Pwn2Own Automotive 2026 concluded with security researchers earning $1,047,000 for exploiting 76 zero-day vulnerabilities from January 21 to January 23. The Pwn2Own Automotive hacking competition focused on car technologies and occurred this week in Tokyo, Japan, during the Automotive World conference. Hackers focused on fully updated in-vehicle infotainment systems, electric …
Read More »Fake PNB MetLife Payment Gateway Stealing Customer Details:Direct to UPI Payments
Hackers are targeting PNB MetLife insurance customers by using fake payment gateways to steal personal information and redirect victims to fraudulent UPI transactions. The scam takes advantage of PNB MetLife’s trusted image by creating fake mobile payment sites that look like real premium payment services. Malicious pages collect policy numbers …
Read More »Fortinet admins report patched FortiGate firewalls getting hacked
Fortinet customers are observing attackers exploiting a patch bypass for a previously fixed critical FortiGate authentication vulnerability (CVE-2025-59718) to hack patched firewalls. One affected admins said that Fortinet has allegedly confirmed that the latest FortiOS version (7.4.10) didn’t fully address this authentication bypass vulnerability, which should’ve been patched in early …
Read More »AI-Powered Ransomware: Attacks Up by 60%: Check Point
Check Point data reveals a 60% increase in ransomware attacks, with North America and Europe being the primary targets. The rise in enterprise Gen AI use has also exposed sensitive data. In 2025, ransomware attacks stood out for their volume, scale, and damage. The December 2025 Global Cyber Attack Statistics …
Read More »Hackers to exploit critical Fortinet FortiSIEM flaw in attacks
A critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code is now being abused in attacks. Security researcher Zach Hanley from Horizon3.ai reported vulnerability CVE-2025-64155, which combines two issues that enable arbitrary writes with admin permissions and privilege escalation to root access. “An improper neutralization of special elements used …
Read More »CastleLoader Malware To Attack US Government Agencies and Critical Infra
A dangerous malware loader dubbed CastleLoader poses a serious risk to US government agencies and critical infrastructure. First detected in early 2025, it has been used to gain initial access in coordinated attacks on federal agencies, IT firms, logistics companies, and essential infrastructure in North America and Europe. Security researchers …
Read More »Instagram data leak reveals sensitive info of 17.5M accounts
A major security breach has affected about 17.5 million Instagram accounts, revealing private information now found on the dark web. The recent incident reported by Malwarebytes has raised severe concerns about user privacy and account security. The breach involves significant personal information that poses risks to users. Affected data includes …
Read More »Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
Hackers reportedly used a compromised SonicWall VPN appliance to gain access and deploy a VMware ESXi exploit, possibly created as early as February 2024. Huntress, a cybersecurity firm, detected activity in December 2025 and halted it before it escalated into a ransomware attack. The attack likely took advantage of three …
Read More »BlueDelta Target Sophos VPN, Google, Microsoft OWA to Steal Credentials
BlueDelta conducted a complex credential-harvesting operation targeting critical infrastructure and research institutions in 2025, as revealed by an investigation from Recorded Future’s Insikt Group. The campaigns leveraged legitimate PDF documents as bait, including publications from the Gulf Research Center titled “Strategic and Political Implications for Israel and Iran: The Day …
Read More »BTRC NEIR face 2.4 million bot traffic in a minute
BTRC’s National equipment identity register (NEIR) Citizen Portal is under attack by 2.4 million bot traffic in a minute. The attackers have been carrying out this attack intermittently since Friday morning. Aminul Bari Shuvro, Chief Solution Officer of Synesis IT (responsible for NEIR) said that forty thousand bot traffic hit …
Read More »
InfoSecBulletin Cybersecurity for mankind