130Articles
8Categories
2025-10-29Date
πŸ›
Microsoft Issues Alert on ASP.NET Flaw Allowing HTTP Request Smuggling Attacks
πŸ›
XWiki Remote Code Execution Flaw Actively Weaponized for Coinmining
KEV
πŸ›
Active Exploits Hit Dassault and XWiki β€” CISA Confirms Critical Flaws Under Attack
πŸ›
Docker Compose Flaw Lets Attackers Overwrite Arbitrary Files
πŸ›
Google Wear OS Flaw Lets Any App Send Texts on Behalf of Users
πŸ›
Windows Server Update Services (WSUS) vulnerability abused to harvest sensitive data
πŸ›
CVE-2025-40025 f2fs: fix to do sanity check on node footer for non inode dnode
πŸ›
CVE-2025-40051 vhost: vringh: Modify the return value check
πŸ›
CVE-2025-40077 f2fs: fix to avoid overflow while left shift operation
πŸ›
CVE-2025-40064 smc: Fix use-after-free in __pnet_find_base_ndev().
πŸ›
CVE-2025-40038 KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid
πŸ›
CVE-2025-40042 tracing: Fix race condition in kprobe initialization causing NULL pointer dereference
πŸ›
CVE-2025-40029 bus: fsl-mc: Check return value of platform_get_resource()
πŸ›
CVE-2025-40061 RDMA/rxe: Fix race in do_task() when draining
πŸ›
CVE-2025-40078 bpf: Explicitly check accesses to bpf_sock_addr
πŸ›
CVE-2025-40044 fs: udf: fix OOB read in lengthAllocDescs handling
πŸ›
CVE-2025-40052 smb: client: fix crypto buffers in non-linear memory
πŸ›
CVE-2025-40030 pinctrl: check the return value of pinmux_ops::get_function_name()
πŸ›
CVE-2025-40035 Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak
πŸ›
CVE-2025-40053 net: dlink: handle copy_thresh allocation failure
πŸ›
CVE-2025-40055 ocfs2: fix double free in user_cluster_connect()
πŸ›
CVE-2025-40056 vhost: vringh: Fix copy_to_iter return value check
πŸ›
CVE-2025-40040 mm/ksm: fix flag-dropping behavior in ksm_madvise
πŸ›
CVE-2025-40026 KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
πŸ›
CVE-2025-40060 coresight: trbe: Return NULL pointer for allocation failures
πŸ›
CVE-2025-40080 nbd: restrict sockets to TCP and UDP
πŸ›
CVE-2025-40032 PCI: endpoint: pci-epf-test: Add NULL check for DMA channels before release
πŸ›
CVE-2025-40033 remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable()
πŸ›
CVE-2025-40074 ipv4: start using dst_dev_rcu()
πŸ›
CVE-2025-40043 net: nfc: nci: Add parameter validation for packet data
πŸ›
CVE-2025-40039 ksmbd: Fix race condition in RPC handle list access
πŸ›
CVE-2025-40036 misc: fastrpc: fix possible map leak in fastrpc_put_args
πŸ›
CVE-2025-40048 uio_hv_generic: Let userspace take care of interrupt mask
πŸ›
CVE-2025-40081 perf: arm_spe: Prevent overflow in PERF_IDX2OFF()
πŸ›
CVE-2025-40049 Squashfs: fix uninit-value in squashfs_get_parent
πŸ›
CVE-2025-11840 GNU Binutils ldmisc.c vfinfo out-of-bounds
πŸ›
CVE-2025-40027 net/9p: fix double req put in p9_fd_cancelled
πŸ›
CVE-2025-40065 RISC-V: KVM: Write hgatp register with valid mode bits
πŸ›
CVE-2025-40075 tcp_metrics: use dst_dev_net_rcu()
πŸ›
CVE-2025-40057 ptp: Add a upper bound on max_vclocks
πŸ›
CVE-2025-40068 fs: ntfs3: Fix integer overflow in run_unpack()
πŸ›
CVE-2025-40079 riscv, bpf: Sign extend struct ops return values properly
πŸ›
CVE-2025-40071 tty: n_gsm: Don't block input queue by waiting MSC
⚠️
Aisuru Botnet Shifts from DDoS to Residential Proxies
⚠️
Atroposia malware kit lowers the bar for cybercrime β€” and raises the stakes for enterprise defenders
⚠️
New Atroposia RAT Uses Hidden Remote Desktop, Vulnerability Scanning and Advanced Persistence
⚠️
Mozilla Enforces Transparency Rules for Data Collection in New Firefox Extensions
⚠️
Top 7 agentic AI use cases for cybersecurity
⚠️
New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs
⚠️
CISA Warns of Exploited DELMIA Factory Software Vulnerabilities
⚠️
Is your perimeter having an identity crisis?
⚠️
CISA Issues Alert on Active Exploitation of Dassault Systèmes Security Flaws
⚠️
Ad and PR Giant Dentsu Says Hackers Stole Merkle Data
⚠️
XWiki Vulnerability Exploited in Cryptocurrency Mining Operation
⚠️
Signal’s Post-Quantum Cryptographic Implementation
⚠️
CyberRidge Emerges From Stealth With $26 Million for Photonic Encryption Solution
⚠️
New TEE.fail Exploit Steals Secrets from Intel & AMD DDR5 Trusted Environments
⚠️
Google Publishes New Guide to Help Defenders Monitor Privileged Accounts
⚠️
Massive 4TB EY Database Backup Found Publicly Accessible on Azure
⚠️
Visibility Gaps: Streamlining Patching and Vulnerability Remediation
⚠️
CISA warns of two more actively exploited Dassault vulnerabilities
KEV
⚠️
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices
⚠️
Is Russia Cracking Down on Cyber Criminals? Fake Death Scams & Exposed AI Servers | Cybersecurity Today
⚠️
Former L3Harris Trenchant boss pleads guilty to selling zero-day exploits to Russian broker
⚠️
WordPress security plugin exposes private data to site subscribers
⚠️
Risky Business #812 -- Alleged Trenchant exploit mole is ex-ASD
KEV
πŸ“‹
Zehntausende Exchange-Server in Deutschland gefΓ€hrdet
πŸ“’
Discover Practical AI Tactics for GRC β€” Join the Free Expert Webinar
πŸ“’
Google Chrome security advisory (AV25-706)
πŸ“’
VMware security advisory (AV25-705)
πŸ“’
Jenkins security advisory (AV25-707)
πŸ“’
Insider Risk, Ethical Walls and the Future of Data Governance in Financial Services
πŸ“’
Docker security advisory (AV25–708)
πŸ”₯
LG Uplus is latest South Korean telco to confirm cybersecurity incident
πŸ”₯
How to collect memory-only filesystems on Linux systems, (Wed, Oct 29th)
πŸ”₯
Gunra Ransomware Targets Windows and Linux with Dual Encryption
πŸ”₯
Beast Ransomware Targets Active SMB Connections to Infect Entire Networks
πŸ”₯
Massive Tata Motors Data Leak Exposes 70+ TB of Sensitive Information
πŸ”₯
Ransomware-Attacke auf schwedischen Stromversorger
πŸ”₯
BlueNoroff reemerges with new campaigns for crypto theft and espionage
πŸ”₯
Preparing for the Digital Battlefield of 2026: Ghost Identities, Poisoned Accounts, & AI Agent Havoc
πŸ”₯
Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics
πŸ”₯
Hackers Allegedly Leak HSBC USA Customer and Financial Information
πŸ”₯
New β€˜Gentlemen’ RaaS Appears on Hacking Forums, Targeting Windows, Linux and ESXi
πŸ”₯
Qilin claims pharmacy benefit manager MedImpact | Cybernews
πŸ”₯
Next-gen firewalls, VPNs can increase security risks: At-Bay
πŸ”₯
Advertising giant Dentsu reports data breach at subsidiary Merkle
πŸ”₯
Report: Organizations Are Struggling to Keep Up With AI-Powered Attacks
πŸ”₯
Canada says hacktivists breached water and energy facilities
πŸ•΅οΈ
ISC Stormcast For Wednesday, October 29th, 2025 https://isc.sans.edu/podcastdetail/9676, (Wed, Oct 29th)
πŸ•΅οΈ
Ethical Prompt Injection: Fighting Shadow AI with Its Own Weapon
πŸ•΅οΈ
10 NPM Packages That Automatically Run on Install and Steal Credentials
πŸ•΅οΈ
Emergence of the Chief Trust Officer as CISOs Earn Business Respect and Agenda Shifts - BSW #419
πŸ•΅οΈ
Chrome to Turn HTTPS on by Default for Public Sites
πŸ•΅οΈ
10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux
πŸ•΅οΈ
AI Security Firm Polygraf Raises $9.5 Million in Seed Funding
πŸ•΅οΈ
Cybercriminals Launch Flood of Fake Forex Platforms to Harvest Logins
πŸ•΅οΈ
New Android Trojan 'Herodotus' Outsmarts Anti-Fraud Systems by Typing Like a Human
πŸ•΅οΈ
The Human-AI Partnership: Securing the New Dual-Front of Business Risk
πŸ•΅οΈ
PureHVNC RAT Distributed via Weaponized Judicial Documents
πŸ•΅οΈ
MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS
πŸ•΅οΈ
Russian Hackers Target Government with Stealthy β€œLiving-Off-the-Land” Tactics
πŸ•΅οΈ
Scammers target international students by threatening their visa status - Help Net Security
πŸ•΅οΈ
AI agents can leak company data through simple web searches - Help Net Security
πŸ•΅οΈ
Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack - SecurityWeek
πŸ•΅οΈ
What are You Working on Wednesday
πŸ•΅οΈ
Germany: 92% of Exchange servers left unprotected | Cybernews
πŸ•΅οΈ
Hackers Target Swedish Power Grid Operator - SecurityWeek
πŸ•΅οΈ
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
πŸ•΅οΈ
Sweet Security Brings Runtime-CNAPP Power to Windows
πŸ•΅οΈ
TurboMirai-Class 'Aisuru' Botnet Blamed for 20+ Tbps DDoS Attacks - SecurityWeek
πŸ•΅οΈ
Azure down: Thousands of users complain about outage; here's Microsoft's latest statement
πŸ•΅οΈ
Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services Worldwide
πŸ•΅οΈ
MY TAKE: What a cystoscopy taught me about the changing face of patient care β€” and trusting AI
🌐
CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware
🌐
AL25-016 Internet-accessible industrial control systems (ICS) abused by hacktivists
🌐
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
πŸ“‘
New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves
πŸ“‘
Tata Motors confirms it fixed security flaws, which exposed company and customer data
πŸ“‘
TechCrunch Disrupt 2025: Day 3
πŸ“‘
Microsoft fixes 0x800F081F errors causing Windows update failures
πŸ“‘
Which social media are the most privacy-oriented in 2025 | Kaspersky official blog
πŸ“‘
Sophos Firewall v22: Health Check
πŸ“‘
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts
πŸ“‘
PhantomRaven attack floods npm with credential-stealing packages
πŸ“‘
Microsoft: DNS outage impacts Azure and Microsoft 365 services
πŸ“‘
Microsoft fixes Media Creation Tool broken on some Windows PCs
πŸ“‘
Cybersecurity Awareness Month 2025: When seeing isn't believing
πŸ“‘
One IP address, many users: detecting CGNAT to reduce collateral effects
πŸ“‘
Defending QUIC from acknowledgement-based DDoS attacks