Latest Cybersecurity News and Articles


GPUHammer: New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs

12 July 2025
NVIDIA is urging customers to enable System-level Error Correction Codes (ECC) as a defense against a variant of a RowHammer attack demonstrated against its graphics processing units (GPUs). "Risk of successful exploitation from RowHammer attacks varies based on DRAM device, platform, design specification, and system settings," the GPU maker said in an advisory released this week. Dubbed

Grok-4 Falls to a Jailbreak Two days After Its Release

12 July 2025
The latest release of the xAI LLM, Grok-4, has already fallen to a sophisticated jailbreak. The post Grok-4 Falls to a Jailbreak Two days After Its Release appeared first on SecurityWeek.

Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHub

12 July 2025
Cybersecurity researchers have discovered a serious security issue that allows leaked Laravel APP_KEYs to be weaponized to gain remote code execution capabilities on hundreds of applications. "Laravel's APP_KEY, essential for encrypting sensitive data, is often leaked publicly (e.g., on GitHub)," GitGuardian said. "If attackers get access to this key, they can exploit a deserialization flaw to

Sudo Vulnerability Discovered, May Exposes Linux Systems

11 July 2025
Sudo, the privileged command-line tool often installed on Linux systems, has two local privilege vulnerabilities. 

‘Hacking is assumed now’: experts raise the alarm about added risk of surveillance cameras in childcare centres

11 July 2025
‘Hacking is assumed now’: experts raise the alarm about added risk of surveillance cameras in childcare centres As governments consider mandatory CCTV in early education, one big provider with cameras already installed is yet to formalise guidelines for how the footage will be stored and usedGet our breaking news email, free app or daily news podcastIn the wake of horrifying reports last week alleging that eight children had been sexually abused by a worker in a Melbourne childcare centre, politicians and providers have scrambled to offer a response.One option emerged from the fray as something concrete and immediate: the installation of CCTV cameras in childcare centres.Sign up for Guardian Australia’s breaking news email Continue reading...

Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)

11 July 2025
Fortinet has released fixes for a critical security flaw impacting FortiWeb that could enable an unauthenticated attacker to run arbitrary database commands on susceptible instances. Tracked as CVE-2025-25257, the vulnerability carries a CVSS score of 9.6 out of a maximum of 10.0. "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in

Louis Vuitton says UK customer data stolen in cyber-attack

11 July 2025
Louis Vuitton says UK customer data stolen in cyber-attack Lead brand of French luxury group LVMH reassures customers financial data such as bank details were not takenLouis Vuitton has said the data of some UK customers has been stolen as it became the latest retailer targeted by cyber hackers.The retailer, the leading brand of the French luxury group LVMH, said an unauthorised third party had accessed its UK operation’s systems and obtained information such as names, contact details and purchase history. Continue reading...

Increase in Identity-Based Attacks Attributed to Infostealers

11 July 2025
Info-stealing malware and advanced phishing kits account for 156% increase in cyberattacks that target user logins.

In Other News: Microsoft Finds AMD CPU Flaws, ZuRu macOS Malware Evolves, DoNot APT Targets Govs

11 July 2025
Noteworthy stories that might have slipped under the radar: Microsoft shows attack against AMD processors, SentinelOne details latest ZuRu macOS malware version, Indian APT DoNot targets governments.  The post In Other News: Microsoft Finds AMD CPU Flaws, ZuRu macOS Malware Evolves, DoNot APT Targets Govs appeared first on SecurityWeek.

PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution

11 July 2025
Cybersecurity researchers have discovered a set of four security flaws in OpenSynergy's BlueSDK Bluetooth stack that, if successfully exploited, could allow remote code execution on millions of transport vehicles from different vendors. The vulnerabilities, dubbed PerfektBlue, can be fashioned together as an exploit chain to run arbitrary code on cars from at least three major automakers,

Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent

11 July 2025
With IPOs taking longer than ever, the venture firm’s fund aims to keep startup veterans motivated while staying private. The post Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent appeared first on SecurityWeek.

Securing Data in the AI Era

11 July 2025
The 2025 Data Risk Report: Enterprises face potentially serious data loss risks from AI-fueled tools. Adopting a unified, AI-driven approach to data security can help. As businesses increasingly rely on cloud-driven platforms and AI-powered tools to accelerate digital transformation, the stakes for safeguarding sensitive enterprise data have reached unprecedented levels. The Zscaler ThreatLabz

Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild

11 July 2025
A recently disclosed maximum-severity security flaw impacting the Wing FTP Server has come under active exploitation in the wild, according to Huntress. The vulnerability, tracked as CVE-2025-47812 (CVSS score: 10.0), is a case of improper handling of null ('\0') bytes in the server's web interface, which allows for remote code execution. It has been addressed in version 7.4.4. "The user and

Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals

11 July 2025
An Iranian-backed ransomware-as-a-service (RaaS) named Pay2Key has resurfaced in the wake of the Israel-Iran-U.S. conflict last month, offering bigger payouts to cybercriminals who launch attacks against Israel and the U.S. The financially motivated scheme, now operating under the moniker Pay2Key.I2P, is assessed to be linked to a hacking group tracked as Fox Kitten (aka Lemon Sandstorm). "

EU Unveils AI Code of Practice to Help Businesses Comply With Bloc’s Rules

11 July 2025
The EU code is voluntary and complements the EU’s AI Act, a comprehensive set of regulations that was approved last year and is taking effect in phases. The post EU Unveils AI Code of Practice to Help Businesses Comply With Bloc’s Rules appeared first on SecurityWeek.

McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications

11 July 2025
Two vulnerabilities in an internal API allowed unauthorized access to contacts and chats, exposing the information of 64 million McDonald’s applicants. The post McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications appeared first on SecurityWeek.

Critical Wing FTP Server Vulnerability Exploited

11 July 2025
Wing FTP Server vulnerability CVE-2025-47812 can be exploited for arbitrary command execution with root or system privileges. The post Critical Wing FTP Server Vulnerability Exploited appeared first on SecurityWeek.

TikTok Faces Fresh European Privacy Investigation Over China Data Transfers

11 July 2025
The Irish Data Privacy Commission announced that TikTok is facing a new European Union privacy investigation into user data sent to China. The post TikTok Faces Fresh European Privacy Investigation Over China Data Transfers appeared first on SecurityWeek.

July 2025 Breaks a Decade of Monthly Android Patches

11 July 2025
Since August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025. The post July 2025 Breaks a Decade of Monthly Android Patches appeared first on SecurityWeek.

Rowhammer Attack Demonstrated Against Nvidia GPU

11 July 2025
Researchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models. The post Rowhammer Attack Demonstrated Against Nvidia GPU appeared first on SecurityWeek.