93Articles
8Categories
2025-07-28Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-20281 Cisco Identity Services Engine Injection Vulnerability CVE-2025-20337 Cisco Identity Services Engine Injection Vulnerability CV…
KEV
🐛
New “ToolShell” Exploit Targets SharePoint Servers for Full Takeover
🐛
LG Innotek Camera Flaws Could Give Hackers Full Admin Access
🐛
400,000 WordPress Websites Exposed by Post SMTP Plugin Vulnerability
🐛
Microsoft SharePoint Zero-Day
🐛
Chinese ‘Fire Ant’ spies start to bite unpatched VMware instances
🐛
Sploitlight: Analyzing a Spotlight-based macOS TCC vulnerability
🐛
Exploit available for critical Cisco ISE bug exploited in attacks
🐛
ToolShell: Uncovering Five Critical Vulnerabilities in Microsoft SharePoint
⚠️
Darkweb – das verkannte Security-Tool
⚠️
Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems Worldwide
⚠️
Critical Salesforce Flaws Allow Remote Code Execution – Patch Immediately!
⚠️
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
⚠️
The CISO’s challenge: Getting colleagues to understand what you do
⚠️
Amazon AI Tool Hacked, Scattered Spider Attacks VMware, and Major Ransomware Takedown | Cybersecurity Today
⚠️
Entwickler-Tool von Amazon verseucht
⚠️
Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations
⚠️
tj-actions Lessons Learned, US Cyber Offense, this week's enterprise security news - D... - ESW #417
⚠️
BlackSuit Ransomware Group Transitioning to ‘Chaos’ Amid Leak Site Seizure
⚠️
Inside Muddled Libra’s Playbook: Call Center Attacks for Initial Breach
⚠️
Root Evidence Launches With $12.5 Million in Seed Funding
⚠️
Android Malware-as-a-Service Gets Cheaper, Packing 2FA Interception
⚠️
NPM ‘is’ Package with 2.8M Weekly Downloads Exploited in Attack on Developers
⚠️
“We’re Too New To Be Hacked” – Famous Last Words 😬 #infosec
⚠️
Parasitic Sharepoint Exploits, (Mon, Jul 28th)
⚠️
CISA flags PaperCut RCE bug as exploited in attacks, patch now
⚠️
Raven Stealer Malware Exploits Telegram to Steal Logins, Payment Data, and Autofill Info
⚠️
Why Open Source Might Save Your Job 🔓
⚠️
UNC3886 Hackers Target Singapore’s Critical Infrastructure by Exploiting 0-Day Vulnerabilities
⚠️
Sploitlight: Analyzing a Spotlight-based macOS TCC vulnerability
⚠️
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
⚠️
Chinese Hackers Exploit Software Vulnerabilities to Breach Targeted Systems
⚠️
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution
⚠️
ArmouryLoader Bypasses Security Protections to Inject Malicious Code
⚠️
Vulnhuntr: Open-source tool to identify remotely exploitable vulnerabilities
⚠️
Lovense sex toy app flaw leaks private user email addresses
📢
IBM security advisory (AV25-453)
📢
When AI Meets Security… You Get THIS Nightmare
📢
Dell security advisory (AV25-454)
📢
Ubuntu security advisory (AV25-455)
📢
Atlassian security advisory (AV25-457)
📢
Red Hat security advisory (AV25-456)
📢
Internet Archive is now a US federal depository library
📢
Are passkeys enterprise-ready? | Kaspersky official blog
📢
Microsoft Edge security advisory (AV25-458)
📢
[Control systems] CISA ICS security advisories (AV25-459)
📢
GitHub security advisory (AV25-460)
📢
BeyondTrust security advisory (AV25-461)
🔥
Leak Zone Dark Web Forum Breach Exposes 22 Million User IPs and Locations
🔥
Hackers Breach Intelligence Portal Used by the CIA and Other Agencies
🔥
Women’s Dating App “Tea” Data Leak Exposes 13,000 User Selfies
🔥
Weekly Update 462
🔥
Threat Actors Claim Breach of Airpay Payment Gateway
🔥
Allianz Life Data Breach Impacts Most of 1.4 Million US Customers
🔥
Email Security Is Stuck in the Antivirus Era: Why It Needs a Modern Approach
🔥
Scattered Spider Targeting VMware vSphere Environments
🔥
NASCAR Confirms Personal Information Stolen in Ransomware Attack
🔥
⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More
🔥
Flights grounded as Russia’s largest airline Aeroflot hit by cyberattack
🔥
French submarine secrets surface after cyber attack
🔥
France's warship builder Naval Group investigates 1TB data breach
🔥
Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads
🔥
New York state cyber chief calls out Trump for cybersecurity cuts
🔥
Tea app leak worsens with second database exposing user chats
🔥
Unlocking the Power of Amazon Security Lake for Proactive Security
🕵️
ISC Stormcast For Monday, July 28th, 2025 https://isc.sans.edu/podcastdetail/9544, (Mon, Jul 28th)
🕵️
SHUYAL Emerges: Stealing Login Credentials from 19 Major Browsers
🕵️
Inside Laundry Bear: Unveiling Infrastructure, Tactics, and Procedures
🕵️
KnowBe4 Named a 2025 Gartner Peer Insights™ Customers’ Choice for Email Security Platforms
🕵️
Atomic macOS Stealer Upgraded with Remote Access Backdoor
🕵️
10 Best Ethical Hacking Service Providers in 2025
🕵️
LLM Honeypots Deceive Hackers into Exposing Attack Methods
🕵️
Revisiting UNC3886 Tactics to Defend Against Present Risk
🕵️
Free Tool Autoswagger Finds The API Flaws Attackers Hope You Miss
🕵️
Botconf 2025
🕵️
You Have an Alarm, But Did You Lock the Door? 🔐
🕵️
Mentorship Monday - Discussions for career and learning!
🕵️
Granular Access is Greater Than Admin Chaos 🧠 Here's The Fix
🕵️
Oyster Backdoor Disguised as PuTTY and KeyPass Targets IT Admins via SEO Poisoning
🕵️
That Time Tom Lehrer Pranked the NSA
🕵️
Feeling Lost in Tech? Here’s What to Do 🚀
🕵️
Nobody Knew We Were Making Millions 💰
🕵️
Why Even Hardcore Hackers Use Active Directory Today
🕵️
Want to Join CCDC But No Team? Here's Your Shortcut!
🕵️
MY TAKE: The signal vs. the noise: email messaging in the era of my AI talking to your AI
🌐
Security considerations for critical infrastructure (ITSAP.10.100)
🌐
Endgame Gear mouse config tool infected users with malware
📡
Sophos’ Secure by Design 2025 Progress
📡
OpenAI could rival Google Shopping with ChatGPT Shop
📡
OpenAI prepares GPT-5 for roll out
📡
Microsoft will stop supporting Windows 11 22H2 in October
📡
Advancing cybersecurity for K-12 and libraries: Strategic considerations for the FCC Cybersecurity Pilot Program
📡
Allianz Life hit by hackers, customer and staff personal data stolen