48Articles
9Categories
2025-04-17Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2025-31200  Apple Multiple Products Memory Corruption Vulnerability CVE-2025-31201  Apple Multiple Products Arbitrary Read and W…
KEV
🚨
Update these two servers from Gladinet immediately, CISOs toldCISOs running Gladinet’s CentreStack file server or Triofox file sharing server should update the applications as soon as possible because of a hard-coded key vulnerability which is being exploited now, say researchers at Huntress. “Immediate action is essential.” John Hammond, p…
KEV
🐛
Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now
🐛
Critical Erlang/OTP SSH Flaw Exposes Many Devices to Remote Hacking
🐛
Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution
🐛
CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices
KEV
🐛
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks
KEV
🐛
CVE-2025-27747 Microsoft Word Remote Code Execution Vulnerability
🐛
CVE-2025-27729 Windows Shell Remote Code Execution Vulnerability
🐛
Chromium: CVE-2025-3620 Use after free in USB
🐛
Chromium: CVE-2025-3619 Heap buffer overflow in Codecs
🐛
CVE-Finanzierung weiterhin gesichert
🐛
Hackers target Apple users in an ‘extremely sophisticated attack’
KEV
🐛
MITRE funding still in up in the air, say experts
⚠️
Man Helped Individuals in China Get Jobs Involving Sensitive US Government Projects
⚠️
Vulnerabilities Patched in Atlassian, Cisco Products
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
The Continued Abuse of Legitimate Domains: A Spike in the Exploitation of Google Drive to Send Phishing Attacks
⚠️
Neue ResolverRAT-Malware zielt auf Gesundheitsbranche
⚠️
CISOs no closer to containing shadow AI’s skyrocketing data risks
⚠️
Russia-linked APT29 targets European diplomats with new malware
⚠️
Insecure Code vs. the Entire RGB Industry | WinRing 0 Driver, ft. Wendell of Level1 Techs
⚠️
Multiple Groups Exploit NTLM Flaw in Microsoft Windows
⚠️
CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices
KEV
📢
CISA warns of potential data breaches caused by legacy Oracle Cloud leak
🔥
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates
🔥
Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers
🔥
Lack of Security Awareness Tops List of Obstacles to Cyber Defense
🔥
Mit der Firmenübernahme steigt das Angriffsrisiko
🔥
Over 16,000 Fortinet devices compromised with symlink backdoor
🔥
Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial
🔥
Huge ransomware campaign targets AWS S3 storage: attackers have thousands of keys
🕵️
Age Verification Using Facial Scans
🕵️
Demystifying Security Posture Management
🕵️
State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns
🕵️
ISC Stormcast For Thursday, April 17th, 2025 https://isc.sans.edu/podcastdetail/9412, (Thu, Apr 17th)
🕵️
RedTail, Remnux and Malware Management [Guest Diary], (Wed, Apr 16th)
🕵️
Microsoft’s Secure by Design journey: One year of success
🕵️
[Scary] A New Real Cash Scam Sweeps Across the U.S. Warn Your Family and Friends!
🕵️
CrazyHunter Campaign Targets Taiwanese Critical Sectors
🕵️
New macOS Spyware PasivRobber Linked to Chinese State Actors
🕵️
Chinese Hacker Group Mustang Panda Bypass EDR Detection With New Hacking Tools
🕵️
Snake Oilers: Pangea, Cosive and Sysdig
🌐
Florida draft law mandating encryption backdoors for social media accounts billed ‘dangerous and dumb’
🎙️
Moving CVEs past one-nation control
📡
Artificial Intelligence – What's all the fuss?
📡
Blockchain Offers Security Benefits – But Don't Neglect Your Passwords
📡
CapCut copycats are on the prowl