Wednesday , June 24 2026

Recent Posts

2025: Top cybersecurity and cyberattack stories

The cybersecurity landscape in 2025 saw an increase in the scale and sophistication of cyber threats. Nation-states, organized crime, and hybrid groups blurred the lines between espionage and financial crime, while supply chain weaknesses and social engineering became major attack methods. Massive data theft targeting cloud platforms like Salesforce exposed …

Read More »

80 internet-exposed MongoDB database instances found in Bangladesh

MongoDB

BGD e-GOV CIRT found 80 insecure MongoDB databases in Bangladesh exposed online, affected by the CVE-2025-14847 vulnerability (MongoBleed). This critical flaw allows remote attackers to access sensitive server data when zlib compression is enabled. MongoDB is often used to store personal, financial, and operational information. This exposure poses significant risks …

Read More »

RondoDox botnet uses React2Shell flaw to breach Next.js servers

RondoDox

The RondoDox botnet is using the serious React2Shell vulnerability (CVE-2025-55182) to infect unprotected Next.js servers with malware and cryptominers. RondoDox, a large-scale botnet first reported by Fortinet in July 2025, targets various n-day vulnerabilities in global attacks. In November, VulnCheck discovered new variants of RondoDox that exploit the critical remote …

Read More »