100Articles
9Categories
2025-10-15Date
🚨
CISA Alerts on Rapid7 Velociraptor Flaw Exploited in Ransomware CampaignsThe Cybersecurity and Infrastructure Security Agency has added a critical vulnerability in Rapid7 Velociraptor to its Known Exploited Vulnerabilities catalogue, warning that threat actors are actively exploiting the flaw in ransomware attacks. The vulnerability, tracked as CVE-20…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-54253 Adobe Experience Manager Forms Code Execution Vulnerability This type of vulnerability is a frequent attack vector for malici…
KEV
🐛
October 2025 Patch Tuesday: Holes in Windows Server Update Service and an ancient modem driver
KEV
🐛
Hackers Exploit Windows Remote Access Connection Manager 0-Day in Ongoing Attacks
🐛
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
🐛
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control
🐛
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access
🐛
FortiOS CLI Bypass Flaw Lets Attackers Run Arbitrary System Commands
🐛
FortiPAM & FortiSwitch Manager Flaw Allows Attackers to Bypass Authentication
🐛
Chrome Use-After-Free Flaw Lets Attackers Execute Arbitrary Code
🐛
Windows Agere Modem Driver 0-Day Exploited in Active Privilege Escalation Attacks
KEV
🐛
Adobe Security Update Fixes Critical CVE-2025-49553 Bug
🐛
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
⚠️
Pro-Russian Hacktivists Target Government, Finance and E-Commerce Sites
⚠️
Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws
⚠️
Adobe Patches Critical Vulnerability in Connect Collaboration Suite
⚠️
13 cybersecurity myths organizations need to stop believing
⚠️
TigerJack Hackers Target Developer Marketplaces with 11 Malicious VS Code Extensions
⚠️
Automating Compliance and Risk with Agentic AI as CISOs (R)Evolve - Trevor Horwitz - BSW #417
⚠️
Critical Veeam Backup RCE Flaws Allow Remote Execution of Malicious Code
⚠️
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
KEV
⚠️
Microsoft IIS Exploit Allows Unauthenticated Attackers to Run Arbitrary Code
⚠️
Apple’s Bug Bounty Program
⚠️
Beyond the checklist: Building adaptive GRC frameworks for agentic AI
⚠️
TigerJack’s malicious VSCode extensions mine, steal, and stay hidden
⚠️
How Attackers Bypass Synced Passkeys
⚠️
Introducing MAESTRO: A framework for securing generative and agentic AI
⚠️
Flax Typhoon exploited ArcGIS to gain long-term access
KEV
⚠️
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
⚠️
F5 says hackers stole undisclosed BIG-IP flaws, source code
⚠️
F5 Blames Nation-State Hackers for Theft of Source Code and Vulnerability Data
⚠️
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks
⚠️
Hackers Breach F5 and Stole BIG-IP Source Code and Undisclosed Vulnerability Data
⚠️
CISA Directs Federal Agencies to Mitigate Vulnerabilities in F5 Devices
⚠️
F5 says hackers stole undisclosed BIG-IP flaws, source code
⚠️
F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion
⚠️
Fortra cops to exploitation of GoAnywhere file-transfer service defect
⚠️
F5 network compromised
⚠️
MCPTotal Launches to Power Secure Enterprise MCP Workflows
⚠️
PowerSchool hacker gets sentenced to four years in prison
⚠️
Source code and vulnerability info stolen from F5 Networks
⚠️
58% of CISOs are boosting AI security budgets
⚠️
MCPTotal Launches to Power Secure Enterprise MCP Workflows
⚠️
Risky Business #810 -- Data extortion attacks have a silver lining
📋
High-Severity Vulnerabilities Patched by Fortinet and Ivanti
📋
ICS Patch Tuesday: Fixes Announced by Siemens, Schneider, Rockwell, ABB, Phoenix Contact
📋
Microsoft: Sept Windows Server updates cause Active Directory issues
📋
October Patch Tuesday beats January ’25 record
📋
F5 releases BIG-IP patches for stolen security vulnerabilities
📢
NCSC Issues Warning as UK Sees Four Cyber Attacks a Week
📢
Microsoft security advisory - October 2025 monthly rollup (AV25-666)
📢
Adobe security advisory (AV25-667)
📢
UK: 130% Spike in “Nationally Significant” Cyber Incidents - Infosecurity Magazine
📢
Fortinet security advisory (AV25-668)
📢
NCSC warns companies to prepare for a day when your screens go dark
📢
F5 security advisory (AV25-669)
📢
CISA Issues Emergency Directive to Address Critical Vulnerabilities in F5 Devices
📢
[Control systems] ABB security advisory (AV25-670)
📢
Google Chrome security advisory (AV25-671)
📢
Cisco security advisory (AV25-672)
📢
BreachLock Named Representative Provider for Penetration Testing as a Service (PTaaS) in New Gartner® Report
📢
Secure the Edge with Prisma Browser and the Essential Eight
🔥
Hello Cake - 22,907 breached accounts
🔥
Clipboard Pictures Exfiltration in Python Infostealer, (Wed, Oct 15th)
🔥
Hacker attackieren Vergabeportal für öffentliche Aufträge
🔥
GhostBat RAT Android Malware Poses as Fake RTO Apps to Steal Banking Data from Indian Users
🔥
Deutsche Logistik schlecht vor Cyberattacken geschützt
🔥
Hackers claim attacks on Texas electric co-ops | Cybernews
🔥
Capita Fined £14m After 2023 Breach that Hit 6.6 Million People - Infosecurity Magazine
🔥
Customer Service Firm 5CA Denies Responsibility for Discord Data Breach
🔥
BlackSuit Ransomware Breaches Corporate Network Using Single Compromised VPN Credential
🔥
Clothing giant MANGO discloses data breach exposing customer info
🔥
The importance of hardening customer support tools against cyberattacks
🔥
Fake LastPass, Bitwarden breach alerts lead to PC hijacks
🔥
Capita to pay £14 million for data breach impacting 6.6 million people
🔥
AL25-014 Security Incident impacting F5
🔥
Smashing Security podcast #439: A breach, a burnout, and a bit of Fleetwood Mac
🔥
Hackers steal data of fashion retailer Mango’s customers
🕵️
RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks
🕵️
Telegram Becomes the Nerve Center for Modern Hacktivist Operations
🕵️
UEFI Shell Flaws Let Hackers Disable Secure Boot on Over 200,000 Laptops
🕵️
Pixnapping Attack Hijacks Google Authenticator 2FA Codes in Under 30 Seconds
🕵️
End of Support for Windows 10 Sparks Security Fears Among Millions of Users
🕵️
Chinese Hackers Use Geo-Mapping Tool for Year-Long Persistence
🕵️
Oracle issues second emergency patch for E-Business Suite in two weeks | CSO Online
🕵️
Study reveals satellites comms spilling unencrypted data • The Register
🕵️
Webinar Today: Fact vs. Fiction – The Truth About API Security
🕵️
What are You Working on Wednesday
🕵️
SecurityWeek to Host 2025 ICS Cybersecurity Conference October 27-30 in Atlanta
🕵️
News Alert: MCPTotal unveils the first platform to secure Model Context Protocol workflows
🕵️
338 Malicious npm Packages Linked to North Korean Hackers | eSecurity Planet
🕵️
Chinese Threat Group 'Jewelbug' Quietly Infiltrated Russian IT Network for Months
🕵️
ISC Stormcast For Thursday, October 16th, 2025 https://isc.sans.edu/podcastdetail/9658, (Wed, Oct 15th)
🕵️
IT service desks: The security blind spot that may put your business at risk
🌐
How to spot dark web threats on your network using NDR
📡
Inspiring Futures: Empowering the Next Generation of Girls in Tech
📡
Cyber giant F5 Networks says government hackers had ‘long-term’ access to its systems, stole code and customer data
📡
Sophos Firewall v22 is now available in early access
📡
WireTap and Battering RAM: attacks on TEEs | Kaspersky official blog
📡
YouTube is down worldwide with playback error