86Articles
8Categories
2025-06-13Date
🐛
WebDAV Remote Code Execution 0-Day Actively Exploited — PoC Released
KEV
🐛
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware
KEV
🐛
PoC Exploit Unveiled for Windows Disk Cleanup Elevation Vulnerability
🐛
Ungepatchte Lücken ermöglichen Übernahme von GitLab-Konten
🐛
GCVE-BCP-03 - Decentralized Publication Standard implemented in Vulnerability-Lookup
🐛
Graphite Spyware Uses iOS Zero-Click Flaw to Target Journalists
🐛
HashiCorp Nomad ACL Lookup Flaw Allows Privilege Escalation
🐛
Acer Control Center Flaw Lets Attackers Run Malicious Code as Elevated User
🐛
Amazon Cloud Cam Flaw Allows Attackers to Intercept and Modify Network Traffic
🐛
Microsoft Defender Spoofing Flaw Enables Privilege Escalation and AD Access
🐛
NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073
🐛
Spring Framework Flaw Enables Remote File Disclosure via “Content‑Disposition” Header
🐛
Mitigating prompt injection attacks with a layered defense strategy
🐛
Chromium: CVE-2025-5959 Type Confusion in V8
🐛
Chromium: CVE-2025-5958 Use after free in Media
⚠️
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider
⚠️
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider
⚠️
AI Security Threats: Echo Leak, MCP Vulnerabilities, Meta's Privacy Scandal, and the 'Peep Show'
⚠️
How to log and monitor PowerShell activity for suspicious scripts and commands
⚠️
ZeroRISC Raises $10 Million for Open Source Silicon Security Solutions
⚠️
TokenBreak Exploit Tricks AI Models Using Minimal Input Changes
⚠️
Critical Vulnerabilities Patched in Trend Micro Apex Central, Endpoint Encryption
⚠️
Critical Vulnerability Exposes Many Mitel MiCollab Instances to Remote Hacking
⚠️
JSFireTruck Obfuscation Helps Cybercriminals Hijack Trusted Sites with Malicious JavaScript
⚠️
Fog Ransomware Uses Pentesting Tools to Steal Data and Launch Attacks
⚠️
Unpatched IT Tool Opens Door – Hackers Breach Billing Software Firm via SimpleHelp RMM
⚠️
Paragon Spyware used to Spy on European Journalists
⚠️
SimpleHelp Vulnerability Exploited Against Utility Billing Software Users
⚠️
Developers Beware – Sophisticated Phishing Scams Exploit GitHub Device Code Flow to Hijack Tokens
⚠️
Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion
⚠️
Victoria’s Secret restores critical systems after cyberattack
⚠️
Fog ransomware gang abuses employee monitoring tool in unusual multi-stage attack
⚠️
Microsoft Defender Spoofing Flaw Enables Privilege Escalation and AD Access
⚠️
Apple confirmed that Messages app flaw was actively exploited in the wild
KEV
⚠️
The Linux Family Tree is INSANE! 😱
📋
June Patch Tuesday digs into 67 bugs
📢
Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday
📢
NIST Releases New Guide – 19 Strategies for Building Zero Trust Architectures
📢
Trend Micro security advisory (AV25-343)
🔥
Ualabee - 472,296 breached accounts
🔥
Cloudflare: Outage not caused by security incident, data is safe
🔥
Fog Ransomware Attack Employs Unusual Tools
🔥
Hackers claim fresh T-Mobile data breach​ | Cybernews
🔥
Cloudflare: Outage not caused by security incident, data is safe
🔥
LockBit panel data leak shows Chinese orgs among the most targeted - Help Net Security
🔥
Microsoft confirms auth issues affecting Microsoft 365 users
🔥
Spanish arm of French insurance giant posted on hacker forum
🔥
Hackerangriff treibt Serviettenhersteller Fasana in die Insolvenz
🔥
Bert ransomware: what you need to know
🔥
In Other News: Cloudflare Outage, Cracked.io Users Identified, Victoria’s Secret Cyberattack Cost
🔥
Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper | Trend Micro (US)
🔥
Are You Too Late to Adopt ‘Shift Left’ Security?
🔥
Why We Keep Blaming Users Instead of Fixing Security 🛑
🔥
Healthcare Hacks: Why You Can’t Just 'Fix' a Data Leak!
🔥
CVSS Scores: A Broken System? 💻⚠️
🔥
🚨 The Dark Web Is Selling Cyberattacks – Here’s How!
🔥
The Only 4 Steps You Need in Any Cybersecurity Playbook 🔐
🕵️
[Guest Diary] Anatomy of a Linux SSH Honeypot Attack: Detailed Analysis of Captured Malware, (Fri, Jun 13th)
🕵️
ISC Stormcast For Friday, June 13th, 2025 https://isc.sans.edu/podcastdetail/9492, (Fri, Jun 13th)
🕵️
Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected
🕵️
Europol Says Criminal Demand for Data is “Skyrocketing”
🕵️
The New AI Attack Surface — How Cortex Cloud Secures MCP
🕵️
JSFireTruck: Exploring Malicious JavaScript Using JSF*ck as an Obfuscation Technique
🕵️
New 'SmartAttack' Steals Air-Gapped Data Using Smartwatches - SecurityWeek
🕵️
TeamFiltration Abused in Entra ID Account Takeover Campaign
🕵️
Harvard Said It – 80% of AI Deployments Are Trash!
🕵️
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
🕵️
Arsen Launches AI-Powered Vishing Simulation to Help Organizations Combat Voice Phishing at Scale
🕵️
Inside a Dark Adtech Empire Fed by Fake CAPTCHAs – Krebs on Security
🕵️
Kali Linux 2025.2 Released: New Tools, Smartwatch and Car Hacking Added
🕵️
Checkups and Checklists: Cyber Risk Isn’t Just a Technical Problem
🕵️
What Is AI?
🕵️
Discord flaw lets hackers reuse expired invites in malware campaign
🕵️
The Moment She Realized Data Scientists Don’t Use SDLC… 😨
🕵️
News alert: Arsen launches AI-powered vishing simulation to help combat voice phishing at scale
🕵️
Friday Squid Blogging: Stubby Squid
🕵️
$200,000 Zoom Call, Microsoft, Zero-Click, China & HD With $649 million of Bitcoin - SWN #485
🌐
CTEM is the New SOC: Shifting from Monitoring Alerts to Measuring Risk
🌐
Over 269,000 Websites Infected with JSFireTruck JavaScript Malware in One Month
🌐
Discord flaw lets hackers reuse expired invites in malware campaign
📡
South African man imprisoned after ransom demand against his former employer
📡
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
📡
Why Denmark is breaking up with Microsoft
📡
Dutch police identify users as young as 11-year-old on Cracked.io hacking forum
📡
Google links massive cloud outage to API management issue
📡
Chinese-owned VPN apps hide their origin