Microsoft has warned users about the ease with which hackers can spread malware through its Outlook email client. The tech giant has released a patch for the CVE-2025-21298 vulnerability, which it rated as 9.8 (critical) in severity. Microsoft advises users to view emails in plain text and turn off or restrict NTLM traffic if they are unable to apply the patch immediately. The vulnerability lies in the Windows Object Linking and Embedding function and could potentially lead to remote code execution.

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate

