94Articles
10Categories
2025-07-22Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability CVE-2025-49706 Microsoft SharePoint Improper Authentication Vulnerability These…
KEV
🚨
CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-54309 CrushFTP Unprotected Alternate Channel Vulnerability CVE-2025-6558 Google Chromium ANGLE and GPU Improper Input Validation Vulne…
KEV
🐛
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)
🐛
Kubernetes Image Builder Vulnerability Grants Root Access to Windows Nodes
🐛
wolfSSL Security Update Addresses Apple Trust Store Bypass
🐛
New Scanner Launched to Detect CVE-2025-53770 in SharePoint Servers
🐛
Cisco Alerts on ISE RCE Vulnerability Actively Exploited
KEV
🐛
CVE-2022-44693 Microsoft SharePoint Server Remote Code Execution Vulnerability
⚠️
ExpressVPN Windows Client Flaw Could Expose User Information
⚠️
New Report Reveals Just 10% of Employees Drive 73% of Cyber Risk
⚠️
Microsoft ‘digital escorts’ reveal crucial US counterintelligence blind spot
⚠️
ToolShell Zero-Day Attacks on SharePoint: First Wave Linked to China, Hit High-Value Targets
⚠️
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
⚠️
Cybercriminals Merge Android Malware with Click Fraud Apps to Harvest Credentials
⚠️
Rise of Compromised LLMs - Sohrob Kazerounian - ASW #340
⚠️
Dark Web Travel Agencies Exploit Cheap Deals to Steal Credit Card Data
⚠️
“Encryption Backdoors and the Fourth Amendment”
⚠️
Critical Sophos Firewall Flaws Allow Pre-Auth RCE
⚠️
Microsoft Sharepoint ToolShell attacks linked to Chinese hackers
⚠️
Apache Jena Vulnerability Allows Arbitrary File Access
⚠️
Hackers Selling macOS 0-Day LPE Exploit on Dark Forums
⚠️
Prettier-ESLint npm packages hijacked in a sophisticated supply chain attack
⚠️
Dell demonstration platform breached by World Leaks extortion group
⚠️
Cisco Confirms Active Exploits Targeting ISE Flaws Enabling Unauthenticated Root Access
⚠️
Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
KEV
⚠️
Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day
⚠️
Threat Actors Target Linux SSH Servers to Deploy SVF Botnet
⚠️
Joint Advisory Issued on Protecting Against Interlock Ransomware
⚠️
ETQ Reliance RCE Flaw Grants Full SYSTEM Access with a Single Space
⚠️
Disrupting active exploitation of on-premises SharePoint vulnerabilities
⚠️
Microsoft Sentinel data lake: Unify signals, cut costs, and power agentic AI
⚠️
CISA Releases Nine Industrial Control Systems Advisories
⚠️
Multiple Vulnerabilities in Microsoft SharePoint Server Could Allow for Remote Code Execution
⚠️
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups
⚠️
Microsoft Says Chinese APTs Exploited ToolShell Zero-Days Weeks Before Patch
⚠️
How a Single Download Can Infect Your Entire System 🧨
⚠️
Common mistakes in using CVSS | Kaspersky official blog
⚠️
Lumma infostealer malware returns after law enforcement disruption
⚠️
Donatello, SharePoint, CrushFTP, WordPress, Replit, AllaKore, Rob Allen, and more... -... - SWN #496
⚠️
News alert: Living Security report reveals that just 10% of employees drive 73% of cyber risk
⚠️
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
⚠️
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
⚠️
Multiple Vulnerabilities in Microsoft SharePoint Server Could Allow for Remote Code Execution
📋
Microsoft: Windows Server KB5062557 causes cluster, VM issues
📢
NIS2-Umsetzungsgesetz: Geschäftsleitung haftet mit Privatvermögen
📢
The CISO code of conduct: Ditch the ego, lead for real
📢
New DCHSpy Android Malware Targets WhatsApp, Call Logs, Audio, and Photos
📢
[Control systems] ABB security advisory (AV25-441)
📢
Vulnerabilities Expose Helmholz Industrial Routers to Hacking
📢
Mozilla security advisory (AV25-442)
📢
The AI Fix #60: Elon’s AI girlfriend, the arsonist red panda, and the AI that will kill you
📢
Sophos security advisory (AV25-443)
📢
Iranian Hackers Target Global Airlines to Steal Sensitive Data
📢
Joint Advisory Issued on Protecting Against Interlock Ransomware
📢
CISA and FBI warn of escalating Interlock ransomware attacks
📢
Funding to protect US from Stuxnet-like worm expired Sunday
🔥
Dell Data Breach – World Leaks Group Hacks Test Lab Platform
🔥
Weak Password Enables Ransomware Attack on 158-Year-Old Firm
🔥
Cybercriminals from GLOBAL GROUP Target All Platforms with Golang Ransomware
🔥
11 Years of Microsoft Regional Director and 15 Years of MVP
🔥
Dior Says Personal Information Stolen in Cyberattack
🔥
UK to ban public sector orgs from paying ransomware gangs
🔥
UK Bans Public Sector from Paying Ransomware Gangs
🔥
Scavenger Malware Compromises Popular npm Packages to Target Developers
🔥
UK government wants ransomware victims to report cyberattacks so it can disrupt the hackers
🔥
Major European healthcare network discloses security breach
🔥
Apple alerted Iranians to iPhone spyware attacks, say researchers
🔥
Ransomware Trends in 2025
🔥
Why GenAI Isn’t Reinventing Attacks… Yet
🕵️
ISC Stormcast For Tuesday, July 22nd, 2025 https://isc.sans.edu/podcastdetail/9536, (Tue, Jul 22nd)
🕵️
Wireshark 4.4.8 Released, (Tue, Jul 22nd)
🕵️
New Report Reveals Just 10% Of Employees Drive 73% Of Cyber Risk
🕵️
Angriff auf Ameos-Kliniken: Möglicherweise Patientendaten betroffen
🕵️
Financial Institutions Under Siege by Greedy Sponge Hackers’ Modified AllaKore RAT
🕵️
UK Sanctions Russian Hackers Tied to Assassination Attempts
🕵️
PoisonSeed überlistet FIDO-Schlüssel
🕵️
Darktrace Acquires Mira Security
🕵️
How Apps and Your Phone Can Expose Your Life Without Permission
🕵️
CyberheistNews Vol 15 #29 [Jawdropper] AI Is Luring Travelers to Places That Don't Even Exist!
🕵️
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
🕵️
ClickFake Interview Attack Leverages ClickFix Technique to Deploy GolangGhost Malware
🕵️
New Web3 Phishing Scam Uses Fake AI Platforms to Steal Credentials
🕵️
Dell Says Data Leaked by Hackers Is Fake
🕵️
Reclaiming Control: How Enterprises Can Fix Broken Security Operations
🕵️
Can AI Agents Spam Each Other?!
🕵️
New APIsec University Training Modules Now Available in KnowBe4’s Diamond Library
🌐
Back to Business: Lumma Stealer Returns with Stealthier Methods
🌐
National security meets next-gen tech at TechCrunch Disrupt 2025’s AI Defense panel
🌐
Coyote malware abuses Windows accessibility framework for data theft
🎙️
Why is your data worth so much? | Unlocked 403 cybersecurity podcast (S2E4)
📡
WinRAR MoTW Propagation Privacy, (Tue, Jul 22nd)
📡
How to Advance from SOC Manager to CISO?
📡
Windows 11 gets new Black Screen of Death, auto recovery tool
📡
Windows 11 KB5062660 update brings new 'Windows Resilience' features