Hatty AI

DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked

DeepSeek is a Chinese artificial intelligence startup that has seen a meteoric increase in popularity over the past few days. However, one of its databases was left exposed on the Internet, which could have given malicious actors access to sensitive information. Wiz security researcher Gal says that the ClickHouse database allows “full control over database […]

DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked Read More »

Lightning AI Studio Vulnerability could’ve allowed RCE via hidden URL Parameter

Researchers in cybersecurity have revealed a critical flaw that could have led to remote code execution if exploited. Noma, an application security firm, said that the vulnerability, which has a CVSS rating of 9.4, allows “attackers to potentially run arbitrary commands as root” by exploiting a URL parameter hidden in the URL.

Lightning AI Studio Vulnerability could’ve allowed RCE via hidden URL Parameter Read More »

Authorities seize domains of popular hacking forums in Major Cybercrime crackdown

A law enforcement operation conducted internationally has dismantled domains linked to various online platforms that are linked to cybercrime, such as Cracked Nulled Sellix and StarkRDP. The effort, which took between January 28 and 30 2025, focused on the following domains: www.cracked.io www.nulled.to www.mysellix.io www.sellix.io www.starkrdp.io These websites now greet visitors with a

Authorities seize domains of popular hacking forums in Major Cybercrime crackdown Read More »

Broadcom patches VMware Aria flaws – Exploits may lead to credential theft

Broadcom has released five security updates that address vulnerabilities in VMware Aria Operations, Aria Operations for Logs and Aria Operations. Customers are warned that attackers may exploit these flaws to gain elevated access to the system or obtain sensitive data. Below is a list of known flaws that affect versions 8.x and earlier of the

Broadcom patches VMware Aria flaws – Exploits may lead to credential theft Read More »

Google bans 158,000 malicious Android app developer accounts in 2024

Google has announced that it will block over 2.36 millions Android apps that violate its policies from being published on the Google Play app store in 2024. It also banned more than 158,000 bad developers accounts who attempted to publish these harmful apps. The tech giant noted that it also prevented 1.3 millions apps from

Google bans 158,000 malicious Android app developer accounts in 2024 Read More »

Malicious Go package exploits module mirror caching for persistent remote access

Cybersecurity researchers have drawn attention to an attack on the software supply chain that targets the Go ecosystem. The malicious package can grant the adversary remote control of infected systems. The package, named github.com/boltdb-go/bolt, is a typosquat of the legitimate BoltDB database module (github.com/boltdb/bolt), per Socket. The malicious version (1.3.1) has been published to

Malicious Go package exploits module mirror caching for persistent remote access Read More »

Microsoft SharePoint Connector flaw could have enabled credential theft across Power Platform

Cybersecurity researchers have revealed details of a vulnerability that has been patched in the Microsoft SharePoint connector for Power Platform. If exploited successfully, it could allow threat actors access to a user’s credentials, and then launch further attacks. This could manifest as post-exploitation actions, which allow the attackers to send requests to SharePoint API on

Microsoft SharePoint Connector flaw could have enabled credential theft across Power Platform Read More »

Scroll to Top