News
-
High-severity authentication bypass patched in Passwordstate credential manager, vendor says
Click Studios has released a patch for Passwordstate to fix a high-severity authentication bypass vulnerability that could allow attackers to access the emergency access page and the admin area. The vulnerability affects Passwordstate deployments used by thousands of customers and security professionals, with a CVE identifier not yet assigned. The company has published a forum…
-
Zero‑day FreePBX vulnerability exploited in the wild; active exploitation prompts urgent security advisories
Administrators of FreePBX are urged to upgrade and restrict access after a zero-day vulnerability (CVE-2025-57819) was actively exploited on public-facing systems, with a maximum CVSS score of 10.0 and multiple indicators of compromise identified.
-
FBI, Dutch police shut down VerifTools fake-ID marketplace; servers seized in Amsterdam
Intl. law-enforcement agencies halted VerifTools, a major fake-ID marketplace, seizing multiple Amsterdam servers and revealing a scheme that generated millions in illicit proceeds and undermined identity verification systems across borders.
-
MathWorks reports ransomware breach exposed data of 10,476 individuals
MathWorks disclosed that a ransomware group stole the data of 10,476 individuals after breaching its network in April, prompting outages affecting MFA, SSO, and other services. The company has not named the ransomware operator, and authorities note that a resolution or ransom payment, if any, remains undisclosed.
-
TransUnion breach affects 4.46 million; third-party app exposed personal data, not credit records
TransUnion disclosed a cyber incident affecting about 4.46 million individuals via a third-party application used by its US consumer-support operations. The breach did not touch core credit data, but exposed limited personal information, with victims offered two years of credit monitoring and fraud assistance.
-
Nx supply-chain attack: Malicious npm packages exfiltrate credentials and tokens
Security researchers say a supply-chain attack on the nx build system led to malicious nx npm packages that exfiltrated credentials and tokens. The breach was tied to a vulnerable PR workflow and elevated GitHub permissions, prompting widespread token rotation and intensified vendor-targeted remediation.
-
Sweden hit by cyberattack on municipal IT supplier Miljödata, disrupting services for more than 200 municipalities
A cyberattack on Miljödata disrupted access to municipal IT systems across more than 200 regions in Sweden, with reports of potential data leakage and a ransom demand tied to the incident.
-
Storm-0501 Debuts Brutal Hybrid Ransomware Attack Chain, Microsoft Warns
Microsoft Threat Intelligence warns Storm-0501 has deployed a brutal hybrid ransomware chain, exploiting hijacked privileged accounts to pivot between on‑prem and cloud, exfiltrate data, delete backups and encrypt remaining cloud resources, pressuring victims to pay or face potential shutdown.
-
Healthcare Services Group breach affects more than 624,000 individuals
Healthcare Services Group said a data breach exposed the personal information of more than 624,000 individuals, with unauthorized access occurring between Sept. 27 and Oct. 3, 2024 and notifications sent on Aug. 25, 2025. Data types varied but included identifiers and financial details; credit monitoring is being offered, and there is no current evidence of…










