A severe zero-day vulnerability has been found in the widely used Eventin WordPress plugin (Themewinter), which puts over 10,000 websites at extreme risk for complete takeover. CVE-2025-47539 is the identifier for the flaw, which permits unauthenticated privilege escalation, allowing users to create user accounts at the Administrator level without having…
About the Incidence What began as a handful of phishing attacks by early 2025 became a large, organised attack aimed at the fisheries, telecommunications, and insurance sectors in Kuwait. Security Researchers at Hunt.io have found evidence of a large phishing campaign that used over 230 different malicious websites to try…
Cybersecurity experts are concerned about a high-impact vulnerability in Fortinet’s FortiOS, FortiProxy, and FortiSwitchManager, designated as CVE-2025-22252. The vulnerability could allow the attacker to circumvent authentication and gain privileges as an administrator on enterprise networks that deploy Fortinet security appliances. What is CVE-2025-22252? CVE-2025-22252 is an authentication for critical function…
An Incidence The hunter becomes the hunted. LockBit, once the most dominant ransomware-as-a-service (RaaS) syndicate on the dark web, has been shattered from within. In a dramatic twist, the criminal enterprise infamous for extorting hundreds of millions from global victims has now suffered a severe breach of its infrastructure, exposing…
Introduction Cyber attacks are now a common thing in the modern world and are responsible for causing extensive harm to the various parties involved. Considering cyber threats, such as cyber attacks, data leaks, ransomware, and others, including Distributed Denial of Service (DDoS) attacks, the outcome is quite severe, resulting in…
When a website has been hacked, it is a serious matter for any business. Websites can be hacked for a number of reasons—data breaches, financial consequences, reputational damage, or worse. Hackers exploit a vulnerability to install malware, compromise their website, retrieve their customers’ sensitive data, or redirect a visitor to…
What is HTTP Public Key Pinning? HTTP Public Key Pinning (HPKP) is a security feature built to protect websites from man-in-the-middle (MITM) attacks of a mis issued certificate. HPKP enables administrators to specify which cryptographic public keys are trusted for a particular domain. Also, HPKP prevents browsers from accepting certificates…
What Is SSL Inspection? SSL inspection is the term commonly used to refer to SSL/TLS decryption or SSL visibility, whereby encrypted SSL/TLS traffic is intercepted by a security appliance or software to be decrypted for further scrutiny. It allows organizations to inspect, filter, and intercept the encrypted traffic passing through…
In this tech-dependent age most of the important and sensitive data are stored and are available online. So, it is compulsory that these data must have a reliable security. And here comes in picture the SSL Encryption. What is SSL Encryption? SSL (Secure Sockets Layer) encryption operates as a security…
What is Public CA? A Public Certificate Authority (Public CA) is a trusted third-party organization that provides digital certificates to verify the identity of entities on the Internet. A digital certificate is also commonly referred to as an SSL/TLS certificate. Public CAs issue certificates to clients and servers to create…
Recently, a sophisticated phishing campaign targeted WooCommerce store owners by falsely reporting critical vulnerabilities, then tricking victims into installing malware – disguised as an essential security patch.. Security researchers and WooCommerce’s team have issued alerts to help make store owners aware and keep themselves safe. We summarize everything you need…
A critical vulnerability in the SSL.com domain validation process allowed unauthorized parties to get the certificates on behalf of you or your organisation. SSL.com is one of the famous Certificate Authorities (CA) trusted by all major browsers. This Vulnerability is reported by security researchers; in their demonstration, they showed how…
If you’ve ever browsed the internet, you’ve utilized Port 80, even if you didn’t know it. Port 80 is an underlying infrastructure that brings searches to your screen and most of the web traffic we rely upon daily depends on this Port. Everything that pops up on the World Wide…
What is a PKI Certificate? PKI Certificate, also known as a digital certificate, is an electronic document used for the purpose of verifying the possession of a certain public key in a particular security system. It also plays an important role in authenticating safe communication as well as transactions using…
About the Incidence Cybercriminals are using a new technique to run their phishing campaigns. This advanced phishing attack bypasses Gmail’s security filters. The phishing email seems to be genuine because the form address in the email is “
[email protected]” and it’s a valid signed email. The attack was discovered by “Nick…