB5061768 emergency update, available exclusively through the Microsoft Update Catalog. This is also a cumulative update, meaning you won’t have […]

2 mins read