China’s CERT Issues Security Warning on OpenClaw AI Tool

China's cybersecurity agency has raised alarms about the OpenClaw AI tool, citing serious security vulnerabilities and potential risks to users.

China's cybersecurity agency has raised alarms about the OpenClaw AI tool, citing serious security vulnerabilities and potential risks to users.

A new multi-stage malware campaign, dubbed VOID#GEIST, has been identified, utilizing batch scripts to deliver various remote access trojans, including XWorm, AsyncRAT, and Xeno RAT.

Security researchers have identified a spyware campaign that disguises itself as an emergency alert application, targeting Israeli citizens through SMS messages.

Transport for London has revealed that a data breach in 2024 impacted more than 7 million customers, significantly more than the initially reported figure of 5,000.

An Iranian cyber group has infiltrated multiple US organizations, including a bank and an airport, utilizing a new backdoor named Dindoor. The ongoing situation raises concerns about potential data theft and future cyberattacks.

The emergence of AI agents in enterprises raises significant identity management challenges, with many organizations struggling to govern these non-human identities effectively.

Microsoft has issued a warning regarding ongoing OAuth abuse scams that exploit phishing tactics to deliver malware, particularly targeting government and public-sector organizations.

A popular Iranian prayer app, BadeSaba, has reportedly been hacked by Israel to disseminate propaganda messages amid ongoing conflict, raising concerns about cybersecurity and the implications for app developers.

The UK government has significantly improved its response to DNS vulnerabilities in the public sector through an automated monitoring system, reducing remediation times dramatically.

Despite a drop in ransomware payments, the number of attacks surged to unprecedented levels in 2025, according to Chainalysis' latest report.