55Articles
7Categories
2025-05-08Date
🐛
SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root
🐛
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT
🐛
CVE-2025-33072 Microsoft msagsfeedback.azurewebsites.net Information Disclosure Vulnerability
🐛
CVE-2025-29972 Azure Storage Resource Provider Spoofing Vulnerability
🐛
CVE-2025-29827 Azure Automation Elevation of Privilege Vulnerability
🐛
CVE-2025-29813 Azure DevOps Elevation of Privilege Vulnerability
🐛
CVE-2025-47733 Microsoft Power Apps Information Disclosure Vulnerability
🐛
CVE-2025-47732 Microsoft Dataverse Remote Code Execution Vulnerability
🐛
Chromium: CVE-2025-4372 Use after free in WebAudio
🐛
CVE-2025-23123 (CVSS 10): Critical UniFi Protect Cameras Flaw Demands Immediate Updates
🐛
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT
⚠️
38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
⚠️
CISA Releases Five Industrial Control Systems Advisories
⚠️
Using AI to stop tech support scams in Chrome
⚠️
CISA warns of cyberattacks targeting the US oil and gas infrastructure
⚠️
CrowdStrike cuts 500 jobs in AI pivot, but flags risks
⚠️
How to capture forensic evidence for Microsoft 365
⚠️
India-Pakistan conflict underscores your C-suite’s need to prepare for war
⚠️
Six DDoS sites seized in multi-national law enforcement operation
⚠️
Play ransomware exploited Windows logging flaw in zero-day attacks
⚠️
OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws
📢
UK under assault as number of ‘significant’ cyberattacks doubles: Foreign powers, ransomware gangs, AI threats drive surge in incidents affecting private businesses and government systems
📢
CISA warns of hackers targeting critical oil infrastructure
📢
UK under assault as number of ‘significant’ cyberattacks doubles: Foreign powers, ransomware gangs, AI threats drive surge in incidents affecting private businesses and government systems
🔥
FBI: End-of-life routers hacked for cybercrime proxy networks
🔥
Education giant Pearson hit by cyberattack exposing customer data
🔥
Supply chain attack hits npm package with 45,000 weekly downloads
🔥
After the Breach: Finding new Partners with Solutions for Have I Been Pwned Users
🔥
Security Tools Alone Don't Protect You — Control Effectiveness Does
🔥
Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures
🔥
A timeline of South Korean telco giant SKT’s data breach
🔥
OnRPG - 1,047,640 breached accounts
🔥
LockBit ransomware gang hacked, victim negotiations exposed
🕵️
NICKEL TAPESTRY expands fraudulent worker operations
🕵️
Valarian Bags $20M Seed Capital for ‘Isolation-First’ Infrastructure Tech
🕵️
Europol Announces More DDoS Service Takedowns, Arrests
🕵️
Welcoming the Isle of Man Government to Have I Been Pwned
🕵️
MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware
🕵️
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware
🕵️
ISC Stormcast For Thursday, May 8th, 2025 https://isc.sans.edu/podcastdetail/9442, (Thu, May 8th)
🕵️
Phishing Kits Are Growing More Sophisticated; Focused on Bypassing MFA
🕵️
DHL-Masche: Betrüger plündern Konten von Zehntausenden Deutschen
🕵️
Palo Alto Networks: Champion in Two Canalys Global Leadership Matrices
🕵️
DOGE software engineer’s computer infected by info-stealing malware
🕵️
Operation PowerOFF Takes Down 9 DDoS Domains
🕵️
The many variants of the ClickFix social engineering tactic - Help Net Security
🕵️
OneDrive New Feature Allows Default Sync of Personal & Corporate Accounts
🕵️
The Top Threat Actor Groups Targeting the Financial Sector
🌐
Malicious PyPi package hides RAT malware, targets Discord devs since 2022
🌐
Smashing Security podcast #416: High street hacks, and Disney’s Wingdings woe
📡
Putting the dampener on tamperers
📡
Cisco fixes max severity IOS XE flaw letting attackers hijack devices
📡
No Internet Access? SSH to the Rescue!, (Thu, May 8th)
📡
PowerSchool paid a hacker’s ransom, but now schools say they are being extorted
📡
VC firm Insight Partners confirms personal data stolen during January hack