81Articles
7Categories
2025-08-28Date
🐛
Attackers exploiting NetScaler ADC and Gateway zero day flaw, Citrix warns
KEV
🐛
Over 28,000 Citrix Servers at Risk from Active 0-Day RCE Exploit
KEV
🐛
CISA Issues Alert on Citrix NetScaler 0-Day RCE Exploited in the Wild
KEV
🐛
BadSuccessor After Patch: Using dMSAs for Credential Theft and Lateral Movement in AD
🐛
Cisco Nexus 3000 & 9000 Vulnerability Enables DoS Attacks
🐛
Cisco IMC Virtual Keyboard Vulnerability Allows Attackers to Redirect Users to Malicious Websites
🐛
Chromium: CVE-2025-9478 Use after free in ANGLE
🐛
Salt Typhoon APT techniques revealed in new report
⚠️
Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud Attacks
⚠️
Anthropic detects the inevitable: genAI-only attacks, no humans involved
⚠️
7 Anzeichen für akuten MSSP-Bedarf
⚠️
UK and allies expose China-based technology companies for enabling global cyber campaign against critical networks
⚠️
UK and allies expose China-based technology companies for enabling global cyber campaign against critical networks
⚠️
The CISO succession crisis: why companies have no plan and how to change that
⚠️
New Research and PoC Reveal Security Risks in LLM-Based Coding
⚠️
Microsoft Unveils Storm-0501’s Cloud-Based Ransomware Deployment Tactics
⚠️
TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents
⚠️
FreePBX Servers Hit by 0-Day Exploit, Disable Internet Access Advised
⚠️
ShadowSilk Targets Penetration-Testing Tools and Public Exploits to Breach Organizations
⚠️
China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years
⚠️
Farmers Insurance Breach Exposes Data of 1.1 Million Customers via Salesforce Compromise
⚠️
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide
⚠️
Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
⚠️
News alert: SquareX finds browser flaw undermining passkeys while exposing banking and SaaS apps
⚠️
Anthropic Blocks Hackers Attempting to Exploit Claude AI for Cyber Attacks
⚠️
Threat Actors Exploit Velociraptor Incident Response Tool for Remote Access
⚠️
Passwordstate dev urges users to patch auth bypass vulnerability
⚠️
CISA Releases Nine Industrial Control Systems Advisories
⚠️
Cisco UCS Manager Software Flaw Allows Attackers to Inject Malicious Commands
⚠️
How SafeLine WAF Turns Hackers’ Scanners into Trash
⚠️
2025 CSO Hall of Fame: George Finney on decryption risks, AI, and the CISO’s growing clout
⚠️
How Gainesville Regional Utilities is locking down vendor risk
⚠️
Google warns Salesloft breach impacted some Workspace accounts
⚠️
ADV200013 Microsoft Guidance for Addressing Spoofing Vulnerability in DNS Resolver
⚠️
News alert: Halo Security’s custom dashboards give security teams control while streamlining workflows
⚠️
Hackers Steal Your Car and Vulnerabilities - Rob Allen - PSW #889
📢
Regierung plant stärkere Cyberabwehr
📢
CISA Releases Guide to Hunt and Mitigate Chinese State-Sponsored Threats
📢
The FBI and agencies in the UK, Canada, and others warn that a Chinese hacking campaign targeting US telecoms has expanded to more countries and US companies
📢
Webinar Today: Ransomware Defense That Meets Evolving Compliance Mandates
📢
GitLab security advisory (AV25-549)
🔥
Microsoft Teams Flaw Prevents Users From Accessing Embedded Office Files
🔥
Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack
🔥
New Research Explores Emulating Scattered Spider Tactics in Real-World Scenarios
🔥
First AI-Powered Ransomware “PromptLock” Uses OpenAI gpt-oss-20b for Encryption
🔥
Hidden Vulnerabilities of Project Management Tools & How FluentPro Backup Secures Them
🔥
TransUnion says hackers stole 4.4 million customers’ personal information
🔥
Webinar: Why Top Teams Are Prioritizing Code-to-Cloud Mapping in Our 2025 AppSec
🔥
Lazarus Group Targets Windows 11 with ClickFix Tactics and Fake Job Offers
🔥
TransUnion suffers data breach impacting over 4.4 million people
🔥
MATLAB dev says ransomware gang stole data of 10,000 people
🔥
Electronics Manufacturer Data I/O Suffers Ransomware Breach
🔥
State of Nevada Faces IT Outage Amid Cyberattack, Offices Suspended
🔥
Malware devs abuse Anthropic’s Claude AI to build ransomware
🔥
CrowdStrike buys Onum in agentic SOC push
🕵️
ISC Stormcast For Thursday, August 28th, 2025 https://isc.sans.edu/podcastdetail/9590, (Thu, Aug 28th)
🕵️
Chinesische Telekom-Hacker in 80 Ländern aktiv
🕵️
New TamperedChef Attack Uses Weaponized PDF Editor to Steal Sensitive Data and Login Credentials
🕵️
115.000 Phishing-Emails in einer Woche versendet
🕵️
U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits
🕵️
The UK May Be Dropping Its Backdoor Mandate
🕵️
U.S. Treasury Sanctions North Korean IT Worker Network Funding Weapons Programs
🕵️
CrowdStrike to Acquire Onum to Fuel Falcon Next-Gen SIEM With Real-Time Telemetry
🕵️
Weaponized ScreenConnect RMM Tool Deceives Users into Installing Xworm RAT
🕵️
Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names
🕵️
Report: Cybercriminals are Hiring Social Engineering Talent
🕵️
Securing the AI "Before Times”
🕵️
New Phishing Kit Bypasses MFA to Steal Microsoft 365 Credentials
🕵️
US targets North Korean IT worker army with new sanctions
🌐
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials
🌐
Wave of npm supply chain attacks exposes thousands of enterprise developer credentials
📡
NX build compromise detection and response | Kaspersky official blog
📡
Defend what matters: Introducing Sophos Endpoint for Legacy Platforms
📡
Shadow IT Is Expanding Your Attack Surface. Here’s Proof
📡
Police seize VerifTools fake ID marketplace servers, domains
📡
Increasing Searches for ZIP Files, (Thu, Aug 28th)
📡
Microsoft Word will save your files to the cloud by default
📡
Affiliates Flock to ‘Soulless’ Scam Gambling Machine
📡
Google shares workarounds for auth failures on ChromeOS devices
📡
This month in security with Tony Anscombe – August 2025 edition
📡
Trend Vision One™ Email Security Raises the Standard