92Articles
8Categories
2025-10-24Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-54236 Adobe Commerce and Magento Improper Input Validation Vulnerability CVE-2025-59287 Microsoft Windows Server Update Service (WSUS) …
KEV
🚨
Microsoft Releases Out-of-Band Security Update to Mitigate Windows Server Update Service Vulnerability, CVE-2025-59287Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE-2025-59287 , that a prior update did not fully mitigate.  CISA strongly urges organ…
KEV
πŸ›
CVE-2022-49173 spi: fsi: Implement a timeout for polling status
πŸ›
CVE-2022-49469 btrfs: fix anon_dev leak in create_subvol()
πŸ›
CVE-2022-49543 ath11k: fix the warning of dev_wake in mhi_pm_disable_transition()
πŸ›
CVE-2022-49552 bpf: Fix combination of jit blinding and pointers to bpf subprogs.
πŸ›
CVE-2022-49562 KVM: x86: Use __try_cmpxchg_user() to update guest PTE A/D bits
πŸ›
CVE-2022-49610 KVM: VMX: Prevent RSB underflow before vmenter
πŸ›
CVE-2022-49635 drm/i915/selftests: fix subtraction overflow bug
πŸ›
CVE-2025-11411 Possible domain hijacking via promiscuous records in the authority section
πŸ›
CVE-2025-62813 LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
πŸ›
Microsoft Releases Urgent Fix for Windows Server Update Services RCE FLaw
πŸ›
Critical Windows Server WSUS Vulnerability Exploited in the Wild
KEV
πŸ›
Microsoft Issues Emergency Patch for Actively Exploited Critical WSUS Vulnerability
KEV
πŸ›
AL25-015 - Vulnerability impacting Microsoft Windows Server Update Services - CVE-2025-59287
πŸ›
Critical Microsoft WSUS flaw exploited in wild after insufficient patch
KEV
⚠️
AI browsers can be abused by malicious AI sidebar extensions: Report
⚠️
Hackers Exploit Galaxy S25 0-Day to Turn On Camera and Track Users
⚠️
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
⚠️
YouTube Ghost Malware Campaign: Over 3,000 Infected Videos Target Users
⚠️
Microsoft Boosts Windows Security by Disabling File Previews for Downloads
⚠️
Windows Server emergency patches fix WSUS bug with PoC exploit
⚠️
Malicious NuGet Packages Pose as Nethereum, Steal Crypto Wallet Keys
⚠️
Pwn2Own WhatsApp Hacker Says Exploit Privately Reported to Meta
⚠️
Quantum resistance and the Signal Protocol: From PQXDH to Triple Ratchet
⚠️
IIS Servers Hijacked via Exposed ASP.NET Machine Keys β€” Malicious Modules Injected in the Wild
⚠️
New RedTiger Tool Targets Gamers and Discord Accounts in the Wild
⚠️
Der Weg zur CPS-Resilienz
⚠️
New PDF Tool Detects Malicious Files Using PDF Object Hashing
⚠️
The Cybersecurity Perception Gap: Why Executives and Practitioners See Risk Differently
⚠️
Lazarus group targets European drone makers in new espionage campaign
⚠️
Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
⚠️
Windows Server emergency patches fix WSUS bug with PoC exploit
⚠️
UN agreement on cybercrime criticized over risks to cybersecurity researchers
⚠️
Critical WSUS flaw in Windows Server now exploited in attacks
⚠️
Why Threat Actors Succeed
⚠️
Hackers launch mass attacks exploiting outdated WordPress plugins
⚠️
Top 10 Best Breach And Attack Simulation (BAS) Vendors in 2025
⚠️
A Vulnerability in Microsoft Windows Server Update Services (WSUS) Could Allow for Remote Code Execution
πŸ“’
Scammers try to trick LastPass users into giving up credentials by telling them they’re dead
πŸ“’
Cybersecurity Awareness Month 2025: Cyber-risk thrives in the shadows
πŸ”₯
AI Sidebar Spoofing Attack: SquareX Uncovers Malicious Extensions that Impersonate AI Browser Sidebars
πŸ”₯
Cybersecurity Today: New Threats from AI and Code Extensions
πŸ”₯
Linux RATs on Windows: Ransomware Actors Target VMware Deployments
πŸ”₯
Hackers Steal Microsoft Teams Chats & Emails by Grabbing Access Tokens
πŸ”₯
Ransomware recovery perils: 40% of paying victims still lose their data
πŸ”₯
Formel 1 betroffen: Cyberattacke auf Fahrer-Portal
πŸ”₯
Toys β€œR” Us Canada Data Breach Exposes Customer Personal Information
πŸ”₯
Ransomware Actors Targeting Global Public Sectors and Critical Infrastructure
πŸ”₯
Medusa Ransomware Leaks 834 GB of Comcast Data After $1.2M Demand – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
πŸ”₯
Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | Trend Micro (US)
πŸ”₯
Shadow Escape 0-Click Attack in AI Assistants Puts Trillions of Records at Risk – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
πŸ”₯
Cyber incidents in Texas, Tennessee and Indiana impacting critical government services | The Record from Recorded Future News
πŸ”₯
LockBit 5.0 Targets Windows, Linux, and ESXi Systems in Ongoing Attacks
πŸ”₯
Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
πŸ”₯
Toys β€œR” Us Canada warns customers' info leaked in data breach
πŸ”₯
Fake LastPass death claims used to breach password vaults
πŸ”₯
Top 10 Best Security Operations Center (SOC) as a Service Providers in 2025
πŸ”₯
Top 10 Best Cyber Threat Intelligence Companies in 2025
πŸ”₯
Top 10 Best Digital Forensics And Incident Response (DFIR) Firms in 2025
πŸ•΅οΈ
ISC Stormcast For Friday, October 24th, 2025 https://isc.sans.edu/podcastdetail/9670, (Fri, Oct 24th)
πŸ•΅οΈ
TIL that PortSwigger is a joke
πŸ•΅οΈ
New Phishing Wave Uses OAuth Prompts to Take Over Microsoft Accounts
πŸ•΅οΈ
Phishing Campaign Uses Unique UUIDs to Evade Secure Email Gateways
πŸ•΅οΈ
North Korean Hackers Target UAV Industry to Steal Confidential Data
πŸ•΅οΈ
Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks
πŸ•΅οΈ
Part Four of The Kryptos Sculpture
πŸ•΅οΈ
Toys β€˜R’ Us Canada Customer Information Leaked Online
πŸ•΅οΈ
Mideast, African Hackers Target Gov'ts, Banks, Small Retailers
πŸ•΅οΈ
Google Warns of Cybercriminals Using Fake Job Postings to Spread Malware and Steal Credentials
πŸ•΅οΈ
In Other News: iOS 26 Deletes Spyware Evidence, Shadow Escape Attack, Cyber Exec Sold Secrets to Russia
πŸ•΅οΈ
New Google TAG report: How Commercial Surveillance Vendors work
πŸ•΅οΈ
Lazarus Group’s Operation DreamJob Targets European Defense Firms - Infosecurity Magazine
πŸ•΅οΈ
Telegram Messenger Abused by Android Malware to Seize Full Device Control
πŸ•΅οΈ
North Korean Hackers Aim at European Drone Companies
πŸ•΅οΈ
Arsen Launches Smishing Simulation to Help Companies Defend Against Mobile Phishing Threats
πŸ•΅οΈ
Amazon Reveals Technical Fault Behind Widescale AWS Service Outage
πŸ•΅οΈ
Hackers Target Perplexity Comet Browser Users
πŸ•΅οΈ
Researchers expose large-scale YouTube malware distribution network - Help Net Security
πŸ•΅οΈ
APT36 Targets Indian Government with Golang-Based DeskRAT Malware Campaign
πŸ•΅οΈ
Phishing Campaign Impersonates Google Careers Recruiters
πŸ•΅οΈ
Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
πŸ•΅οΈ
Friday Squid Blogging: β€œEl Pulpo The Squid”
πŸ•΅οΈ
News alert: Arsen rolls out β€˜Smishing Simulation’ to strengthen defenses against mobile phishing threats
🌐
Self-Spreading 'GlassWorm' Infects VS Code Extensions in Widespread Supply Chain Attack
🌐
3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation
πŸ“‘
Phishing Cloud Account for Information, (Thu, Oct 23rd)
πŸ“‘
Locking it down: A new technique to prevent LLM jailbreaks
πŸ“‘
Mozilla: New Firefox extensions must disclose data collection practices
πŸ“‘
How to reduce costs with self-service password resets
πŸ“‘
Amazon: This week’s AWS outage caused by major DNS failure
πŸ“‘
Privacy rankings of popular messaging apps in 2025 | Kaspersky official blog