Why the LG C5 OLED is still a favorite TV of mine, especially at $700 off

The LG C5 OLED combines breathtaking visuals with a clean, minimalist design for a truly immersive watch – and it’s currently discounted at multiple retailers.

Latest news – ​Read More

Need a new laptop for the office? Save $500 on the Dell 16 Plus and improve your workflow

The Dell 16 Plus is a solid work machine with a large 16-inch screen. All three processor options are on sale.

Latest news – ​Read More

Indian crypto exchange CoinDCX says $44 million stolen from reserves

The founders of Indian cryptocurrency exchange CoinDCX said no customer funds were affected in a more than $40 million theft from reserves.

The Record from Recorded Future News – ​Read More

I’m a wearables editor and here are the 7 Pixel Watch 4 rumors I’m most curious about

I’ve been keeping my eye on Pixel Watch 4 chatter ahead of Google’s Made by Google hardware event in August.

Latest news – ​Read More

New malware samples exfiltrate WhatsApp data to target Iran regime’s enemies

Researchers from the cybersecurity firm Lookout detected the latest version of DCHSpy one week after Israel’s June bombing campaign targeting Iran’s nuclear program began. DCHSpy was first detected in 2024, but has since evolved and can now exfiltrate data from WhatsApp and files stored on devices, Lookout said.

The Record from Recorded Future News – ​Read More

8 ways I quickly leveled-up my Linux skills – and you can too

Here’s how to improve your Linux skills and get more out of the OS. It’s not as hard to learn as you think.

Latest news – ​Read More

This multi-port car charger can power 4 gadgets at once – and it’s surprisingly cheap

The PrimeTrip VR2 Max is the coolest car charger I’ve ever tested. Here’s why.

Latest news – ​Read More

Microsoft Fix Targets Attacks on SharePoint Zero-Day

On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the Sharepoint flaw to breach U.S. federal and state agencies, universities, and energy companies.

Image: Shutterstock, by Ascannio.

In an advisory about the SharePoint security hole, a.k.a. CVE-2025-53770, Microsoft said it is aware of active attacks targeting on-premises SharePoint Server customers and exploiting vulnerabilities that were only partially addressed by the July 8, 2025 security update.

The Cybersecurity & Infrastructure Security Agency (CISA) concurred, saying CVE-2025-53770 is a variant on a flaw Microsoft patched earlier this month (CVE-2025-49706). Microsoft notes the weakness applies only to SharePoint Servers that organizations use in-house, and that SharePoint Online and Microsoft 365 are not affected.

The Washington Post reported on Sunday that the U.S. government and partners in Canada and Australia are investigating the hack of SharePoint servers, which provide a platform for sharing and managing documents. The Post reports at least two U.S. federal agencies have seen their servers breached via the SharePoint vulnerability.

According to CISA, attackers exploiting the newly-discovered flaw are retrofitting compromised servers with a backdoor dubbed “ToolShell” that provides unauthenticated, remote access to systems. CISA said ToolShell enables attackers to fully access SharePoint content — including file systems and internal configurations — and execute code over the network.

Researchers at Eye Security said they first spotted large-scale exploitation of the SharePoint flaw on July 18, 2025, and soon found dozens of separate servers compromised by the bug and infected with ToolShell. In a blog post, the researchers said the attacks sought to steal SharePoint server ASP.NET machine keys.

“These keys can be used to facilitate further attacks, even at a later date,” Eye Security warned. “It is critical that affected servers rotate SharePoint server ASP.NET machine keys and restart IIS on all SharePoint servers. Patching alone is not enough. We strongly advise defenders not to wait for a vendor fix before taking action. This threat is already operational and spreading rapidly.”

Microsoft’s advisory says the company has issued updates for SharePoint Server Subscription Edition and SharePoint Server 2019, but that it is still working on updates for supported versions of SharePoint 2019 and SharePoint 2016.

CISA advises vulnerable organizations to enable the anti-malware scan interface (AMSI) in SharePoint, to deploy Microsoft Defender AV on all SharePoint servers, and to disconnect affected products from the public-facing Internet until an official patch is available.

The security firm Rapid7 notes that Microsoft has described CVE-2025-53770 as related to a previous vulnerability — CVE-2025-49704, patched earlier this month — and that CVE-2025-49704 was part of an exploit chain demonstrated at the Pwn2Own hacking competition in May 2025. That exploit chain invoked a second SharePoint weakness — CVE-2025-49706 — which Microsoft unsuccessfully tried to fix in this month’s Patch Tuesday.

Microsoft also has issued a patch for a related SharePoint vulnerability — CVE-2025-53771; Microsoft says there are no signs of active attacks on CVE-2025-53771, and that the patch is to provide more robust protections than the update for CVE-2025-49706.

This is a rapidly developing story. Any updates will be noted with timestamps.

Krebs on Security – ​Read More

Why I highly recommend the M4 MacBook Air to most people (and now it’s on sale)

Apple’s M4 MacBook Air elevates the ultraportable game with boosted memory, improved external display support, and a surprisingly competitive price – especially at $150 off.

Latest news – ​Read More

This lightweight Linux distro makes switching from Windows 10 easy

Lubuntu is a fast, no-frills Linux distribution for the masses – and it’s perfect for reviving older hardware. Here’s why.

Latest news – ​Read More