Google has issued emergency updates to patch a critical Chrome zero-day vulnerability (CVE-2025-6554) that is actively being exploited by attackers. This flaw, located in the V8 JavaScript engine, allows remote code execution simply by luring victims to maliciously crafted websites. Security researchers emphasize the urgency of updating all Chrome installations immediately, as this is the fourth such exploit patched by Google in 2025.
Source: Help Net Security
Millions Impacted as Qantas Admits to Massive Customer Data Breach
Australian airline Qantas has disclosed a cyberattack that compromised the personal data of up to six million customers. The breach, linked to unauthorized access of a third-party contact center platform, included sensitive information such as service records, fueling concerns about potential identity theft and phishing attacks.
Source: SecurityWeek
International Criminal Court Hit by Sophisticated Targeted Cyberattack
The International Criminal Court (ICC) reported that it was targeted by a “sophisticated and targeted” cyberattack amid the recent NATO summit. The ICC credited its monitoring and mitigation systems for discovering and containing the breach swiftly, but has not yet revealed details on the scope of the intrusion or the data compromised, raising concerns about the targeting of global legal institutions.
Source: RecordedFuture
US Launches Sweeping Crackdown on North Korean IT Worker Scams
The U.S. Department of Justice has disrupted extensive North Korean remote IT worker schemes operating across at least 16 states. The crackdown included arrests, asset seizures, and searches of so-called “laptop farms” used by operatives suspected of stealing corporate secrets and salaries to fund the Pyongyang regime.
Source: Bleeping Computer
Cloudflare Blocks Unauthorized AI Crawlers by Default, Lets Sites Control Content Access
In a move set to transform how AI developers access web content, Cloudflare now blocks AI crawlers by default unless they receive explicit permission or compensation from site owners. This policy aims to protect copyright holders and ensure that publishers can monitor or monetize their data, as scraping for AI model training continues to surge.
Source: Help Net Security
Critical Citrix NetScaler Flaws Leave Thousands of Servers Exposed Globally
More than 1,200 Citrix NetScaler ADC and Gateway servers remain vulnerable to actively exploited bugs (“Citrix Bleed 2” CVE-2025-5777 and CVE-2025-6543), despite the release of security fixes. Researchers warn that thousands of systems continue to be targeted, underscoring the urgent need for patching to prevent remote attacks and data breaches.
Source: SecurityWeek
US Sanctions Russian Bulletproof Hosting Service for Aiding Ransomware Operations
The U.S. Treasury has sanctioned Russia-based Aeza Group and its subsidiaries for providing bulletproof hosting services to ransomware, infostealer, and illicit darknet operations. These sanctions mark an escalation in efforts to disrupt cybercriminal infrastructure that enables global ransomware campaigns and other cybercrime activity.
Source: Bleeping Computer
You May Also Be Interested In...