112Articles
8Categories
2025-06-17Date
🚨
U.S. CISA adds Apple products, and TP-Link routers flaws to its Known Exploited Vulnerabilities catalogsubmitted by kid to cybersecurity 3 points | 0 comments https://securityaffairs.com/179086/security/u-s-cisa-adds-apple-products-and-tp-link-routers-flaws-to-its-known-exploited-vulnerabilities-catalog.html
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.    CVE-2023-0386 Linux Kernel Improper Ownership Management Vulnerability  These types of vulnerabilities are frequent attack vecto…
KEV
🐛
Zyxel Devices Under Attack as Hackers Exploit UDP Port RCE Flaw
🐛
Hackers Weaponize Langflow Vulnerability to Launch Flodrix Botnet
KEV
🐛
CISA Alerts: iOS Zero‑Click Flaw Actively Exploited
KEV
🐛
Recent Langflow Vulnerability Exploited by Flodrix Botnet
🐛
Hackers Exploiting Chrome Zero‑Day Vulnerability in the Wild
KEV
🐛
TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate Alert
KEV
🐛
Critical sslh Vulnerabilities Allow Remote Denial-of-Service Attacks
🐛
ASUS Armoury Crate Vulnerability Lets Hackers Gain System-Level Access on Windows
🐛
Sicherheitsrisiko bei Salesforce Industry Cloud
🐛
BeyondTrust Tools RCE Vulnerability Allows Attackers Execute Arbitrary Code
🐛
Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet
KEV
⚠️
Apache Tomcat Flaws Allow Auth Bypass and DoS Attacks
⚠️
DeerStealer Malware Deployed Through Exploitation of Windows Run Prompt by Threat Actors
⚠️
8 tips for mastering multicloud security
⚠️
Krimineller Online-Marktplatz abgeschaltet
⚠️
Android Devices Under Siege: How Threat Actors Abuse OEM Permissions for Privilege Escalation
⚠️
Operation 999: Ransomware tabletop tests cyber execs’ response
⚠️
Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335
⚠️
Asus Armoury Crate Vulnerability Leads to Full System Compromise
⚠️
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks
⚠️
Water Curse Hacker Group Uses 76 GitHub Accounts to Spread Multistage Malware
⚠️
Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers
KEV
⚠️
Where AI Provides Value
⚠️
PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud Environments
⚠️
Hard-Coded 'b' Password in Sitecore XP Sparks Major RCE Risk in Enterprise Deployments
⚠️
Hackers Manipulate Search Engines to Push Malicious Sites
⚠️
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks
⚠️
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets
⚠️
Phishing goes prime time: Hackers use trusted sites to hijack search rankings
⚠️
Critical Vulnerabilities in Sitecore Could Lead to Widespread Enterprise Attacks
⚠️
Zyxel Firewall Vulnerability Again in Attacker Crosshairs
⚠️
Hacker steals 1 million Cock.li user records in webmail data breach
⚠️
Security, risk and compliance in the world of AI agents
⚠️
Two Factor Insecurity: How Google, Amazon, Meta and thousands of other companies leave customers vulnerable over one-time codes to save time and money
⚠️
Two Factor Insecurity: How Google, Amazon, Meta and thousands of other companies leave customers vulnerable over one-time codes to save time and money
⚠️
Sitecore CMS exploit chain starts with hardcoded 'b' password
⚠️
Kubernetes Runs the Internet... But Some Still Don't Trust Open Source?
⚠️
New Veeam RCE flaw lets domain users hack backup servers
⚠️
XDSpy Threat Actors Exploit Windows LNK Zero-Day Vulnerability to Target Windows System Users
⚠️
New Veeam RCE flaw lets domain users hack backup servers
⚠️
CISA Releases Five Industrial Control Systems Advisories
⚠️
How Social Pressure Silently Controls Cybersecurity Decisions
⚠️
LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents
⚠️
New Chaos RAT Variants Targeting Windows and Linux Systems to Steal Sensitive Data
⚠️
Your Favorite Command Line Tool Just Turned 27! 🎉
⚠️
BusKill Warrant Canary 2025-2026
⚠️
Why Enterprise Linux Updates Are a Nightmare 😱
⚠️
New ClickFix Malware Variant ‘LightPerlGirl’ Targets Users in Stealthy Hack
⚠️
MDEAutomator: Open-source endpoint management, incident response in MDE
⚠️
MY TAKE: Microsoft owns AI jailbreak risk — Google, Meta, Amazon, OpenAI look the other way
⚠️
Did Log4Shell Just Change Open Source Forever?
⚠️
A Vulnerability in Grafana Could Allow for Arbitrary Code Execution
📢
Citrix security advisory (AV25-350)
📢
BeyondTrust security advisory (AV25-351)
📢
Veeam security advisory (AV25-352)
📢
Google Chrome security advisory (AV25-353)
🔥
GCHQ Intern Sentenced to 7 Years for Illegally Copying Secret Files to Smartphone
🔥
Freedman Healthcare hacked, database software used by 27 state public health departments | Cybernews
🔥
Hackers claim attack on Scania, website down​ | Cybernews
🔥
Backups Are Under Attack: How to Protect Your Backups
🔥
Washington Post Staffer Emails Targeted in Cyber Breach
🔥
UK watchdog fines 23andMe over 2023 data breach
🔥
UK fines 23andMe for ‘profoundly damaging’ breach exposing genetics data
🔥
Hacker steals 1 million Cock.li user records in webmail data breach
🔥
Pro-Israel hacktivist group claims reponsibility for alleged Iranian bank hack
🔥
Scania confirms insurance claim data breach in extortion attempt
🔥
Physical Security Over Firewalls? Here’s Why
🔥
Infecting insurance firms with ransomware… for dummies
🕵️
ISC Stormcast For Tuesday, June 17th, 2025 https://isc.sans.edu/podcastdetail/9496, (Tue, Jun 17th)
🕵️
Cyberbedrohung für Internet-User weiter auf Rekordhoch
🕵️
150K+ Users Affected by Malicious Loan Apps on iOS and Google Play
🕵️
Hackers Use Fake Verification Prompt and Clickfix Technique to Deploy Fileless AsyncRAT
🕵️
WhatsApp’s Status Tab Set to Feature Ads as Meta Monetizes Platform
🕵️
Circumvent Raises $6 Million for Cloud Security Platform
🕵️
Scattered Spider, fresh off retail sector attack spree, pivots to insurance industry | CyberScoop
🕵️
Hackers switch to targeting U.S. insurance companies
🕵️
US Insurance Industry Warned of Scattered Spider Attacks
🕵️
Kali Linux 2025.2 released with 13 new tools, car hacking updates
🕵️
CyberheistNews Vol 15 #24 [Red Alert] How a Fake Cybersecurity Firm Turned Out a Real Threat
🕵️
Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms
🕵️
New Sophisticated Multi-Stage Malware Campaign Weaponizes VBS Files to Execute PowerShell Script
🕵️
Apache Tomcat Flaws Allow Auth Bypass and DoS Attacks
🕵️
Katz Stealer Enhances Credential Theft Capabilities with System Fingerprinting and Persistence Mechanisms
🕵️
Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware
🕵️
Two Predictions. One’s AI. One’s Football. Both 🔥
🕵️
How Long Until the Phishing Starts? About Two Weeks, (Tue, Jun 17th)
🕵️
Baby Tigers Bite — The Hidden Risks of Scaling AI Too Fast
🕵️
Kimsuky and Konni APT Groups Lead Active Attacks Targeting East Asia
🕵️
KnowBe4 Collaborates with Microsoft: Strengthening Email Security Through Strategic Integration
🕵️
Beware: Weaponized Research Papers Delivering Malware Through Password-Protected Documents
🕵️
New Sophisticated Multi-Stage Malware Campaign Uses VBS Files to Execute PowerShell Script
🕵️
This Is the 'Talkies' Moment of Cybersecurity 😮
🕵️
Threat Actor Abuses TeamFiltration for Entra ID Account Takeovers
🕵️
New KimJongRAT Stealer Uses Weaponized LNK File to Deploy PowerShell-Based Dropper
🕵️
Hackers Can Hide Images in Text Data and Embeds Directly into DNS TXT Records
🕵️
New Sorillus RAT Targets European Organizations Through Tunneling Services
🕵️
AI Zombie Lawyer, Scattered Spider, ASUS, Mainframes, GrayAlpha, Backups, Josh Marpet - SWN #486
🎙️
The AI Fix #55: Atari beats ChatGPT at chess, and Apple says AI “thinking” is an illusion
📡
Meta Starts Showing Ads on WhatsApp After 6-Year Delay From 2018 Announcement
📡
Google to scale up AI-powered fraud detection and security operations in India
📡
How to buy and connect a travel eSIM with Kaspersky eSIM Store | Kaspersky official blog
📡
Are Forgotten AD Service Accounts Leaving You at Risk?
📡
Microsoft fixes Surface Hub boot issues with emergency update
📡
How to automate IT ticket handling with AI and Tines
📡
Why Fixing Security Alerts Might Be a Waste of Time! 🤯
📡
Instagram 'BMO' ads use AI deepfakes to scam banking customers
📡
Observability startup Coralogix becomes a unicorn, eyes India expansion
📡
Paddle settles for $5 million over facilitating tech support scams
📡
Instagram ads mimicking BMO, EQ Banks are finance scams
📡
Instagram ads mimicking BMO, EQ Bank are finance scams