87Articles
10Categories
2025-09-23Date
🚨
CISA Releases Advisory on Lessons Learned from an Incident Response EngagementToday, CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool.  This advis…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-10585 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber ac…
KEV
🐛
Libraesva ESG Vulnerability Allows Attackers to Execute Malicious Commands
🐛
SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation
🐛
SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw
🐛
SolarWinds Makes Third Attempt at Patching Exploited Vulnerability
🐛
BYOVD to the next level (part 1) — exploiting a vulnerable driver (CVE-2025-8061)
🐛
SolarWinds fixes Web Help Desk patch bypass for actively exploited flaw — again
KEV
⚠️
Threat Actors with Fake Job Lures Attacking Job Seekers to Deploy Advanced Malware
⚠️
Hackers Exploit GitHub Notifications to Launch Phishing Attacks
⚠️
Hackers Using SVG Files to Deliver Malicious Payloads
⚠️
6 novel ways to use AI in cybersecurity
⚠️
The CISO’s guide to rolling out generative AI at scale
⚠️
Lectora Desktop and Online XSS Vulnerability Enables JavaScript Injection
⚠️
GitHub Introduces npm Security with Stronger Authentication and Trusted Publishing
⚠️
Apple’s New Memory Integrity Enforcement
⚠️
Top 25 MCP Vulnerabilities Reveal How AI Agents Can Be Exploited
⚠️
Automaker giant Stellantis confirms data breach after Salesforce hack
⚠️
ShadowV2 turns DDoS into a cloud-native subscription service
KEV
⚠️
Lean Teams, Higher Stakes: Why CISOs Must Rethink Incident Remediation
⚠️
ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service
⚠️
SpyCloud Report: 2/3 Orgs Extremely Concerned About Identity Attacks Yet Major Blind Spots Persist
⚠️
SolarWinds releases third patch to fix Web Help Desk RCE bug
⚠️
Police dismantles crypto fraud ring linked to €100 million in losses
⚠️
CISA says hackers breached federal agency using GeoServer exploit
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
News alert: SpyCloud report finds security teams overconfident as identity exposures fuel ransomware
⚠️
Libraesva ESG issues emergency fix for bug exploited by state hackers
⚠️
Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack
⚠️
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries
⚠️
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security
⚠️
Widespread Supply Chain Compromise Impacting npm Ecosystem
⚠️
Boyd Gaming discloses data breach after suffering a cyberattack
⚠️
HIBP Demo: Querying the API, and the Free Test Key!
⚠️
A Vulnerability in SolarWinds Web Help Desk Could Allow for Remote Code Execution
📋
SonicWall releases SMA100 firmware update to wipe rootkit malware
📢
Microsoft Publishes Guide for Certificate-Based Authentication in Windows Admin Center
📢
SonicWall security advisory (AV25-612)
📢
SolarWinds security advisory (AV25-613)
📢
Microsoft Purview delivered 30% reduction in data breach likelihood
📢
Citrix security advisory (AV25-614)
📢
CISA Announces Steve Casapulla as Executive Assistant Director for Infrastructure Security
🔥
European Airport Operations Disrupted by Ransomware
🔥
Automotive Titan Stellantis Discloses Data Breach
🔥
NPM package caught using QR Code to fetch cookie-stealing malware
🔥
Beware of Fake Online Speedtest Apps with Hidden JavaScript Code
🔥
Zloader Malware Used as Gateway for Ransomware Deployment in Corporate Networks
🔥
New npm Malware Steals Browser Passwords via Steganographic QR Code
🔥
GitHub tightens npm security with mandatory 2FA, access tokens
🔥
Humber NHS board apologises for NRS Healthcare data breach
🔥
Threat Actors Breach Enterprise Infrastructure Within 18 Minutes of Initial Access
🔥
European airports still dealing with disruptions days after ransomware attack
🔥
Jaguar Land Rover to pause production until next week – at least
🔥
Jaguar Land Rover Says Shutdown Will Continue Until at Least Oct 1 After Cyberattack
🕵️
ISC Stormcast For Tuesday, September 23rd, 2025 https://isc.sans.edu/podcastdetail/9624, (Tue, Sep 23rd)
🕵️
Windows 11 24H2 KB5064081 Update Causes Video Playback Issues
🕵️
Nimbus Manticore Targets Defense and Telecom Industries with New Malware Attack
🕵️
Massive 22.2 Tbps DDoS Attack Sets New World Record
🕵️
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells
🕵️
Scattered Spider Suspect Arrested in US
🕵️
Russia Leveraging Cyber-Attacks as a Strategic Weapon Against Key Industries in Major Nations
🕵️
Hackers Abuse IMDS Service for Cloud Initial Access
🕵️
ShadowV2 DDoS Service Lets Customers Self-Manage Attacks
🕵️
All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher
🕵️
Nightgridcybersecurity.
🕵️
Unit 221B Raises $5 Million for Threat Intel Aiding Hacker Arrests
🕵️
Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content
🕵️
Malicious GitHub pages lure MacOS users into installing Atomic infostealer - Help Net Security
🕵️
U.S. Secret Service Shuts Down 300 SIM Servers and 100K SIM Cards Disabling Cell Towers
🕵️
AsyncRAT spread through malicious SVG files imitating web portals
🕵️
Design Errors in Entra ID, Design Defenses in iOS, Design Difficulties in DeepSeek - ASW #349
🕵️
New EDR-Freeze tool uses Windows WER to suspend security software
🕵️
22.2 Tbps DDoS Attack Breaks Internet With New World Record
🕵️
Defy Security Appoints Esteemed Cybersecurity Leader Gary Warzala to Its Board of Directors
🕵️
GitHub tightens npm security with mandatory 2FA, access tokens
🕵️
CyberheistNews Vol 15 #38 Why Does Protecting AI Agents Need To Be Status Quo?
🕵️
Attackers Abuse Google’s AppSheet to Send Phishing Emails
🕵️
Uhura, Collins, Nimbus Manticore, Sonic Wall, Async Rat, Solar Winds, Aaran Leyland.. - SWN #514
🕵️
A Massive Telecom Threat Was Stopped Right As World Leaders Gathered at UN Headquarters in New York
🌐
GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security
🌐
AI-Powered App Exposes User Data, Creates Risk of Supply Chain Attacks
🎙️
The AI Fix #69: How we really use ChatGPT, and will AI agents crash the economy?
📡
[Guest Diary] Distracting the Analyst for Fun and Profit, (Tue, Sep 23rd)
📡
5 ways to streamline Identity Governance with this free tool
📡
Cloudflare mitigates new record-breaking 22.2 Tbps DDoS attack
📡
WhatsApp adds message translation to iPhone and Android apps
📡
U.S. Secret Service Seizes 300 SIM Servers, 100K Cards Threatening U.S. Officials Near UN