91Articles
9Categories
2025-07-24Date
🚨
Microsoft’s incomplete SharePoint patch led to global exploits by China-linked hackersA July 8 patch for the SharePoint Server zero-day flaw, which resulted in a global attack on nearly 100 organizations over the weekend starting July 18, had failed to fully patch the flaw. The flaw was brought to Microsoft’s notice in May during a hacker competition and was short…
KEV
🐛
CISA Alerts on Google Chromium Input Validation Flaw Actively Exploited
KEV
🐛
AWS Client VPN for Windows Vulnerability Could Allow Privilege Escalation
🐛
TP-Link Network Video Recorder Vulnerability Enables Arbitrary Command Execution
🐛
Metasploit Module Released to Exploit SharePoint 0-Day Vulnerabilities
KEV
🐛
Splunk Guide to Detect, Mitigate, and Respond to the CitrixBleed 2 Vulnerability
🐛
Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices
⚠️
A chit-chat between Llama 2 and ChatGPT for the automated creation of exploits
⚠️
Hackers On A Train - PSW #883
⚠️
7 Security-Praktiken zum Abgewöhnen
KEV
⚠️
Key Operator of World’s Largest XSS Dark Web Platform Detained
⚠️
SonicWall SMA 100 Vulnerabilities Allow Remote Execution of Arbitrary JavaScript
⚠️
Singapore’s cybersecurity paradox: Top firms rated A, yet all breached
⚠️
Weidmueller Industrial Routers Exposed to Remote Code Execution Flaws
⚠️
ToolShell Attacks Hit 400+ SharePoint Servers, US Government Victims Named
⚠️
Google Introduces OSS Rebuild to Boost Security in Open-Source Package Ecosystems
⚠️
Chinese Hackers Launch Targeted Campaign to Infect Windows Systems with Ghost RAT and PhantomNet Malware
⚠️
Microsoft: SharePoint servers also targeted in ransomware attacks
⚠️
SonicWall Patches Critical SMA 100 Vulnerability, Warns of Recent Malware Attack
⚠️
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems
⚠️
Researchers Exploit Cursor Background Agents to Take Over Amazon EC2 Instance
⚠️
Hacker inserts destructive code in Amazon Q as update goes live
⚠️
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices
⚠️
UNC3944 Exploits VMware vSphere to Deploy Ransomware and Steal Data from Organizations
⚠️
Elephant APT Group Exploits VLC Player and Encrypted Shellcode in Attacks on Defense Sector
⚠️
AI slop and fake reports are exhausting some security bug bounties
⚠️
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems
⚠️
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments
⚠️
Surge in Phishing Attacks Exploiting Spoofed SharePoint Domains and Sneaky 2FA Tactics
⚠️
Storm-2603 spotted deploying ransomware on exploited SharePoint servers - Help Net Security
⚠️
Hive0156 Hackers Targeting Government and Military Organizations to Deploy REMCOS RAT
⚠️
Coyote in the Wild: First-Ever Malware That Abuses UI Automation | Akamai
⚠️
The Lazy Way to Validate Vulnerabilities... Works?!
⚠️
Protecting G-Suite/MS365 and Security News - Abhishek Agrawal - PSW #884
⚠️
BlackSuit ransomware leak sites seized in Operation Checkmate
⚠️
If You Don't See It, Can You Secure It? Shadow IT Explained!
⚠️
ToolShell: An all-you-can-eat buffet for threat actors
📋
GitLab Publishes Security Update Addressing Several Vulnerabilities in Community and Enterprise Edition
📢
Europol Arrests XSS Forum Admin in Kyiv After 12-Year Run Operating Cybercrime Marketplace
📢
GRC Firm Vanta Raises $150 Million at $4.15 Billion Valuation
📢
New York Seeking Public Opinion on Water Systems Cyber Regulations
📢
[Control systems] ABB security advisory (AV25-450)
📢
VMware security advisory (AV25-451)
📢
APT28 Hackers Unveil First LLM-Powered Malware, Enhancing Attack Techniques with AI
📢
HPE security advisory (AV25-452)
🔥
New Tool: ficheck.py, (Thu, Jul 24th)
🔥
Free decryptor for victims of Phobos ransomware released
🔥
High-Value NPM Developers Compromised in New Phishing Campaign
🔥
Clorox Sues Cognizant for $380 Million Over 2023 Hack
🔥
China-Based APTs Deploy Fake Dalai Lama Apps to Spy on Tibetan Community
🔥
340K exposed after France Travail data breach​ | Cybernews
🔥
Defence giant Naval Group hit with major breach​ | Cybernews
🔥
US nuclear weapons agency hacked in Microsoft SharePoint attacks
🔥
Hackers breach Toptal GitHub account, publish malicious npm packages
🔥
Sophos captures multiple honors at SE Labs Awards 2025
🔥
Hacker sneaks infostealer malware into early access Steam game
🔥
AI-Powered Cyber Attacks Utilize ML Algorithms to Deploy Malware and Circumvent Traditional Security
🕵️
ISC Stormcast For Thursday, July 24th, 2025 https://isc.sans.edu/podcastdetail/9540, (Thu, Jul 24th)
🕵️
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access
🕵️
Mutmaßlicher Betreiber von großem Cybercrime-Forum geschnappt
🕵️
From Tech Podcasts to Policy: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas
🕵️
AI-Driven Wi-Fi Biometrics WhoFi Tracks Humans Behind Walls with 95.5% Accuracy
🕵️
NPM package ‘is’ with 2.8M weekly downloads infected devs with malware
🕵️
Massive data leak exposes Swedish citizens' lives​ | Cybernews
🕵️
HeroDevs Raises $125 Million to Secure Deprecated OSS
🕵️
NoName057(16) Hackers Target 3,700 Unique Devices Over the Last 13 Months
🕵️
Threat Actors Using .hwp Files to Distribute RokRAT Malware and Evade Detection Mechanisms
🕵️
WAF Just Got an Upgrade… Meet the AI Version!
🕵️
The Shocking Reason Gen Z May Fail in Cybersecurity
🕵️
Malware in official mouse software: Endgame Gears OP1w 4K V2 tool infected with Xred-RAT
🕵️
Is AI Still Overhyped in Cybersecurity? 🤖🔥
🕵️
The End of “Just Say No” in Cybersecurity
🕵️
Operation Cargotalon: Ung0901 Targets Russian Aerospace Defense Using Eaglet Implant
🕵️
Authorities in Ukraine nab alleged admin of Russian-language cybercrime forum | CyberScoop
🕵️
Trump AI plan pushes critical infrastructure to use AI for cyber defense | CyberScoop
🕵️
Phishers Target Aviation Execs to Scam Customers
🕵️
Granular Permissions + Ephemeral Tokens = Hacker Nightmare
🕵️
Security by Design — UX and AI in Modern Cybersecurity
🕵️
Rogue CAPTCHAs: Look out for phony verification pages spreading malware
🌐
CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing
🌐
New Koske Linux malware hides in cute panda images
📡
How to protect yourself from Google Forms scams | Kaspersky official blog
📡
How Solid Protocol Restores Digital Agency
📡
Watch This Webinar to Uncover Hidden Flaws in Login, AI, and Digital Trust — and Fix Them
📡
Pentests once a year? Nope. It’s time to build an offensive SOC
📡
Cybercrime forum Leak Zone publicly exposed its users’ IP addresses
📡
Phishers Target Aviation Execs to Scam Customers
📡
OpenAI confirms ChatGPT Agent is now rolling out for $20 Plus users
📡
Proactive Email Security: The Power of AI