Flodmonitor Blog

Latest insights in cybersecurity, vulnerabilities & threats

Curated by the Flodmonitor research team
November 07, 2025

U.S. Congressional Budget Office faces suspected cyberattack

The U.S. Congressional Budget Office is in hot water after a suspected foreign cyberattack breached its network. The CBO recently confirmed the incident, raising concerns about the potential exposu...

Read the full report
Ayoub Aouragh Oct 26, 2025 1 min read

New CoPhish attack targets OAuth tokens through Copilot Studio

A new phishing attack called CoPhish is making waves, and it’s pretty clever. Cybercriminals are using Microsoft Copilot Studio agents to send out fake OAuth consent requests, all while pretending ...

Explore insight
Ayoub Aouragh Oct 25, 2025 1 min read

WhatsApp hack attempt fails to disclose serious vulnerabilities

A planned $1 million hack on WhatsApp didn’t go as expected. The cybersecurity event, Pwn2Own, saw a participant pull out, only disclosing two low-impact vulnerabilities to Meta, WhatsApp's parent ...

Explore insight
Ayoub Aouragh Oct 25, 2025 1 min read

OpenAI Atlas Omnibox shows vulnerability to jailbreaks

Researchers have found a vulnerability in OpenAI's Atlas Omnibox that could allow sneaky prompts to be disguised as URLs. This means that users might unknowingly trigger commands that could manipul...

Explore insight
Ayoub Aouragh Oct 25, 2025 1 min read

Hackers exploit outdated WordPress plugins in mass attacks

Hackers are on the prowl, targeting WordPress sites with outdated plugins, specifically GutenKit and Hunk Companion. These plugins have some serious security flaws that are ripe for exploitation, a...

Explore insight
Oct 24, 2025 1 min read

Critical Lanscope bug exploited in ongoing cyberattacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) just flagged a serious flaw in Motex Lanscope Endpoint Manager that's been making waves in the cyber world. This vulnerability, know...

Explore insight
Oct 23, 2025 1 min read

Iran-linked MuddyWater targets over 100 organisations globally

You might want to pay attention to this latest cybersecurity scare. The Iranian hacking group MuddyWater has reportedly targeted over 100 organizations in a global espionage campaign. They’ve been ...

Explore insight
Oct 22, 2025 1 min read

PolarEdge targets Cisco, ASUS, QNAP, and Synology routers

Researchers are ringing alarm bells about a nasty botnet malware called PolarEdge, which is zeroing in on routers from big names like Cisco, ASUS, QNAP, and Synology. This malware, first spotted ba...

Explore insight
Oct 22, 2025 1 min read

Vidar Stealer 2.0 introduces multi-threaded data theft techniques

The notorious Vidar Stealer malware is back and better than ever with its new version 2.0, bringing some serious upgrades to the table. The creators of this malware-as-a-service have added multi-th...

Explore insight
Ayoub Aouragh Oct 20, 2025 1 min read

ConnectWise addresses critical vulnerability in Automate tool

ConnectWise has just patched a serious security flaw in its Automate remote monitoring and management tool. If you’re using this software, you’ll want to pay attention. The vulnerability allowed at...

Explore insight
Ayoub Aouragh Oct 20, 2025 1 min read

Vulnerability in Dolby decoder could enable zero-click attacks

A serious vulnerability has been discovered in the Dolby decoder that could allow hackers to launch zero-click attacks on Android devices. This flaw, identified as an out-of-bounds write issue, can...

Explore insight
Ayoub Aouragh Oct 20, 2025 1 min read

NSO ordered to stop hacking WhatsApp, damages reduced to $4 million

A judge has ordered NSO Group to stop hacking WhatsApp, but the damages they owe have taken a big hit. Initially, a jury slapped them with a whopping $167 million in punitive damages, but the judge...

Explore insight
Ayoub Aouragh Oct 20, 2025 1 min read

China accuses US of cyberattack on national time center

China's Ministry of State Security is pointing fingers at the U.S., claiming that the NSA launched a cyberattack on its National Time Center. They allege that American hackers took advantage of vul...

Explore insight