A critical SQL injection vulnerability (CVE-2025-4039) has been identified in PHPGurukul’s Rail Pass Management System version 1.0,...
Exploit
The abrupt shutdown of BreachForums, a major cybercrime marketplace, on April 15, 2025, has left the cybersecurity...
The Oregon Department of Environmental Quality (DEQ) has refused to confirm whether employee data was exfiltrated during...
The latest Metasploit Framework update introduces significant improvements for Active Directory Certificate Services (AD CS) exploitation, particularly...
In August 2024, cybercriminals executed one of the largest single-victim cryptocurrency thefts in history, stealing $243 million...
A stored cross-site scripting (XSS) vulnerability has been identified in Garage Management System 1.0, specifically affecting the...
A critical unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in ABB Cylon Aspect firmware version 4.00.00,...
KiviCare Clinic & Patient Management System (EHR) 3.6.4 SQL Injection Vulnerability (CVE-2024-11728)

KiviCare Clinic & Patient Management System (EHR) 3.6.4 SQL Injection Vulnerability (CVE-2024-11728)
A critical unauthenticated SQL injection vulnerability (CVE-2024-11728) has been identified in KiviCare Clinic & Patient Management System...
A critical supply chain attack has compromised Ripple’s official xrpl.js NPM package, injecting malicious code designed to...
A recently disclosed vulnerability in the code-projects Online Exam Mastering System 1.0 exposes users to reflected Cross-Site...
Baltimore Public Schools Ransomware Attack: Technical Breakdown of Black Basta’s VMware ESXi Exploit

Baltimore Public Schools Ransomware Attack: Technical Breakdown of Black Basta’s VMware ESXi Exploit
In February 2024, Baltimore City Public Schools suffered a significant ransomware attack compromising over 25,000 records of...
South Korea’s largest mobile operator, SK Telecom, has confirmed a malware attack compromising sensitive USIM-related customer data,...
A newly documented proof-of-concept attack named “Cookie-Bite” demonstrates how malicious Chrome extensions can hijack browser session cookies...
A high-severity vulnerability (CVE-2025-2594) has been identified in the WordPress User Registration & Membership plugin, allowing unauthenticated...
A critical buffer overflow vulnerability (CVE-2025-3786) has been identified in Tenda AC15 routers, affecting firmware versions up...
A recently patched vulnerability in Verizon’s Call Filter iOS app allowed unauthorized access to call metadata for...
The FBI has issued an urgent advisory warning Gmail and Outlook users about a surge in Medusa...
A recent breach at Oracle Health has exposed sensitive patient data across multiple US hospitals, raising concerns...
Sam’s Club, the Walmart-owned retail warehouse chain, is currently investigating claims of a data breach linked to...
MailChimp, a widely used email marketing platform, has become a prime target for cybercriminals employing sophisticated phishing...