117Articles
9Categories
2025-07-29Date
🚨
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print management software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The …
KEV
🚨
CISA Issues Alert on Cisco Identity Services Engine Flaw Exploited in Active AttacksThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding severe vulnerabilities in Cisco’s Identity Services Engine (ISE) that are being actively exploited by threat actors. The agency added two critical injection vulnerabil…
KEV
🐛
PoC Exploit Published for Actively Exploited Cisco Identity Services Engine Flaw
KEV
🐛
CISA Issues Alert on PaperCut RCE Vulnerability Under Active Exploitation
KEV
🐛
Citrix NetScaler Devices Memory Leak: CVE-2025-5777
🐛
Auto-Color RAT targets SAP NetWeaver bug in an advanced cyberattack
🐛
Critical CodeIgniter Flaw Exposes Millions of Web Apps to File Upload Attacks
🐛
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
🐛
Could Perplexity Make Cyber Tools Smarter?
⚠️
Empathie trifft IT-Sicherheit: Der Weg zu gelebter Compliance
⚠️
UNC3886 Exploits Multiple 0-Day Bugs in VMware vCenter, ESXi, and Fortinet FortiOS
⚠️
Aeroflot Hit by Year‑Long Cyber Operation That Allegedly Wiped 7,000 Servers
⚠️
The healthcare industry is at a cybersecurity crossroads
⚠️
How AI red teams find hidden flaws before attackers do
⚠️
Hackers Exploit IIS Servers with New Web Shell Script for Full Remote Control
⚠️
New macOS Vulnerability Allows Attackers to Steal Private Files by Bypassing TCC
⚠️
Organizations Warned of Exploited PaperCut Flaw
⚠️
Triage is Key! Python to the Rescue!, (Tue, Jul 29th)
⚠️
PyPI Alerts Developers to New Phishing Attack Using Fake PyPI Site
⚠️
Sploitlight: macOS Vulnerability Leaks Sensitive Information
⚠️
How the Browser Became the Main Cyber Battleground
⚠️
Why React Didn't Kill XSS: The New JavaScript Injection Playbook
⚠️
Researchers Reveal Technical Details of SonicWall SMA100 Series N-Day Vulnerabilities
⚠️
CISA flags PaperCut RCE bug as exploited in attacks, patch now
⚠️
The Huawei Dilemma: Why Europe Needs Strong Intelligence Guardrails
⚠️
Spy satellite agency says law enforcement probing 'incident' affecting contracting site | Reuters
⚠️
The Huawei Dilemma: Why Europe Needs Strong Intelligence Guardrails
⚠️
Exploit available for critical Cisco ISE bug exploited in attacks
⚠️
China-linked group Fire Ant exploits VMware and F5 flaws since early 2025
⚠️
Gemini CLI Vulnerability Allows Silent Execution of Malicious Commands on Developer Systems
⚠️
Seal Security Raises $13 Million to Secure Software Supply Chain
⚠️
Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims
⚠️
CISA and Partners Release Updated Advisory on Scattered Spider Group
⚠️
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44
⚠️
How to Shrink Your Attack Surface Fast ⚔️
⚠️
Lenovo Firmware Vulnerabilities Allow Persistent Implant Deployment
⚠️
Qwins Ltd: Bulletproof Hosting Provider Powering Global Malware Campaigns
⚠️
Qilin Ransomware Gains Momentum with Legal Assistance Option for Affiliates
⚠️
Android Banking Malware Masquerades as Government Agencies to Attack Users
⚠️
CISA Releases Part One of Zero Trust Microsegmentation Guidance
⚠️
CISA Releases Five Industrial Control Systems Advisories
⚠️
Google patches Gemini CLI tool after prompt injection flaw uncovered
⚠️
Vulnerability-Lookup 2.14.0 released
⚠️
Apple Updates Everything: July 2025, (Tue, Jul 29th)
⚠️
The hidden risks of browser extensions – and how to stay safe
⚠️
CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization
📢
Lionishackers Exfiltrate Sensitive Corporate Databases for Sale on the Dark Web
📢
Cybersicherheitsausgaben wachsen langsamer
📢
SolarWinds security advisory (AV25-462)
📢
Joint cyber security advisory on Scattered Spider
📢
VMware security advisory (AV25-463)
📢
Apple security advisory (AV25-464)
🔥
Cyberattack On Russian Airline Aeroflot Causes the Cancellation of More Than 100 Flights
🔥
GitHub Outage Hits Users Globally, Core Services Unavailable
🔥
Gunra Ransomware Group Unveils Efficient Linux Variant
🔥
From Ex Machina to Exfiltration: When AI Gets Too Curious
🔥
Aeroflot Hacked
🔥
GLOBAL GROUP Ransomware Claims Breach of Media Giant Albavisión
🔥
Pro-Ukrainian hackers claim massive cyberattack on Russia's Aeroflot | Reuters
🔥
CyberheistNews Vol 15 #30 [Heads Up] Ransomware is Back—and Smarter Than Ever in 2025: Trends
🔥
FBI seizes $2.4M in Bitcoin from new Chaos ransomware operation
🔥
Unveiling the Lumma Password Stealer Attack: Infection Chain and Escalation Tactics Exposed
🔥
French telecommunications giant Orange discloses cyberattack
🔥
Still Using Passwords? You’re Not Alone...
🔥
Telecom giant Orange warns of disruption amid ongoing cyberattack
🔥
Unveiling 0bj3ctivityStealer’s Execution Chain: New Capabilities and Exfiltration Techniques Exposed
🔥
Tea app’s second data breach exposed over a million private messages
🔥
Russian airline Aeroflot grounds dozens of flights after cyberattack
🔥
Minnesota activates National Guard after St. Paul cyberattack
🔥
Have You Learned from Someone Else’s Cyber Disaster?
🕵️
Creating Realistic Deepfakes Is Getting Easier Than Ever. Fighting Back May Take Even More AI
🕵️
ISC Stormcast For Tuesday, July 29th, 2025 https://isc.sans.edu/podcastdetail/9546, (Tue, Jul 29th)
🕵️
Security pros are drowning in threat-intel data and it's making everything more dangerous
🕵️
Aanchal Gupta Joins Adobe as Chief Security Officer
🕵️
Threat Actors Use Phishing to Target Belgian Grand Prix Fans and Teams
🕵️
Fable Security Raises $31 Million for Human Risk Management Platform
🕵️
Ermittler stoppen Erpresser-Software von Blacksuit/Royal
🕵️
Nach Flugausfällen sprechen Hacker und Kreml von Angriff
🕵️
Linux 6.16 Released with Performance and Networking Enhancements
🕵️
How Product-Led Security Leads to Paved Roads - Julia Knecht - ASW #341
🕵️
Dropzone AI Raises $37 Million for Autonomous SOC Analyst
🕵️
Boost Your Browsing Security: Integrate SecurityCoach with Microsoft Edge for Business
🕵️
Apple Introduces Containerization Feature for Seamless Kali Linux Integration on macOS
🕵️
Microsoft Teams Introduces New Join Bar to Help Users Join Meetings on Time
🕵️
Naval Group Denies Hack Claims, Alleges “Reputational Attack” - Infosecurity Magazine
🕵️
Order out of Chaos – Using Chaos Theory Encryption to Protect OT and IoT
🕵️
A Secure Vision for Our AI-Driven Future
🕵️
Critical Flaws in WordPress Plugin Leave 10,000 Sites Vulnerable - Infosecurity Magazine
🕵️
Resecurity | Methods to Bypass OTP in Mobile Apps: Successful VAPT Scenarios
🕵️
Cybersecurity Scams Targeting Fans and Teams at the 2025 Belgian Grand Prix | CloudSEK
🕵️
Promptfoo Raises $18.4 Million for AI Security Platform
🕵️
2025 INTERNET2 COMMUNITY Exchange Program - CommEX25
🕵️
SquareX Discloses Architectural Limitations Of Browser DevTools In Debugging Malicious Extensions
🕵️
Lazarus Subgroup ‘TraderTraitor’ Targets Cloud Platforms and Contaminates Supply Chains
🕵️
Automate THIS or Risk Burnout in Cybersecurity 🔥
🕵️
New XWorm V6 Variant with Anti-Analysis Features Targeting Windows Users in Active Attacks
🕵️
ToxicPanda Android Banking Malware Compromises Over 4,500 Devices to Harvest Banking Credentials
🕵️
Sealed Chain of Deception: Actors leveraging Node.JS to Launch JSCeal
🕵️
News Alert: SquareX exposes DevTools blind spot allowing widespread browser extension attacks
🕵️
Why Your Secrets Should NEVER Leave Your Infra!
🕵️
SLAs, SaaS, and Scary Surprises… Here’s the Truth
🕵️
Apple’s New Containerization Feature Allows Kali Linux Integration on macOS
🕵️
Air-Gap Hack to Outsmart Red Team? 😮 #cybersecurity
🕵️
This Is How Cybersecurity Coaches Are Really Made 🔐
🕵️
Popup Porn, LoveSense, Tea, Fire Ant, Scatterede Spider, AI Pricing, Josh Marpet... - SWN #498
🌐
Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks
🌐
The AI Fix #61: Replit panics, deletes $1M project; AI gets gold at Math Olympiad
🌐
Google won’t say if UK secretly demanded a backdoor for user data
🎙️
Cyber Circle: Awareness Training neu gedacht
📡
Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers
📡
What to do if you get a phishing email | Kaspersky official blog
📡
How attackers are still phishing "phishing-resistant" authentication
📡
200,000 WordPress websites at risk of being hijacked due to vulnerable Post SMTP plugin
📡
Microsoft Edge now an 'AI-powered browser' with Copilot Mode
📡
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain
📡
GOLD BLADE Remote DLL Sideloading Attack Deploys RedLoader
📡
How Microsoft defends against indirect prompt injection attacks