71Articles
10Categories
2025-09-17Date
🚨
Malicious Listener for Ivanti Endpoint Mobile Management SystemsMalware Analysis at a Glance Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) obtained two sets of malware from an organization compromised by cyber threat actors exploiting CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile (Ivanti EPM…
KEV
🐛
Linux Kernel KSMBD Flaw Lets Remote Attackers Drain Server Resources
🐛
Chaos Mesh Critical Vulnerabilities Expose Kubernetes Clusters to Takeover
🐛
Apple Patches 0-Day Vulnerabilities in Older iPhones and iPads
🐛
Apple patches critical zero-day in ImageIO amid reports of targeted exploits
⚠️
BitPixie Windows Boot Manager Flaw Lets Hackers Escalate Privileges
⚠️
Supply Chain Attack “Shai-Halud” Targets 477 NPM Packages
⚠️
Shai-Hulud Worm - A Self Propagating Supply Chain Threat
⚠️
New FileFix Steganography Campaign Spreads StealC Malware
⚠️
5 steps for deploying agentic AI red teaming
⚠️
PureHVNC RAT Developers Exploit GitHub to Spread Pure Malware Source Code
⚠️
Adtech Abused by Threat Actors to Spread Malicious Advertisements
⚠️
Kubernetes C# Client Flaw Exposes API Server to MiTM Attacks
⚠️
Board Priority But Lack of Access & CISO Pressure, 360 Privacy and Pentera Interviews ... - BSW #413
⚠️
Hackers Exploit AdaptixC2, an Emerging Open-Source C2 Tool
⚠️
Hacking Electronic Safes
⚠️
China-Aligned TA415 Exploits Google Sheets & Calendar for C2
⚠️
Microsoft and Cloudflare execute ‘rugpull’ on massive phishing empire
⚠️
Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service
⚠️
Check Point acquires Lakera to build a unified AI security stack
⚠️
ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
⚠️
Irregular raises $80 million to secure frontier AI models
📋
Apple releases iOS 15.8.5 security update for 10-year old iPhone 6s
📢
DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM
📢
Atlassian security advisory (AV25-596)
📢
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts
📢
HPE security advisory (AV25-597)
📢
Microsoft Edge security advisory (AV25-599)
📢
Jenkins security advisory (AV25-598)
🔥
Wave of 40,000+ Cyberattacks Target API Environments
🔥
World’s Biggest Hacker Forum Admin Gets Resentenced to Serve Three More Years
🔥
Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims
🔥
BreachForums Owner Sent to Prison in Resentencing
🔥
GOLD SALEM’s Warlock operation joins busy ransomware landscape
🔥
Founder of One of World’s Largest Hacker Forums(BreachForums) Resentenced to Three Years in Prison
🔥
How LLMs can be compromised in 2025 | Kaspersky official blog
🔥
SonicWall warns customers to reset credentials after breach
🔥
Jaguar Land Rover to pause production for third week due to cyberattack
🔥
VC giant Insight Partners warns thousands after ransomware breach
🔥
Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc
🕵️
ISC Stormcast For Wednesday, September 17th, 2025 https://isc.sans.edu/podcastdetail/9616, (Wed, Sep 17th)
🕵️
Python-Based “XillenStealer” Campaign Targets Windows Users’ Sensitive Data
🕵️
RaccoonO365 Phishing Service Disrupted, Leader Identified
🕵️
Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit
🕵️
Microsoft Takes Down 300+ Websites Behind RaccoonO365 Phishing Scheme
🕵️
Palo Alto Networks and Microsoft Featured in MITRE ATT&CK Evaluations 2026
🕵️
Google Play Flooded With 224 Malicious Apps, 38 Million Downloads Deliver Malware
🕵️
Decade-Old Pixie Dust Wi-Fi Hack Still Impacts Many Devices
🕵️
Securing the Future of AI
🕵️
Scalekit Raises $5.5 Million to Secure AI Agent Authentication
🕵️
Hackerangriff auf HEM expert
🕵️
New Magecart Attack Injects Malicious JavaScript to Steal Payment Data
🕵️
Details Emerge on Chinese Hacking Operation Impersonating US Lawmaker
🕵️
BeaverTail Malware Delivered Through Malicious Repositories Targets Retailers
🕵️
Microsoft OneDrive Auto-Sync Flaw Leaks Enterprise Secrets from SharePoint Online
🕵️
RegScale Raises $30 Million for GRC Platform
🕵️
MuddyWater Deploys Custom Multi-Stage Malware Hidden Behind Cloudflare
🕵️
What are You Working on Wednesday
🕵️
Satori Threat Intelligence Alert: SlopAds Covers Fraud with Layers of Obfuscation - HUMAN Security
🕵️
Irregular Raises $80 Million for AI Security Testing Lab
🕵️
From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques
🕵️
Virtual Event Today: Attack Surface Management Summit
🕵️
New in Syteca Release 7.21: Agentless Access, Sensitive Data Masking, and Smooth Session Playback
🕵️
News alert: Syteca release 7.21 enhances privacy, access and oversight with powerful new tools
🌐
CTRL-Z DLL Hooking, (Wed, Sep 17th)
🌐
From mischief to malware: ICO warns schools about student hackers
🎙️
Smashing Security podcast #435: Lights! Camera! Hacktion!
📡
RaccoonO365 Phishing Network Shut Down After Microsoft and Cloudflare Disrupt 338 Domains
📡
Rethinking AI Data Security: A Buyer's Guide
📡
From Quantum Hacks to AI Defenses – Expert Guide to Building Unbreakable Cyber Resilience
📡
Microsoft: Office 2016 and Office 2019 reach end of support next month