89Articles
9Categories
2025-09-10Date
🐛
Patch Tuesday priorities: Vulnerabilities in SAP NetWeaver and Microsoft NTLM and Hyper-V
KEV
🐛
Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts
🐛
SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws
🐛
Critical SAP NetWeaver Flaw Allows Attackers to Execute Arbitrary Code
🐛
Windows BitLocker Flaw Allows Privilege Escalation by Attackers
🐛
Critical Flaws in Microsoft Office Enable Remote Code Execution by Attackers
🐛
Apple CarPlay Vulnerability Allows Remote Code Execution to Gain Root Access
🐛
Cursor’s autorun lets hackers execute arbitrary code
🐛
Adobe Commerce and Magento users: Patch critical SessionReaper flaw now
🐛
CISA Presents Vision for the Common Vulnerabilities and Exposures (CVE) Program
⚠️
OT-Security: Warum der Blick auf Open Source lohnt
⚠️
Gentlemen Ransomware Exploits Drivers and Group Policies to Breach Organizations
⚠️
Workday Data Breach Exposed Customer Data and Case Details
⚠️
Chrome Security Update Fixes Critical Remote Code Execution Flaw
⚠️
iCloud Calendar Invites Disguise New Phishing Campaigns
⚠️
DarkSamural APT Group Deploys LNK/PDF Malware to Steal Critical Information
⚠️
Sophos Wireless Access Point Vulnerability Allows Attackers to Bypass Authentication
⚠️
GONEPOSTAL Malware Exploits Outlook for Stealthy Command-and-Control
⚠️
Highly Popular NPM Packages Poisoned in New Supply Chain Attack
⚠️
Fortinet, Ivanti, Nvidia Release Security Updates
⚠️
Forrester 2026 Budget Planning Guide and BlackHat 2025 Interviews - Jess Burn - BSW #412
⚠️
Lazarus Hackers Abuse Git Symlink Vulnerability in Stealthy Phishing Campaign
⚠️
HackerOne Data Breach, Hackers Illegally Access Salesforce Environment
⚠️
Amp’ed RF BT-AP 111 Bluetooth Access Point Vulnerability Enables Admin Takeover
⚠️
What the Salesloft Drift breaches reveal about 4th-party risk
⚠️
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs
KEV
⚠️
Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety
⚠️
Apple Unveils iPhone Memory Protections to Combat Sophisticated Attacks
⚠️
Kikimora Announces Launch of Kikimora Agent: Accessible AI-Powered Cybersecurity Platform for SME Security
⚠️
Ransomware upstart ‘The Gentlemen’ raises the stakes for OT‑heavy sectors
⚠️
CyberVolk Ransomware Targets Windows Systems in Critical Infrastructure and Research Institutions
⚠️
Apple: iPhone 17 lineup and iPhone Air come with Memory Integrity Enforcement, which provides always-on memory safety protection
⚠️
Jaguar Land Rover confirms data theft after recent cyberattack
⚠️
Can I have a new password, please? The $400M question.
⚠️
How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials
⚠️
Automation or Exploitation? The AI Cybersecurity Dilemma!
⚠️
"Yep, I got pwned. Sorry everyone, very embarrassing."
⚠️
When “Free Data” Becomes Your Biggest Security Threat…
⚠️
Your Hybrid Exchange Server Is Still Wide Open 😱
⚠️
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal
📋
ICS Patch Tuesday: Rockwell Automation Leads With 8 Security Advisories
📋
Microsoft fixes app install issues caused by August Windows updates
📋
Microsoft fixes streaming issues triggered by Windows updates
📋
Multiple Vulnerabilities in GitLab Patched, Blocking DoS and SSRF Attack Vectors
📋
September Patch Tuesday handles 81 CVEs
📢
China-Linked APT41 Hackers Target U.S. Trade Officials Amid 2025 Negotiations
📢
The Time-Saving Guide for Service Providers: Automating vCISO and Compliance Services
📢
GitLab security advisory (AV25-584)
📢
Adobe security advisory (AV25-583)
📢
The Mandate, Mission, and Momentum to lead the CVE Program into the Future belongs to CISA
🔥
US Offers $10 Million Reward for Ukrainian Ransomware Operator
🔥
The State of Ransomware in Education 2025
🔥
Lovesac warns customers their data was breached after suspected RansomHub attack six months ago
🔥
AsyncRAT Leverages Fileless Techniques to Bypass Detection
🔥
Jaguar Land Rover says data stolen in disruptive cyberattack
🔥
Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack
🔥
Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems
🔥
US charges suspected ransomware kingpin, and offers $10 million bounty for his capture
🕵️
ISC Stormcast For Wednesday, September 10th, 2025 https://isc.sans.edu/podcastdetail/9606, (Wed, Sep 10th)
🕵️
GitHub Abused by Kimsuky Hackers Delivering Malware Through LNK Files
🕵️
Hackers Impersonate Google AppSheet in Latest Phishing Campaign
🕵️
Threat Actor’s Self-Deployment of EDR Exposes Their Tools and Workflows
🕵️
MY TAKE: The workflow cadences of GenAI — what’s being lost, what’s starting to be reclaimed
🕵️
Hush Security Emerges Stealth to Eliminate Credential Threats With No-Secrets Platform
🕵️
Google Drive Desktop for Windows Flaw Lets Users Gain Full Access to Others’ Drives
🕵️
Red Access Raises $17 Million for Agentless Security Platform
🕵️
Meta Verified Scam Ads on Facebook Steal User Account Details
🕵️
Geordie Emerges From Stealth With $6.5M for AI Agent Security Platform
🕵️
A look at a P2P camera (LookCam app)
🕵️
Neues Phishing-Framework umgeht Multi-Faktor-Authentifizierung
🕵️
BASE64 Over DNS, (Wed, Sep 10th)
🕵️
The Most Overlooked Cybersecurity Skill in Devs ⚡
🕵️
What are You Working on Wednesday
🕵️
Paved Roads Explained: Security Without the Chaos 🚀
🕵️
Monorepo or Microservices… Does Security Care? 😱
🕵️
Report: Shadow AI Poses an Increasing Risk to Organizations
🕵️
US Senator Wyden pushes FTC to investigate Microsoft for 'gross cybersecurity negligence'
🕵️
Why Developers Hate the Wrong Cybersecurity Metrics ⚡
🌐
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems
🎙️
Smashing Security podcast #434: Whopper Hackers, and AI Whoppers
📡
What’s Your Cybersecurity Maturity?
📡
Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises
📡
Google’s former security leads raise $13M to fight email threats before they reach you
📡
Vibe coding? Meet vibe security
📡
Pixel 10 fights AI fakes with new Android photo verification tech
📡
Cursor AI editor lets repos “autorun” malicious code on devices
📡
Hackers left empty-handed after massive NPM supply-chain attack
📡
Microsoft waives fees for Windows devs publishing to Microsoft Store
📡
DDoS defender targeted in 1.5 Bpps denial-of-service attack