NASA Employees Tricked in Long Running Phishing Campaign Targeting Defense Software

Security investigators have uncovered a years long phishing campaign that successfully deceived employees at NASA and other U.S. organizations into sharing sensitive technology. The operation involved a Chinese national who posed as a trusted researcher and contacted targets through carefully crafted messages. By impersonating colleagues and collaborators, the attacker convinced victims they were participating in […]

Critical cPanel Authentication Flaw Exposes Servers to Unauthorized Access

Security researchers have revealed a serious vulnerability affecting cPanel that could allow attackers to bypass authentication and gain access to server control panels. The issue impacts multiple authentication paths and affects all supported versions of cPanel and WebHost Manager. Attackers can exploit this flaw to log in without valid credentials, potentially taking control of hosting […]

Your Private Files Weren’t Private: Inside the Fiverr Data Exposure That Shocked Users

A serious data exposure involving Fiverr has raised alarms after sensitive user files—including tax forms, contracts, IDs, and login credentials—were discovered publicly accessible through Google search results. The issue appears to stem from how files were stored and shared on the platform, rather than a traditional “hack,” but the consequences are just as concerning for […]

108 Chrome Extensions Turned Into A Data Heist

A massive and coordinated malware campaign has exposed just how dangerous seemingly harmless browser add-ons can be. Security researchers have identified 108 malicious Chrome extensions that were secretly stealing sensitive user data, hijacking sessions, and injecting harmful scripts, all while posing as useful everyday tools. At first glance, these extensions appeared legitimate. They advertised features […]