213Articles
9Categories
2025-08-12Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2013-3893 Microsoft Internet Explorer Resource Management Errors Vulnerability CVE-2007-0671 Microsoft Office Excel Remote Code Execution …
KEV
πŸ›
Apache bRPC Vulnerability Lets Attackers Crash Services Remotely via Network
πŸ›
NCSC: Citrix NetScaler Flaw (CVE-2025-6543) is Being Actively Exploited to Breach Organizations
KEV
πŸ›
OT Networks Targeted in Widespread Exploitation of Erlang/OTP Vulnerability
πŸ›
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors
πŸ›
7,000 Citrix NetScaler Devices Still Vulnerable to CVE-2025-5777 and CVE-2025-6543
KEV
πŸ›
1,500 Jenkins Servers Vulnerable to Command Injection via Git Parameter Plugin
πŸ›
CVE-2025-49751 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2025-49745 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2025-49758 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53727 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53729 Microsoft Azure File Sync Elevation of Privilege Vulnerability
πŸ›
CVE-2025-33051 Microsoft Exchange Server Information Disclosure Vulnerability
πŸ›
CVE-2025-53730 Microsoft Office Visio Remote Code Execution Vulnerability
πŸ›
CVE-2025-53741 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-53759 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-53760 Microsoft SharePoint Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53761 Microsoft PowerPoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-24999 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53772 Web Deploy Remote Code Execution Vulnerability
πŸ›
CVE-2025-53773 GitHub Copilot and Visual Studio Remote Code Execution Vulnerability
πŸ›
CVE-2025-53781 Azure Virtual Machines Information Disclosure Vulnerability
πŸ›
CVE-2025-25005 Microsoft Exchange Server Tampering Vulnerability
πŸ›
CVE-2025-25006 Microsoft Exchange Server Spoofing Vulnerability
πŸ›
CVE-2025-25007 Microsoft Exchange Server Spoofing Vulnerability
πŸ›
CVE-2025-49743 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49757 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49759 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49761 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49762 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50153 Desktop Windows Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50154 Microsoft Windows File Explorer Spoofing Vulnerability
πŸ›
CVE-2025-50156 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-50158 Windows NTFS Information Disclosure Vulnerability
πŸ›
CVE-2025-50159 Remote Access Point-to-Point Protocol (PPP) EAP-TLS Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50160 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-50161 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50162 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-50163 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-50164 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-50165 Windows Graphics Component Remote Code Execution Vulnerability
πŸ›
CVE-2025-50166 Windows Distributed Transaction Coordinator (MSDTC) Information Disclosure Vulnerability
πŸ›
CVE-2025-50167 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50168 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50169 Windows SMB Remote Code Execution Vulnerability
πŸ›
CVE-2025-50170 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50171 Remote Desktop Spoofing Vulnerability
πŸ›
CVE-2025-50172 DirectX Graphics Kernel Denial of Service Vulnerability
πŸ›
CVE-2025-50173 Windows Installer Elevation of Privilege Vulnerability
πŸ›
CVE-2025-50176 DirectX Graphics Kernel Remote Code Execution Vulnerability
πŸ›
CVE-2025-50177 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2025-53131 Windows Media Remote Code Execution Vulnerability
πŸ›
CVE-2025-53132 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53133 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53134 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53135 DirectX Graphics Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53136 NT OS Kernel Information Disclosure Vulnerability
πŸ›
CVE-2025-53137 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53138 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53140 Windows Kernel Transaction Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53141 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53142 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53143 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2025-53144 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2025-53145 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
πŸ›
CVE-2025-53147 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53148 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53149 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53151 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53152 Desktop Windows Manager Remote Code Execution Vulnerability
πŸ›
CVE-2025-53153 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53154 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53155 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53156 Windows Storage Port Driver Information Disclosure Vulnerability
πŸ›
CVE-2025-53716 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
πŸ›
CVE-2025-53718 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53719 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53720 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-53721 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53722 Windows Remote Desktop ServicesΒ Denial of Service Vulnerability
πŸ›
CVE-2025-53723 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53724 Windows Push Notifications Apps Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53725 Windows Push Notifications Apps Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53726 Windows Push Notifications Apps Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53728 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
πŸ›
CVE-2025-47954 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53731 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-53732 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-53733 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-53734 Microsoft Office Visio Remote Code Execution Vulnerability
πŸ›
CVE-2025-53735 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-53736 Microsoft Word Information Disclosure Vulnerability
πŸ›
CVE-2025-53737 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-53738 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-53739 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-53740 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-53765 Azure Stack Hub Information Disclosure Vulnerability
πŸ›
CVE-2025-53766 GDI+ Remote Code Execution Vulnerability
πŸ›
CVE-2025-53769 Windows Security App Spoofing Vulnerability
πŸ›
CVE-2025-50157 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-50155 Windows Push Notifications Apps Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53778 Windows NTLM Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53779 Windows Kerberos Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53783 Microsoft Teams Remote Code Execution Vulnerability
πŸ›
CVE-2025-53784 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-53788 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53789 Windows StateRepository API Server file Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53793 Azure Stack Hub Information Disclosure Vulnerability
πŸ›
CVE-2025-48807 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2025-49755 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
πŸ›
CVE-2025-49707 Azure Virtual Machines Spoofing Vulnerability
πŸ›
CVE-2025-49712 Microsoft SharePoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-49736 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
πŸ›
Microsoft August 2025 Patch Tuesday, (Tue, Aug 12th)
KEV
⚠️
Weekly Update 464
⚠️
So verwundbar sind KI-Agenten
⚠️
News alert: INE named among top providers of practical, career-ready cybersecurity training in 2025
⚠️
Reddit Blocks Internet Archive Amid AI Data Scraping Concerns
⚠️
Critical Vulnerability in Carmaker Portal Allows Hackers to Unlock Cars Remotely
⚠️
5 key takeaways from Black Hat USA 2025
⚠️
Record $250K Bug Bounty Awarded for Discovering Critical Chrome RCE Flaw
⚠️
The Future of Supply Chain Security - Janet Worthington - ASW #343
⚠️
SAP Patches Critical S/4HANA Vulnerability
⚠️
GPT-5 jailbroken hours after launch using β€˜Echo Chamber’ and Storytelling exploit
⚠️
Over 29,000 Exchange servers unpatched against high-severity flaw
⚠️
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls
⚠️
Adult sites trick users into Liking Facebook posts using a clickjack Trojan
⚠️
CyberheistNews Vol 15 #32 How Hackers Exploit Microsoft Teams in Social Engineering Attacks
⚠️
Over 3,000 NetScaler devices left unpatched against CitrixBleed 2 bug
⚠️
Ivanti Connect Secure, Policy Secure, and ZTA Flaws Allow Attackers to Launch DoS Attacks
⚠️
Fortinet SSL VPN Targeted by Hackers from 780 Unique IP Addresses
⚠️
ShinyHunters Claims BreachForums Seized by Law Enforcement, Now a Honeypot
⚠️
Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses
⚠️
CISA Releases Seven Industrial Control Systems Advisories
⚠️
ShinyHunters Unveils That BreachForums Taken by Law Enforcement Agencies, Now It Is a Honeypot
⚠️
3 Zero Days Rated 9.3 🀯 You Better Patch That ESXi!
⚠️
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
⚠️
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager
⚠️
Microsoft Patch Tuesday August 2025: 107 Vulnerabilities Patched, Including 35 RCE Flaws
⚠️
Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification
⚠️
Quick Assist Is Built In... So Is the Risk πŸ”“
⚠️
Law Enforcement Seizes BlackSuit Ransomware Servers Targeting U.S. Critical Infrastructure
⚠️
No Regulator, No Rules: Crypto’s Wild West Is Here
⚠️
Hackers leak Allianz Life data stolen in Salesforce attacks
⚠️
Critical Patches Issued for Microsoft Products, August 12, 2025
⚠️
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
πŸ“‹
SAP Security Patch Day Fixes 15 Flaws, Including 3 Injection Vulnerabilities
πŸ“‹
Windows 10 KB5063709 update fixes extended security updates enrollment
πŸ“‹
Microsoft Patch Tuesday, August 2025 Edition
πŸ“’
Digitale SouverΓ€nitΓ€t fΓΌr Deutschland vorerst unerreichbar
πŸ“’
SAP security advisory – August 2025 monthly rollup (AV25-500)
πŸ“’
[Control systems] Siemens security advisory (AV25-502)
πŸ“’
[Control systems] Schneider Electric security advisory (AV25-501)
πŸ“’
APT27 Doesn’t Knock… They Blow In πŸ”“
πŸ”₯
DarkBit Hackers Target VMware ESXi Servers to Deploy Ransomware and Encrypt VMDK Files
πŸ”₯
North Korean Kimsuky Hackers Suffer Data Breach as Insiders Leak Information Online
πŸ”₯
New Ransomware Charon Uses Earth Baxia APT Techniques To Target Enterprises
πŸ”₯
Royal Enfield Reportedly Targeted in Ransomware Attack, Hackers Claim Data Encryption
πŸ”₯
The β€œIncriminating Video” Scam
πŸ”₯
Saint Paul cyberattack linked to Interlock ransomware gang
πŸ”₯
Scattered Spider’s New Telegram Channel Names Targeted Organizations
πŸ”₯
Manpower discloses data breach affecting nearly 145,000 people
πŸ”₯
REvil Actor Accuses Russia of Planning 2021 Kaseya Attack
πŸ”₯
275M patient records breachedβ€”How to meet HIPAA password manager requirements
πŸ”₯
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang
πŸ”₯
McPwned: The McHire Breach Explained πŸ’»πŸ›‘
πŸ”₯
US govt seizes $1 million in crypto from BlackSuit ransomware gang
πŸ”₯
Think Your Site’s Safe? Gravity Forms Just Got Hit.
πŸ”₯
New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises | Trend Micro (US)
πŸ”₯
Saint Paul cyberattack linked to Interlock ransomware gang
πŸ”₯
Hackers breach and expose a major North Korean spying operation
πŸ”₯
Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain Risks
πŸ”₯
Docker Hub still hosts dozens of Linux images with the XZ backdoor
πŸ”₯
Russian government hackers said to be behind US federal court filing system hack: report
πŸ”₯
If Cybersecurity Had a Superpower… It'd Be THIS.
πŸ”₯
Russia Is Suspected to Be Behind Breach of Federal Court Filing System
πŸ•΅οΈ
ISC Stormcast For Tuesday, August 12th, 2025 https://isc.sans.edu/podcastdetail/9566, (Tue, Aug 12th)
πŸ•΅οΈ
Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity
πŸ•΅οΈ
News alert: New Heimdal study reveals tool overload is driving fatigue, missed threats in MSPs
πŸ•΅οΈ
Researchers Detail Script-Masking Tactics That Bypass Defenses
πŸ•΅οΈ
Forging a Secure Digital Future
πŸ•΅οΈ
SHARED INTEL Q&A: From Code Red to the β€˜new control plane’ β€” Marc Maiffret on identity
πŸ•΅οΈ
Honoring KnowBe4’s 15 Years of Excellence with a New Brand Identity
πŸ•΅οΈ
Hackers steal Google Ads business contact data | Cybernews
πŸ•΅οΈ
CodeSecCon Is Today: Where Software Security’s Next Chapter Unfolds (Virtual Event)
πŸ•΅οΈ
Flaws in Major Automaker's Dealership Systems Allowed Car Hacking, Personal Data Theft - SecurityWeek
πŸ•΅οΈ
1Kosmos Raises $57 Million for Identity Verification and Authentication Platform
πŸ•΅οΈ
New β€˜Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks
πŸ•΅οΈ
Don't Just Watch Cyber Happenβ€”Shape It
πŸ•΅οΈ
Curly COMrades cyberspies hit govt orgs with custom malware
πŸ•΅οΈ
Inside the Dark Web’s Access Economy: How Hackers Sell the Keys to Enterprise Networks
πŸ•΅οΈ
Dow’s 125-year legacy: Innovating with AI to secure a long future
πŸ•΅οΈ
PoisonSeed Phishing Kit Bypasses MFA to Steal Credentials from Users and Organizations
πŸ•΅οΈ
Scattered Spider and ShinyHunters' Next Move: Leaking Data
πŸ•΅οΈ
Electronic Arts Blocks 300,000 Cheating Attempts After Battlefield 6 Beta Launch
πŸ•΅οΈ
Google, Bing, Brave… And the AI Mafia Behind It All πŸ€–
πŸ•΅οΈ
300 Baud, Buddy Hackett Nudes, Dell, badUSB, Exchange, Erlang/OTP, Josh Marpet... - SWN #502
🌐
The AI Fix #63: GPT-5 is the best AI ever, and Jim Acosta interviews a murdered teenager’s avatar
🌐
Docker Hub still hosts dozens of Linux images with the XZ backdoor
πŸ“‘
Sleepwalk: a sophisticated way to steal encryption keys | Kaspersky official blog
πŸ“‘
The Ultimate Battle: Enterprise Browsers vs. Secure Browser Extensions
πŸ“‘
Windows 11 23H2 Home and Pro reach end of support in November
πŸ“‘
Enhancements and new offerings for Sophos’ email security portfolio
πŸ“‘
Models of cloud computing (ITSAP.50.111)
πŸ“‘
Introduction to cloud computing (ITSAP.50.110)
πŸ“‘
Introduction to cloud computing (ITSAP.50.110)
πŸ“‘
Android's pKVM hypervisor earns SESIP Level 5 security certification
πŸ“‘
Windows 11 KB5063878 & KB5063875 cumulative updates released
πŸ“‘
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT
πŸ“‘
ChatGPT's new subscription costs less than $5, but it's not for everyone
πŸ“‘
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro
πŸ“‘
Supply-chain dependencies: Check your resilience blind spot
πŸ“‘
How the always-on generation can level up its cybersecurity game