94Articles
9Categories
2025-09-24Date
🐛
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability
🐛
CISA Issues Alert on Actively Exploited Google Chrome 0-Day Vulnerability
KEV
🐛
Libraesva Email Security Gateway Vulnerability Exploited by Nation-State Hackers
🐛
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials
🐛
Salesforce CLI Installer Flaw Lets Attackers Run Code and Gain SYSTEM-Level Access
🐛
OnePlus OxygenOS Vulnerability Lets Apps Access SMS Data Without User Permission
🐛
Attackers Exploit BMC Firmware Vulnerabilities to Bypass Signature Verification
🐛
Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models
🐛
OnePlus leaves researchers on read over Android bug that exposes texts: Rapid7 warns flaw could let any app peek at your SMS, but smartphone vendor won't pick up
🐛
CVE-2025-55322 OmniParser Remote Code Execution Vulnerability
⚠️
Application Security Posture Management – ein Kaufratgeber
⚠️
5 questions CISOs should ask vendors
⚠️
Rearchitecting Systems for Privacy as AI Agents Force You to Rethink Security - Guilla... - BSW #414
⚠️
Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts
⚠️
CISA Reveals Hackers Breached U.S. Federal Agency via GeoServer RCE Flaw
⚠️
Macs go phishing as GitHub impostors drop Atomic stealer
⚠️
What I learned extending zero trust to the storage layer
⚠️
Chromium-Based Browsers in Windows Domains Vulnerable to Arbitrary Extension Loads
⚠️
GeoServer Flaw Exploited in US Federal Agency Hack
⚠️
New YiBackdoor Malware Shares Major Code Overlaps with IcedID and Latrodectus
⚠️
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer Attacks
KEV
⚠️
CISA says hackers breached federal agency using GeoServer exploit
⚠️
Attackers Use Domain Fronting to Tunnel Malicious Traffic via Google Meet, YouTube and Chrome Update Servers
⚠️
Multiple Apps on Google’s Firebase Platform Exposing Sensitive Data
⚠️
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
⚠️
Police seizes $439 million stolen by cybercrime rings worldwide
⚠️
Exploit Attempts Against Older Hikvision Camera Vulnerability, (Wed, Sep 24th)
⚠️
Unpatched flaw in OnePlus phones lets rogue apps text messages
⚠️
Cisco warns of IOS zero-day vulnerability exploited in attacks
⚠️
Retail at risk: How one alert uncovered a persistent cyberthreat​​
⚠️
Decoupled SIEM: Where I Think We Are Now?
⚠️
Smashing Security podcast #436: The €600,000 gold heist, powered by ransomware
📋
Chrome High-severity Flaws Expose Sensitive Data, Trigger System Crashes
📋
SonicWall Issues Emergency Patch to Remove ‘OVERSTEP’ Rootkit Malware on SMA Devices
📋
SonicWall Updates SMA 100 Appliances to Remove Overstep Malware
📢
Google Chrome security advisory (AV25-615)
📢
Drupal security advisory (AV25-617)
📢
Cisco security advisory (AV25-616)
📢
HPE security advisory (AV25-618)
🔥
GitHub's NPM Lockdown, Deep Fake Threats, and Yellowknife's Cyber Incident: Cybersecurity Today
🔥
Jaguar Land Rover Factory Reopening Delayed After Cyber Attack
🔥
Iranian Hackers Use Fake Job Lures to Breach Europe’s Critical Industries
🔥
Iranian Hackers Use Fake Job Lures to Breach Europe’s Critical Industries
🔥
Bouygues Telecom - 5,685,771 breached accounts
🔥
Allianz: Cyberabwehr hilft – Hacker suchen leichtere Beute
🔥
Nach Cyberangriff: IT-Störung in Hoppegarten dauert an
🔥
The Ransomware Speed Crisis
🔥
EV Charging Provider Confirm Data Breach - Customers Personal Data Exposed
🔥
European Airport Cyberattack Linked to Obscure Ransomware, Suspect Arrested
🔥
UK police arrest man linked to ransomware attack that caused airport disruptions in Europe
🔥
New YiBackdoor Allows Attackers to Execute Arbitrary Commands and Exfiltrate Sensitive Data from Hacked Systems
🔥
UK Police Arrest Suspect Tied to Ransomware Attack on European Airports
🔥
UK arrests suspect for RTX ransomware attack causing airport disruptions
🔥
Attackers Bypass EDR by Using In-Memory PE Loaders Delivered via Malicious Downloads
🔥
Hackers Target Casino Operator Boyd Gaming
🔥
Obscura, an obscure new ransomware variant
🔥
INC ransomware: what you need to know
🔥
This Is How Your LLM Gets Compromised
🔥
Domino Effect: How One Vendor's AI App Breach Toppled Giants
🕵️
ISC Stormcast For Wednesday, September 24th, 2025 https://isc.sans.edu/podcastdetail/9626, (Wed, Sep 24th)
🕵️
New “YiBackdoor” Malware Lets Hackers Run Commands and Steal Data
🕵️
ShadowV2 Botnet Infects AWS Docker Containers to Launch DDoS Campaign
🕵️
Kali Linux 2025.3 Launches With Fresh Features and 10 New Pentesting Tools
🕵️
North Korean IT Worker Gains Access to Organization’s Network Through Innocent Job Application
🕵️
RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders
🕵️
Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps
🕵️
GitHub Boosting Security in Response to NPM Supply Chain Attacks
🕵️
Banking Trojans Targeting Android Users Disguise as Government and Trusted Payment Apps
🕵️
US Disrupts Massive Cell Phone Array in New York
🕵️
How One Bad Password Ended a 158-Year-Old Business
🕵️
Russian Disinformation Campaign Targets Moldova’s Upcoming Elections
🕵️
NPM package caught using QR Code to fetch cookie-stealing malware
🕵️
AI vs. AI: Detecting an AI-obfuscated phishing campaign
🕵️
Weaponized Malware: GitHub Hosts Malware from Malwarebytes, LastPass, Citibank, SentinelOne, and More
🕵️
ShadowV2 Botnet Infects AWS Docker Containers to Launch DDoS Campaign
🕵️
Google: Brickstone malware used to steal U.S. orgs' data for over a year
🕵️
What are You Working on Wednesday
🕵️
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
🕵️
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
🕵️
Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike
🕵️
Google: Brickstorm malware used to steal U.S. orgs' data for over a year
🕵️
Accelerating adoption of AI for cybersecurity at DEF CON 33
🌐
QR codes become the vehicle for malware in new technique
🌐
New Supermicro BMC flaws can create persistent backdoors
🎙️
Risky Business #808 -- Insane megabug in Entra left all tenants exposed
📡
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
📡
GitHub notifications abused to impersonate Y Combinator for crypto theft
📡
PyPI urges users to reset credentials after new phishing attacks
📡
Lovense ignored app vulnerabilities for eight years | Kaspersky official blog
📡
Step into the future: The full AI Stage at TechCrunch Disrupt 2025
📡
Helping OT Organizations to Establish Defensible Architecture and More Resilient Operations
📡
Kali Linux 2025.3 released with 10 new tools, wifi enhancements
📡
Neon, the No. 2 social app on the Apple App Store, pays users to record their phone calls and sells data to AI firms
📡
OpenAI is testing a new GPT-5-based AI agent "GPT-Alpha"