68Articles
9Categories
2025-08-29Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-57819 Sangoma FreePBX Authentication Bypass Vulnerability  This type of vulnerability is a frequent attack vector for malicious cybe…
KEV
🐛
Critical Hikvision Vulnerabilities Allow Remote Command Injection
🐛
Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution
🐛
WhatsApp Zero-Day Vulnerability Exploited with 0-Click Attacks to Hack Apple Devices
⚠️
Silver Fox Hackers Use Driver Vulnerability to Evade Security on Windows Systems
⚠️
New Mac Malware Dubbed “JSCoreRunner” Weaponizing PDF Conversion Site to Deliver Malware
⚠️
Cybercrime increasingly moving beyond financial gains
⚠️
Threat Actors Use Facebook Ads to Deliver Android Malware
⚠️
Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations
⚠️
Operation Serengeti 2.0: Trend Micro Helps Law Enforcement Fight Cybercrime in Africa
⚠️
TransUnion Data Breach Compromises Over 4 Million Customers
⚠️
Microsoft Teams Abused in Cyberattack Delivering PowerShell-Based Remote Access Malware
⚠️
Click Studios Patches Passwordstate Authentication Bypass Vulnerability in Emergency Access Page
⚠️
FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available
KEV
⚠️
Ransomware Group Exploits Hybrid Cloud Gaps, Gains Full Azure Control in Enterprise Attacks
⚠️
Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions
⚠️
US Sanctions Russian National, Chinese Firm Aiding North Korean IT Workers
⚠️
Google Confirms Workspace Accounts Also Hit in Salesforce–Salesloft Drift Data Theft Campaign
⚠️
KI greift erstmals autonom an
⚠️
AppSuite PDF Editor Exploit Lets Hackers Run Arbitrary Commands
⚠️
VS Code Marketplace Abused by Threat Actors to Deliver Malware via Trusted Extensions
⚠️
Two New feeds from CERT-FR integrated in Vulnerability-Lookup
⚠️
VerifTools Fake ID Operation Dismantled by Law Enforcement
⚠️
New BruteForceAI Tool Automatically Detects Login Pages and Executes Smart Brute-Force Attacks
⚠️
Microsoft to enforce MFA for Azure resource management in October
⚠️
WhatsApp patches vulnerability exploited in zero-day attacks
⚠️
WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware
⚠️
Chinese hacking group Salt Typhoon expansion prompts multinational advisory
📋
Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign
📋
Microsoft says recent Windows update didn't kill your SSD
📢
Zipline Phishing, Google Urges Password Resets, and AI-Driven Threats: Cybersecurity Today
📢
Netherlands Confirms China’s Salt Typhoon Hacking Group Targeted Small Dutch Telcos
📢
Netherlands Confirms China’s Salt Typhoon Hacking Group Targeted Small Dutch Telcos
📢
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication
📢
Sangoma FreePBX security advisory (AV25–550)
📢
Microsoft Edge security advisory (AV25-551)
🔥
Catch-22: Uncovering Compromised Hosts using SSH Public Keys | USENIX
🔥
Popular Nx Packages Compromised by Credential-Stealing Malware
🔥
TransUnion Data Breach Impacts 4.4 Million
🔥
I Hacked BellaBot and Every Robot from China's Biggest Robotics Company (Pudu Only Fixed It When I Told Their Clients)
🔥
In Other News: Iranian Ships Hacked, Verified Android Developers, AI Used in Attacks
🔥
Sweden scrambles after ransomware attack puts sensitive worker data at risk
🔥
FBI says China’s Salt Typhoon hacked at least 200 US companies
🔥
FBI says China’s Salt Typhoon hacked at least 200 US companies
🕵️
ISC Stormcast For Friday, August 29th, 2025 https://isc.sans.edu/podcastdetail/9592, (Fri, Aug 29th)
🕵️
DPRK Remote Work Tactics: Leveraging Code-Sharing Platforms
🕵️
Baggage Tag Scam
🕵️
VirusTotal Launches Endpoint That Explains Code Functionality for Malware Analysts
🕵️
Your KnowBe4 Fresh Content Updates from August 2025
🕵️
TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
🕵️
Google is getting ready to 'hack back' as US considers shifting from cyber defense to offense — new 'Scam Farms' bill opens up new retaliatory hacking actions
🕵️
One of the Biggest Mysteries in Cybersecurity: Why Don’t We Teach or Demand Secure
🕵️
Weaponized PDFs and LNK Files Used in Windows Attacks
🕵️
Cybersecurity News Review - Week 35 (2025)
🕵️
WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware
🕵️
WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware
🕵️
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials
🕵️
Friday Squid Blogging: Catching Humboldt Squid
🕵️
Astro Oblivion, FreePBX, GitHub, OWASP, Promptlock, Claude Aaran Leyland - SWN #507
🌐
TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
🌐
Cyber security best practices for managing email
🌐
Cyber security best practices for managing email (ITSAP.60.002)
🌐
Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager
📡
Feds Seize $6.4M VerifTools Fake-ID Marketplace, but Operators Relaunch on New Domain
📡
Can Your Security Stack See ChatGPT? Why Network Visibility Matters
📡
Empowering Rural Education: Sophos India’s Volunteering Initiative
📡
WordPress: vulnerabilities in plugins and themes | Kaspersky official blog
📡
Microsoft fixes bug behind Windows certificate enrollment errors