Two critical security flaws in n8n have exposed sandboxing vulnerabilities, enabling remote code execution for attackers
Flux RSS
— Sources secondairesResearchers discover that PureRAT’s code now contains emojis – indicating it has been written by AI based-on comments ripped from social media.
Zscaler analysts found critical vulnerabilities in 100% of enterprise AI systems, with 90% compromised in under 90 minutes
Sonatype warns that open source threats became industrialized with a surge in malicious packages in 2025
Chainalysis claims Chinese money launderers now account for 20% of global activity
Critical sandbox escape vulnerability in Grist-Core enables remote code execution via a malicious formula
PeckBirdy command-and-control framework targeting gambling, government sectors in Asia since 2023 has been linked to China-aligned APTs
Bugcrowd study reveals 82% of security researchers now use AI, a big increase from 2023 figures
Microsoft urged customers running Microsoft Office 2016 and 2019 to apply the patch to be protected
Nike is investigating after the World Leaks ransomware group posted a 1.4TB data dump
CISA released initial list of PQC-capable hardware and software to guide companies amid quantum threats
Fortra researchers have discovered a new SEO poisoning operation known as “HaxorSEO”
The US law firm Hagens Berman will lead a class action lawsuit against Coupang over security failures that led to a June 2025 data breach
Threat actors posing as IT support teams use phishing kits to generate fake login sites in real-time to trick victims into handing over credentials
A destructive cyber attack targeting Poland’s energy sector has been linked to Russian APT group Sandworm
Open letter by NHS technology leaders outlines plans to identify risks to software supply chain security across health and social care system
Under Armour said there is no evidence at this point to suggest the incident affected systems used to process payments or store customer passwords
Critical vulnerability in Appsmith allows account takeover via flawed password reset process
Security flaw in RealHomes CRM plugin allowed file uploads; patches released for 30,000+ sites
VulnCheck analysts found that vulnerabilities exploited before being publicly disclosed rose from 23.6% in 2024 to 28.96% in 2025