197Articles
7Categories
2025-09-09Date
πŸ›
New Exploitation Method Discovered for Linux Kernel Use-After-Free Vulnerability
πŸ›
SessionReaper Vulnerability Puts Magento & Adobe Commerce Sites in Hacker Crosshairs
πŸ›
Ivanti Endpoint Manager Vulnerabilities Allow Remote Code Execution by Attackers
πŸ›
FortiDDoS Vulnerability Lets Hackers Execute Unauthorized OS Commands
πŸ›
Adobe patches critical SessionReaper flaw in Magento eCommerce platform
πŸ›
CVE-2025-49734 PowerShell Direct Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53797 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53798 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-54095 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-54096 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-54097 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-54099 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54101 Windows SMB Client Remote Code Execution Vulnerability
πŸ›
CVE-2025-54102 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54106 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-54110 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54111 Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54894 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54895 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54896 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54897 Microsoft SharePoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-54898 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54899 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54902 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54903 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54904 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54905 Microsoft Word Information Disclosure Vulnerability
πŸ›
CVE-2025-54906 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-54907 Microsoft Office Visio Remote Code Execution Vulnerability
πŸ›
CVE-2025-54908 Microsoft PowerPoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-54913 Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54916 Windows NTFS Remote Code Execution Vulnerability
πŸ›
CVE-2025-54918 Windows NTLM Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54919 Windows Graphics Component Remote Code Execution Vulnerability
πŸ›
CVE-2025-55223 DirectX Graphics Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2025-55225 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-55226 Graphics Kernel Remote Code Execution Vulnerability
πŸ›
CVE-2025-55228 Windows Graphics Component Remote Code Execution Vulnerability
πŸ›
CVE-2025-55232 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
πŸ›
CVE-2025-55236 Graphics Kernel Remote Code Execution Vulnerability
πŸ›
CVE-2025-55245 Xbox Gaming Services Elevation of Privilege Vulnerability
πŸ›
CVE-2025-55243 Microsoft OfficePlus Spoofing Vulnerability
πŸ›
CVE-2025-55316 Azure Arc Elevation of Privilege Vulnerability
πŸ›
CVE-2025-55317 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49692 Azure Connected Machine Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47997 Microsoft SQL Server Information Disclosure Vulnerability
πŸ›
CVE-2025-53796 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53799 Windows Imaging Component Information Disclosure Vulnerability
πŸ›
CVE-2025-53800 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53801 Microsoft DWM Core Library Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53802 Windows Bluetooth Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53803 Windows Kernel Memory Information Disclosure Vulnerability
πŸ›
CVE-2025-53804 Windows Kernel-Mode Driver Information Disclosure Vulnerability
πŸ›
CVE-2025-53805 HTTP.sys Denial of Service Vulnerability
πŸ›
CVE-2025-53806 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-53807 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53808 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-53809 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
πŸ›
CVE-2025-53810 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54091 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54092 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54093 Windows TCP/IP Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54094 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54098 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54103 Windows Management Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54104 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54105 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54107 MapUrlToZone Security Feature Bypass Vulnerability
πŸ›
CVE-2025-54108 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54109 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54112 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54113 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-54114 Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability
πŸ›
CVE-2025-54115 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54116 Windows MultiPoint Services Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54900 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-54901 Microsoft Excel Information Disclosure Vulnerability
πŸ›
CVE-2025-54910 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-54911 Windows BitLocker Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54912 Windows BitLocker Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54915 Windows Defender Firewall Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-54917 MapUrlToZone Security Feature Bypass Vulnerability
πŸ›
CVE-2025-55224 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2025-55227 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2025-55234 Windows SMB Elevation of Privilege Vulnerability
πŸ›
CVE-2024-21907 VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json
⚠️
AI powered autonomous ransomware campaigns are coming, say experts
⚠️
Qualys Confirms Cyberattack Campaign Targeting Salesforce via Salesloft and Drift
⚠️
5 ways CISOs are experimenting with AI
⚠️
Windows Defender Vulnerability Lets Hackers Hijack and Disable Services Using Symbolic Links
⚠️
Dynatrace Data Breach Exposes Customer Information Stored in Salesforce
⚠️
71% of CISOs hit with third-party security incident this year
⚠️
MostereRAT Exploits AnyDesk and TightVNC for Remote Access on Windows Systems
⚠️
New Malware Exploits Exposed Docker APIs to Gain Persistent Root SSH Access
⚠️
Limitations and Liabilities of LLM Coding - Ted Shorter, Seemant Sehgal - ASW #347
⚠️
New Cyber Attack Exploits DeskSoft to Spread Malware via RDP Command Execution
⚠️
Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations
⚠️
From MostereRAT to ClickFix: New Malware Campaigns Highlight Rising AI and Phishing Risks
⚠️
TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs
⚠️
SAP Security Patch Day Addresses 21 Vulnerabilities, 4 Classified as Critical
⚠️
When AI nukes your database: The dark side of vibe coding
⚠️
U.S. Cracks Down on Scam Networks in Southeast Asia Draining Billions
⚠️
Massive npm supply chain attack hits 18 popular packages with 2B weekly downloads
⚠️
Smart GPUGate malware exploits GitHub and Google Ads for evasive targeting
⚠️
Phishing kit Salty2FA washes away confidence in MFA
⚠️
SAP Patches Critical NetWeaver Vulnerabilities
⚠️
Exposed Docker APIs Likely Exploited to Build Botnet
⚠️
Zoom Security Update Fixes Vulnerabilities in Windows Client and Workplace Platform
⚠️
Multiple Vulnerabilities Discovered in Ivanti Connect Secure, Policy Secure, and ZTA Gateways
⚠️
CISA Releases Fourteen Industrial Control Systems Advisories
⚠️
News alert: Link11 tracks 225% surge in DDoS attacks, record-breaking scale and duration
⚠️
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
⚠️
Turning Data Into Defense: The Metrics That Count
⚠️
Adobe Patches Critical ColdFusion and Commerce Vulnerabilities
⚠️
Microsoft September 2025 Patch Tuesday – 81 Vulnerabilities and 2 Zero Days Fixed
⚠️
Microsoft Patches 86 Vulnerabilities
⚠️
Microsoft Patch Tuesday September 2025, (Tue, Sep 9th)
⚠️
Top 10 Best Internal Network Penetration Testing Providers in 2025
⚠️
AI Bombs: The New Zero-Day? 🚨
⚠️
Microsoft Patch Tuesday, September 2025 Edition
KEV
⚠️
CISOs Hate This: The 10% Patch Rule Explained
⚠️
Critical Patches Issued for Microsoft Products, September 09, 2025
⚠️
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
⚠️
Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution
πŸ“’
GitHub Actions missbraucht
πŸ“’
SAP security advisory – September 2025 monthly rollup (AV25-576)
πŸ“’
HPE security advisory (AV25-577)
πŸ“’
[Control systems] Schneider Electric security advisory (AV25-578)
πŸ“’
[Control systems] Siemens security advisory (AV25-579)
πŸ“’
US charges admin of LockerGoga, MegaCortex, Nefilim ransomware
πŸ“’
Fortinet security advisory (AV25-580)
πŸ“’
Ivanti security advisory (AV25-581)
πŸ“’
Microsoft security advisory – September 2025 monthly rollup (AV25-582)
πŸ”₯
18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security
πŸ”₯
Largest NPM Compromise in History(Packages With Over 2.6 Billion Total Weekly Downloads) - Supply Chain Attack
πŸ”₯
Chinese Hackers Salt Typhoon and UNC4841 Team Up to Breach Critical Infrastructure
πŸ”₯
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack
πŸ”₯
Popular npm packages compromised | Kaspersky official blog
πŸ”₯
Jaguar Land Rover Halts Operations Longer Due to Cyberattack Impact
πŸ”₯
Plex Urges Password Resets Following Data Breach
πŸ”₯
Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
πŸ”₯
How Leading CISOs are Getting Budget Approval
πŸ”₯
160,000 Impacted by Wayne Memorial Hospital Data Breach
πŸ”₯
Plex Media Server: Important Notice of Security Incident
πŸ”₯
Ransomware Losses Climb as AI Pushes Phishing to New Heights
πŸ”₯
Plex urges users to change passwords after data breach
πŸ”₯
Report: Addressing cybersecurity burnout in 2025
πŸ”₯
The AI Fix #67: Will Smith’s AI crowd scandal, and gullible agents fall for scams
πŸ”₯
npm debug and chalk packages compromised
πŸ”₯
Georgia Hospital Notifying 163,000 of 2024 Ransomware Hack
πŸ”₯
Hackers hide behind Tor in exposed Docker API breaches
πŸ”₯
Preventing business disruption and building cyber-resilience with MDR
πŸ•΅οΈ
45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage
πŸ•΅οΈ
LookCam App Users Exposed to Critical Security Risks
πŸ•΅οΈ
ISC Stormcast For Tuesday, September 9th, 2025 https://isc.sans.edu/podcastdetail/9604, (Tue, Sep 9th)
πŸ•΅οΈ
Maduro Hails Huawei Mate X6 Gift From China as β€˜Unhackable’ by U.S.
πŸ•΅οΈ
Hackers Hijack 18 Popular npm Packages Downloaded Over 2 Billion Times Weekly
πŸ•΅οΈ
APT37 Deploys New Rust and Python Malware Targeting Windows Systems
πŸ•΅οΈ
Hacker ΓΌbernehmen Youtube-KanΓ€le von Arte
πŸ•΅οΈ
Ex-WhatsApp cybersecurity head says Meta endangered billions of users in new suit
πŸ•΅οΈ
Ex-WhatsApp cybersecurity head says Meta endangered billions of users in new suit
πŸ•΅οΈ
OrangeCon 2025
πŸ•΅οΈ
SentinelOne to Acquire Observo AI in $225 Million Deal
πŸ•΅οΈ
Graphite, the Israeli spyware acquired by ICE
πŸ•΅οΈ
Graphite, the Israeli spyware acquired by ICE
πŸ•΅οΈ
Mitsubishi Electric to Acquire Nozomi Networks for Nearly $1 Billion
πŸ•΅οΈ
SpamGPT: New AI Email Attack Tool Fueling Massive Phishing Operations
πŸ•΅οΈ
New Cryptanalysis of the Fiat-Shamir Protocol
πŸ•΅οΈ
How a Single Faulty Windows Driver Can Crash Your System and Cause Blue Screen of Death
πŸ•΅οΈ
RatOn Hijacks Bank Account to Launch Automated Money Transfers
πŸ•΅οΈ
Aembit Named to Fast Company’s Seventh-Annual List of the 100 Best Workplaces for Innovators
πŸ•΅οΈ
Data from Police Body Camera Apps Routed to Chinese Cloud Servers Over TLS Port 9091
πŸ•΅οΈ
Ex-WhatsApp Security Chief Sues Meta Over Vulnerabilities, Retaliation
πŸ•΅οΈ
Phishing Alert: Kimusky Hackers Masquerade as Tax Authority with β€˜September Tax Return Due Date’ Email
πŸ•΅οΈ
Microsoft to Add New AI-Powered Actions in File Explorer
πŸ•΅οΈ
Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure
πŸ•΅οΈ
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
πŸ•΅οΈ
AppSec Meets AI: What Could Possibly Go Wrong? πŸ’₯
πŸ•΅οΈ
When Security Fails, Why Does Software Still Survive?
πŸ•΅οΈ
45 New Domains Linked to Salt Typhoon, UNC4841
πŸ•΅οΈ
Surge in networks scans targeting Cisco ASA devices raise concerns
πŸ•΅οΈ
The One Mistake That Breaks Container Security πŸ›‘
πŸ•΅οΈ
CyberheistNews Vol 15 #36 One of the Biggest Mysteries in Cybersecurity: Why Don't We Demand This?
πŸ•΅οΈ
BlackHat 2025: Why Everyone’s Talking About Agentic AI
πŸ•΅οΈ
Hellhounds, Anthropic, iCloud, NPM, gitforked, notdoor, TOR, Signal, Josh Marpet - SWN #510
πŸ•΅οΈ
Security Operations Under Fire Inside Black Hat's NOC
🌐
RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities
πŸ“‘
[Webinar] Shadow AI Agents Multiply Fast β€” Learn How to Detect and Control Them
πŸ“‘
Microsoft testing new AI features in Windows 11 File Explorer
πŸ“‘
SAP fixes maximum severity NetWeaver command execution flaw
πŸ“‘
Microsoft: Anti-spam bug blocks links in Exchange Online, Teams
πŸ“‘
New enhancements to the Sophos AI Assistant
πŸ“‘
How External Attack Surface Management helps enterprises manage cyber risk
πŸ“‘
Windows 11 KB5065426 & KB5065431 cumulative updates released
πŸ“‘
Kosovo hacker pleads guilty to running BlackDB cybercrime marketplace
πŸ“‘
Windows 10 KB5065429 update includes 14 changes and fixes
πŸ“‘
U.S. sanctions cyber scammers who stole billions from Americans