A critical vulnerability in Microsoft SharePoint is under active attack, putting thousands of on-premise servers at risk. The flaw, tracked as CVE-2025-53770 and dubbed “ToolShell,” allows unauthenticated remote code execution and requires no user interaction. Microsoft confirmed the zero-day on 19 July. A day later, CISA followed suit, adding the bug to its Known Exploited Vulnerabilities catalog. SharePoint Online (used in Microsoft 365) is not affected. But all supported on-premise versions from SharePoint 2013 onward are in the blast radius. There is no patch yet. The attack is simple and effective. Threat actors send malicious serialized data to the server,…
Kirsten Doyle
Cybercriminals have found a new way to stay hidden in plain sight. They’re using artificial intelligence to cloak phishing sites, fake stores, and malware traps, shielding them from scanners while still reaching real victims. This was revealed by recent research from SlashNext. It’s not a trick, but a service. And it’s catching on fast. These platforms (part of a growing ecosystem known as cloaking-as-a-service or CaaS)use machine learning and behavioral profiling to show one version of a website to security systems and another to everyone else. To a crawler, the page looks clean. To a person, it’s a scam. A…
Cyber attacks are rising. Fast. In the second quarter of 2025, entities around the world faced an average of 1,984 cyber attacks each week. This was revealed by new research from Check Point. That’s a 21% increase from the same period last year, and 58% higher than two years ago. The upward trend is clear, but the regional and sector-specific data shows where the pressure is building most. Europe saw the sharpest rise, with attacks jumping 22% year over year. The region’s mix of geopolitical friction, regulatory fragmentation, and a high concentration of sensitive data is proving irresistible to bad…
A global police operation has dealt a heavy blow to the pro-Russian cybercrime network dubbed NoName057(16), which has been accused of launching disruptive digital attacks in support of Moscow’s war against Ukraine. Between 14 and 17 July, law enforcement agencies from across Europe and North America carried out coordinated raids and seizures under Operation Eastwood. The crackdown was led by Europol and Eurojust, and supported by a wide coalition of countries and cybersecurity experts. It dismantled a major portion of the group’s infrastructure, took servers offline, issued arrest warrants, and warned hundreds of suspected sympathisers. NoName057(16) is known for orchestrating…
A Shopify plugin meant to safeguard privacy did the opposite. For over 100 days, it quietly exposed hundreds of online stores to the kind of risk most businesses dread; data theft, full account takeover, and hijacked ad spend. Ironically, the culprit was a compliance plugin called Consentik, built to help Shopify merchants adhere to regulations like GDPR and CCPA. The flaw turned out to be an unsecured Kafka server that broadcast sensitive data in real-time. No password, no firewall, no warning. Researchers at Cybernews discovered the misconfigured server leaking: Shopify Personal Access Tokens Facebook Ad Tokens Real-time store analytics All…
A medical billing company tied to UnitedHealth has suffered one of the year’s largest healthcare breaches. More than 5.4 million people have been caught in the fallout. Episource, which handles claims and billing for doctors and hospitals, said a criminal gained access to its systems earlier this year. The breach lasted a week, ending on 6 February. In that time, the attacker was able to “see and take copies” of patient data. The information stolen includes names, phone numbers, addresses, emails. It also includes medical record numbers, test results, diagnoses, prescriptions, and other treatment data. Insurance plans and policy numbers…
A Chinese state-backed hacking group infiltrated a U.S. Army National Guard network and stayed there, undetected, for most of 2024. The group, known as Salt Typhoon, is believed to have operated inside the network of an unnamed U.S. state from March through December, according to a Department of Homeland Security memo. Their reach may have extended far beyond that single state. The threat actors exfiltrated sensitive data. Network traffic. Admin credentials. Diagrams. Even personally identifiable information and the geographic locations of National Guard personnel. According to the Pentagon’s findings, over and above mapping the compromised network, Salt Typhoon mapped its…
This year’s AI Appreciation Day shines a light on the rising power of artificial intelligence in every field. Cybersecurity experts come together to discuss what AI has achieved, and the hurdles it still faces. Cybersecurity experts share their views with Information Security Buzz: Traditional Access Controls Fall Short Rom Carmel, Co-founder and CEO at Apono, adds that unlike static on-prem environments, cloud infrastructure is distributed and dynamic, requiring real-time capabilities to manage access securely and efficiently. “As organizations scale and adopt multi-cloud architectures, traditional access controls often fall short, lacking the agility and context awareness needed to keep pace.” Carmel…
Threat actors have a new trick: hiding malicious JavaScript inside what looks like an innocent image, according to the Ontinue research team. A string of phishing campaigns is using SVG (Scalable Vector Graphics) files to smuggle browser redirects past traditional security tools. The result? Stealthy attacks, minimal user interaction, and victims who never see it coming. Images That Bite SVGs aren’t just pictures. They’re text-based XML files, which means attackers can slip JavaScript into them without raising alarms. In these campaigns, the SVG files include hidden scripts disguised within script tags, using a format that conceals the actual code content.…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a grave warning about a critical vulnerability affects railroad communication systems across the US. The flaw, designated as CVE-2025-1727, can potentially enable bad actors to control train brakes remotely (radio-proximity, not global internet). This vulnerability focuses on the End-of-Train and Head-of-Train protocols, collectively known as FRED. These systems link trains in movement. This vulnerability stems from insecure authentication within the protocol. Attackers can exploit this by using software-defined radio to spoof brake control packets. If exploited, the consequences could be dire. Unauthorized commands might cause sudden stops or brake failures. Such…
