From Detection to Patch: Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation

Oct 10, 2025Ravie LakshmananVulnerability / Network Security Fortra on Thursday revealed the results of its investigation into CVE-2025-10035, a critical security flaw in GoAnywhere Managed File Transfer (MFT) that’s assessed to have come under active exploitation since at least September 11, 2025. The company said it began its investigation on September 11 following a “potential […]

Continue Reading

Singapore police probe Nvidia customer Megaspeed over alleged China export violations

Singapore authorities are investigating artificial intelligence computing firm Megaspeed, a customer of American AI chipmaker Nvidia, for allegedly helping Chinese companies evade curbs on U.S. chip exports. “The Singapore Police Force confirms that investigations are ongoing into Megaspeed for suspected breaches of our domestic laws,” the police told CNBC in an email. The probe comes […]

Continue Reading

175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign

Oct 10, 2025Ravie LakshmananCybercrime / Malware Cybersecurity researchers have flagged a new set of 175 malicious packages on the npm registry that have been used to facilitate credential harvesting attacks as part of an unusual campaign. The packages have been collectively downloaded 26,000 times, acting as an infrastructure for a widespread phishing campaign codenamed Beamglea […]

Continue Reading

From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability

Oct 10, 2025Ravie LakshmananVulnerability / Zero-Day Cybersecurity company Huntress said it has observed active in-the-wild exploitation of an unpatched security flaw impacting Gladinet CentreStack and TrioFox products. The zero-day vulnerability, tracked as CVE-2025-11371 (CVSS score: 6.1), is an unauthenticated local file inclusion bug that allows unintended disclosure of system files. It impacts all versions of […]

Continue Reading

CL0P-Linked Hackers Breach Dozens of Organizations Through Oracle Software Flaw

Oct 10, 2025Ravie LakshmananVulnerability / Threat Intelligence Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle’s E-Business Suite (EBS) software since August 9, 2025, Google Threat Intelligence Group (GTIG) and Mandiant said in a new report released Thursday. “We’re still assessing the scope of this incident, but […]

Continue Reading

Instagram, Facebook Add Support for Meta AI-Powered Reels Translation in Hindi and Other Languages

Meta has expanded its Reels translation feature on Instagram and Facebook to include Hindi and Portuguese, in addition to the existing English and Spanish support. The AI-powered tool replicates the creator’s voice and offers a lip-sync option for natural-looking translations. Dubbed Reels carry a “Translated with Meta AI” label, and users can choose to enable […]

Continue Reading