80Articles
8Categories
2025-10-03Date
🚨
Vulnerability Report - September 2025submitted by cm0002 to cybersecurity 1 points | 0 comments Introduction This vulnerability report has been generated using data aggregated on Vulnerability-Lookup , with contributions from the platform’s community. It highlights the most frequently mentioned vulnerability for Sep…
KEV
🐛
Cl0p-linked threat actors target Oracle E-Business Suite in extortion campaign
🐛
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild
KEV
🐛
Hackers Exploit Grafana Vulnerability Allowing Arbitrary File Reads
🐛
Newly-discovered threat group hijacking IIS servers for SEO fraud, warns Cisco Talos
🐛
CVE-2025-59489 MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability
⚠️
New Obex Tools Blocks Runtime Loading of EDR Dynamic Libraries
⚠️
HomeRefill - 187,457 breached accounts
⚠️
PoC Released for VMware Workstation Guest-to-Host Escape Vulnerability
⚠️
That CISO job offer could be a ‘pig-butchering’ scam
⚠️
Oracle Confirms Hackers Target E-Business Suite Data in Extortion Campaigns
⚠️
IIS Servers Compromised by Chinese Hackers for SEO Manipulation
⚠️
Threat Actors Imitate Popular Brands in New Malware Distribution Campaigns
⚠️
State-aligned cyber attacks "a strategic threat to European Union's public institutions and critical infrastructure"
⚠️
State-aligned cyber attacks "a strategic threat to European Union's public institutions and critical infrastructure"
⚠️
WhatsApp Exploited to Spread SORVEPOTEL Malware on Windows Systems
⚠️
Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks
⚠️
Organizations Warned of Exploited Meteobridge Vulnerability
⚠️
Unauthenticated RCE Flaw Patched in DrayTek Routers
⚠️
Attacks on critical infrastructure, espionage, IP theft, malign influence, transnational repression: China's cyber attacks "second to none", represent biggest cyber threat to Canada, report warns
⚠️
Attacks on critical infrastructure, espionage, IP theft, malign influence, transnational repression: China's cyber attacks "second to none", represent biggest cyber threat to Canada, report warns
⚠️
DrayOS Router Flaw Allows Remote Code Execution by Attackers
⚠️
Hacking group claims theft of 1 billion records from Salesforce customer databases
⚠️
Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability - SecurityWeek
⚠️
CommetJacking attack tricks Comet browser into stealing emails
⚠️
ShinyHunters launches Salesforce data leak site to extort 39 victims
⚠️
Japanese beer giant Asahi confirms ransomware attack
⚠️
Do AI-designed proteins create a biosecurity vulnerability?
📢
Cybersecurity Today: Red Hat Breach, CLOP Targets Oracle, and CISA Cuts Critical Support
📢
Oneleet Raises $33 Million for Security Compliance Platform
📢
Japan: Brewer Asahi suspends domestic operations after cyberattack disrupts ordering and shipping
📢
Japan: Brewer Asahi suspends domestic operations after cyberattack disrupts ordering and shipping
📢
Microsoft Edge security advisory (AV25-639)
📢
Top 10 Best Supply Chain Risk Management Solutions in 2025
🔥
Latest Pilot Jobs - 118,864 breached accounts
🔥
GhostSocks Malware-as-a-Service Turns Compromised Devices into Proxies for Threat Actors
🔥
Oracle links Clop extortion attacks to July 2025 vulnerabilities
🔥
Renault UK Customer Records Stolen in Third-Party Breach
🔥
Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL
🔥
766,000 Impacted by Data Breach at Dealership Software Provider Motility - SecurityWeek
🔥
Red Hat confirms security incident after hackers breach GitLab instance
🔥
In Other News: PQC Adoption, New Android Spyware, FEMA Data Breach
🔥
Japan running dry: Ransomware attack leaves nation days away from Asahi beer shortage
🔥
Renault and Dacia UK warn of data breach impacting customers
🔥
Top 10 Best End-to-End Threat Intelligence Companies in 2025
🔥
Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users
🕵️
ISC Stormcast For Friday, October 3rd, 2025 https://isc.sans.edu/podcastdetail/9640, (Fri, Oct 3rd)
🕵️
Confucius Hacker Group Weaponizes Documents to Infect Windows Systems with AnonDoor Malware
🕵️
Microsoft Defender Bug Sparks Numerous False BIOS Security Alerts
🕵️
Hundreds of Free VPN Apps Expose Android and iOS Users’ Personal Data
🕵️
Signal Introduces Hybrid Post-Quantum Ratchet to Strengthen Security
🕵️
Red Hat Confirms GitLab Instance Hack, Data Theft
🕵️
Rhadamanthys Stealer Offered on Dark Web for $299–$499
🕵️
Chrome 141 and Firefox 143 Patches Fix High-Severity Vulnerabilities
🕵️
New ‘Point-and-Click’ Phishing Kit Evades Security Filters to Deliver Malicious Payloads
🕵️
MokN Raises $3 Million for Phish-Back Solution
🕵️
New "Cavalry Werewolf" Attack Hits Russian Agencies with FoalShell and StallionRAT
🕵️
SideWinder Hacker Group Targets Users with Fake Outlook/Zimbra Portals to Steal Login Credentials
🕵️
New XWorm V6 Variant Embeds Malicious Code into Trusted Windows Applications
🕵️
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown
🕵️
Threat Actors Pose as Government Officials to Attack Organizations with StallionRAT
🕵️
Clop extortion emails claim theft of Oracle E-Business Suite data
🕵️
Your KnowBe4 Fresh Content Updates from September 2025
🕵️
New Android Spyware Targeting Users by Imitating Signal and ToTok Apps
🕵️
Le Tour du Hack 2025 talks now available on PeerTube!
🕵️
Report: Deepfake Attacks Have Targeted Nearly Two-Thirds of Organizations
🕵️
Rhadamanthys Stealer Evolves: Adds Device Fingerprinting, PNG Steganography Payloads
🕵️
Off-Topic Friday
🕵️
North Korean Hackers Target Job Seekers With Social Engineering Tricks
🕵️
Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer
🕵️
Friday Squid Blogging: Squid Overfishing in the Southwest Atlantic
🕵️
Ratboi, Clop, Oracle, svgs, Impact Solutions, The Pentagon, Open AI, Josh Marpet... - SWN #517
🌐
Product Walkthrough: How Passwork 7 Addresses Complexity of Enterprise Security
📡
Gmail business users can now send encrypted emails to anyone
📡
Presenting AI to the Board as a CISO? Here’s a Template.
📡
Phoenix: Rowhammer that works on DDR5 | Kaspersky official blog
📡
Signal adds new cryptographic defense against quantum attacks
📡
Google confirms Android dev verification will have free and paid tiers, no public list of devs
📡
Opera wants you to pay $19.90 per month for its new AI browser
📡
Manufacturing under fire: Strengthening cyber-defenses amid surging threats