Surveillance Firm Bypasses SS7 Protections to Retrieve User Location

A surveillance company was caught using an SS7 bypass technique to trick wireless carriers into divulging users’ locations.

The post Surveillance Firm Bypasses SS7 Protections to Retrieve User Location appeared first on SecurityWeek.

SecurityWeek – ​Read More

Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers

Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.

The post Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers appeared first on SecurityWeek.

SecurityWeek – ​Read More

750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service

The Alcohol & Drug Testing Service (TADTS) says personal information was stolen in a July 2024 ransomware attack.

The post 750,000 Impacted by Data Breach at The Alcohol & Drug Testing Service appeared first on SecurityWeek.

SecurityWeek – ​Read More

Exploited CrushFTP Zero-Day Provides Admin Access to Servers

Hackers are exploiting a zero-day vulnerability in CrushFTP to gain administrative privileges on vulnerable servers via HTTPS.

The post Exploited CrushFTP Zero-Day Provides Admin Access to Servers appeared first on SecurityWeek.

SecurityWeek – ​Read More

PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse

Cybersecurity researchers have disclosed a novel attack technique that allows threat actors to bypass Fast IDentity Online (FIDO) key protections by deceiving users into approving authentication requests from spoofed company login portals.
The activity, observed by Expel as part of a phishing campaign in the wild, has been attributed to a threat actor named PoisonSeed, which was recently flagged

The Hacker News – ​Read More

I still prefer my Google Pixel 9 Pro over the expensive flagships – and it’s not even close

Google’s Pixel 9 Pro is still the Android I keep coming back to for its combination of price, features, and performance.

Latest news – ​Read More

Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access

Hewlett-Packard Enterprise (HPE) has released security updates to address a critical security flaw affecting Instant On Access Points that could allow an attacker to bypass authentication and gain administrative access to susceptible systems.
The vulnerability, tracked as CVE-2025-37103, carries a CVSS score of 9.8 out of a maximum of 10.0.
“Hard-coded login credentials were found in HPE

The Hacker News – ​Read More

3,500 Websites Hijacked to Secretly Mine Crypto Using Stealth JavaScript and WebSocket Tactics

A new attack campaign has compromised more than 3,500 websites worldwide with JavaScript cryptocurrency miners, marking the return of browser-based cryptojacking attacks once popularized by the likes of CoinHive. 
Although the service has since shuttered after browser makers took steps to ban miner-related apps and add-ons, researchers from the c/side said they found evidence of a stealthy

The Hacker News – ​Read More

Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks

Microsoft on Sunday released security patches for an actively exploited security flaw in SharePoint and also released details of another vulnerability that it said has been addressed with “more robust protections.”
The tech giant acknowledged it’s “aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security

The Hacker News – ​Read More