113Articles
8Categories
2025-05-21Date
🐛
Critical VMware ESXi & vCenter Flaw Allows Remote Execution of Arbitrary Commands
🐛
Critical Vulnerability in Palo Alto GlobalProtect Gateway & Portal Enables Remote Code Execution
🐛
Critical OpenPGP.js Vulnerability Allows Spoofing
🐛
Ivanti EPMM 0-Day RCE Vulnerability Under Active Attack
🐛
PowerDNS Vulnerability Allows Attackers to Trigger DoS Attacks Through Malicious TCP Connections
🐛
Critical flaw in OpenPGP.js raises alarms for encrypted email services
🐛
Vulnerabilities impacting SAP NetWeaver (CVE-2025-31324 and CVE-2025-42999)
🐛
Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway
🐛
BadSuccessor: Unpatched Microsoft Active Directory attack enables domain takeover
⚠️
Poor DNS hygiene is leading to domain hijacking: Report
⚠️
Software Bill of Material umsetzen: Die besten SBOM-Tools
⚠️
Threat intelligence platform buyer’s guide: Top vendors, selection advice
⚠️
Hazy Hawk Targets DNS Vulnerabilities to Hijack Cloud Resources and Spread Malware
⚠️
Attaxion Leads the Way as First EASM Platform to Integrate ENISA’s EU Vulnerability Database (EUVD)
⚠️
Ransomware Attack Forces Kettering Health to Cancel Procedures
⚠️
Kettering Health Experiences System-Wide Outage Due to Ransomware Attack
⚠️
Critical Vulnerability in Lexmark Printers Enables Remote Code Execution
⚠️
Cybercriminals Could Leverage Google Cloud Platform for Malicious Activities
⚠️
Malicious Hackers Create Fake AI Tool to Exploit Millions of Users
⚠️
Atlassian Alerts Users to Multiple Critical Vulnerabilities Affecting Data Center Server
⚠️
CISO Cheat Sheet, as Role Evolves and vCISO is Viable, Cobalt Strike and Resilience - ... - BSW #396
⚠️
Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities
⚠️
Over 100 Malicious Chrome Extensions Exploiting Users to Steal Login Credentials and Execute Remote Code
⚠️
GitHub package limit put law firm in security bind
⚠️
More AIs Are Taking Polls and Surveys
⚠️
Kettering Health hit by system-wide outage after ransomware attack
⚠️
SideWinder APT Hackers Exploits Legacy Office Vulnerabilities to Deploy Malware Undetected
⚠️
Trust becomes an attack vector in the new campaign using trojanized KeePass
⚠️
VanHelsing Ransomware Builder Exposed on Hacker Forums
⚠️
IBM Warns: One-Third of Cyber Attacks Use Advanced Tactics to Steal Login Credentials
⚠️
News alert: Attaxion integrates its EASM Platform with ENISA’s EU Vulnerability Database (EUVD)
⚠️
Ransomware-Bande BlackBasta hat neuen Malware-Favoriten
⚠️
DragonForce targets rivals in a play for dominance
⚠️
Russian GRU Cyber Actors Targeting Western Logistics Entities and Tech Companies
⚠️
News alert: DataHub secures $35M Series B to enable AI to safely manage and use data
⚠️
Coinbase Says Rogue Contractor Data Breach Affects 69,461 Users
⚠️
This Dog Pulled a Full Adversarial Simulation—And Won
⚠️
ThreatLocker Patch Management: A Security-First Approach to Closing Vulnerability Windows
⚠️
Windows 11 Introduces Enhanced Administrator Protection to Strengthen Security Against Elevated Privilege Attacks
⚠️
71 Fake Websites Impersonating German Retailer to Steal Payment Information
⚠️
PupkinStealer Exploits Web Browser Passwords and App Tokens to Exfiltrate Data Through Telegram
⚠️
Russian State-Sponsored Threat Actors is Targeting Western Logistics Entities and Technology Companies.
⚠️
Docker Zombie Malware Infects Containers for Crypto Mining and Self-Replication
⚠️
Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
⚠️
Russia to enforce location tracking app on all foreigners in Moscow
⚠️
Wyden: AT&T, T-Mobile, and Verizon weren’t notifying senators of surveillance requests
⚠️
Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics
⚠️
Crawl-O-Matic Was THIS Close to Exploding WordPress 🔥
⚠️
Critical Samlify SSO flaw lets attackers log in as admin
⚠️
ESET takes part in global operation to disrupt Lumma Stealer
⚠️
Risky Business #792 -- Beware, Coinbase users. Crypto thieves are taking fingers now
📋
Microsoft Emergency Patch, Pwn2Own Berlin 2025 Highlights, and Emerging Cybersecurity Threats
📢
Joint advisory on Russian cyber campaign targeting logistics providers and IT companies
📢
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a
📢
Russian State-Sponsored Threat Actors is Targeting Western Logistics Entities and Technology Companies.
📢
Threat Actors Target U.S. Critical Infrastructure with LummaC2 Malware
📢
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
📢
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
📢
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
📢
GitLab security advisory (AV25-287)
📢
Cisco security advisory (AV25-288)
📢
CISA Says Russian Hackers Targeting Western Supply-Lines to Ukraine
🔥
Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager
🔥
Coinbase says recent data breach impacts 69,461 customers
🔥
Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit
🔥
Marks & Spencer faces $402 million profit hit after cyberattack
🔥
Cellcom Service Disruption Caused by Cyberattack
🔥
LockBit Internal Data Leak Reveals Payload Creation Methods and Ransom Demands
🔥
US Student to Plead Guilty Over PowerSchool Hack
🔥
Cellcom Confirms Cybersecurity Breach After Network Failure
🔥
How to Detect Phishing Attacks Faster: Tycoon2FA Example
🔥
19-Year-Old Hacker Admits Guilt in Major Cyberattack on PowerSchool
🔥
Coinbase says its data breach affects at least 69,000 customers
🔥
Cyberangriff auf Arla Deutschland
🔥
European Union sanctions Stark Industries for enabling cyberattacks
🔥
US student agrees to plead guilty to hack affecting tens of millions of students
🔥
New Scan Uncovers 150K Industrial Systems Worldwide Vulnerable to Cyberattacks
🔥
3AM ransomware uses spoofed IT calls, email bombing to breach networks
🔥
The Pharmacist Behind 2 Billion Deepfakes 😳
🔥
M&S says it will respond to April cyberattack by accelerating digital transformation plans
🔥
Veracode Just Found Something Terrifying in Google Calendar
🔥
Russian hackers breach orgs to track aid routes to Ukraine
🔥
Smashing Security podcast #418: Grid failures, Instagram scams, and Legal Aid leaks
🕵️
CSO30 Australia Awards 2025: Nominations now open
🕵️
ISC Stormcast For Wednesday, May 21st, 2025 https://isc.sans.edu/podcastdetail/9460, (Wed, May 21st)
🕵️
New Phishing Attack Uses AES & Malicious npm Packages to Office 365 Login Credentials
🕵️
Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers
🕵️
Google DeepMind Unveils Defense Against Indirect Prompt Injection Attacks
🕵️
What are You Working on Wednesday
🕵️
RSAC Fireside Chat: Enterprise browsers arise to align security with the modern flow of work
🕵️
Dero miner spreads inside containerized Linux environments
🕵️
Cortex Cloud — Unified Efficiency, Now with Dual FedRAMP Authority
🕵️
GenAI Security Is the New BYOD 🚨
🕵️
Hackers Masquerade as Organizations to Steal Payroll Logins and Redirect Payments from Employees
🕵️
Hackers Target Mobile Users Using PWA JavaScript to Bypass Browser Security
🕵️
Microsoft Sinkholes Domains, Disrupts Notorious ‘Lumma Stealer’ Malware Operation
🕵️
New Variant of Crypto Confidence Scam
🕵️
GenAI Adoption Just Doubled — Are You Falling Behind?
🕵️
Lumma infostealer malware operation disrupted, 2,300 domains seized
🌐
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims
🌐
PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms
🌐
Lumma infostealer malware operation disrupted, 2,300 domains seized
📡
Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps
📡
Securing CI/CD workflows with Wazuh
📡
Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs
📡
How One Idea Transformed Network Virtualization!
📡
New Variant of Crypto Confidence Scam, (Wed, May 21st)
📡
This Company Almost Hired a Ghost Employee! 👻
📡
What is cyber-resilience, and how to start implementing it
📡
Sophos Firewall v21.5: Streamlined management
📡
Signal resorts to “weird trick” to block Windows Recall in Desktop app
📡
OpenAI hints at a big upgrade for ChatGPT Operator Agent
📡
Anthropic web config hints at Claude Sonnet 4 and Opus 4