107Articles
8Categories
2025-10-31Date
🚨
CISA Adds Exploited XWiki, VMware Flaws to KEV CatalogBroadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation. The post CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog appeared first on SecurityWeek .
KEV
🚨
CISA Issues Advisory on XWiki Flaw Allowing Remote Code ExecutionThe Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting XWiki Platform to its Known Exploited Vulnerabilities catalog, highlighting the urgent security threat posed by an eval injection flaw. This vulnerability could allow any gues…
KEV
πŸ›
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
KEV
πŸ›
AI-powered bug hunting shakes up bounty industry β€” for better or worse
πŸ›
CISA Alerts on Active Exploitation of VMware Tools and Aria Operations 0-Day
πŸ›
Progress Releases Patch for MOVEit Transfer Resource Consumption Flaw
πŸ›
OpenAI launches Aardvark to detect and patch hidden bugs in code
πŸ›
Attackers Exploit Windows Server Update Services Flaw to Steal Sensitive Organizational Data
πŸ›
China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
πŸ›
Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI
πŸ›
Chromium: CVE-2025-12447 Incorrect security UI in Omnibox
πŸ›
Chromium: CVE-2025-12446 Incorrect security UI in SplitView
πŸ›
Chromium: CVE-2025-12445 Policy bypass in Extensions
πŸ›
Chromium: CVE-2025-12433 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2025-12441 Out of bounds read in V8
πŸ›
Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
πŸ›
Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
πŸ›
Chromium: CVE-2025-12434 Race in Storage
πŸ›
Chromium: CVE-2025-12435 Incorrect security UI in Omnibox
πŸ›
Chromium: CVE-2025-12436 Policy bypass in Extensions
πŸ›
Chromium: CVE-2025-12437 Use after free in PageInfo
πŸ›
Chromium: CVE-2025-12438 Use after free in Ozone
πŸ›
Chromium: CVE-2025-12433 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
πŸ›
Chromium: CVE-2025-12430 Object lifecycle issue in Media
πŸ›
Chromium: CVE-2025-12432 Race in V8
πŸ›
Chromium: CVE-2025-12429 Inappropriate implementation in V8
πŸ›
Chromium: CVE-2025-12428 Type Confusion in V8
πŸ›
Chromium: CVE-2025-12036 Inappropriate implementation in V8
πŸ›
CVE-2025-60711 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
πŸ›
Chinese hackers target Western diplomats using hard-to-patch Windows shortcut flaw
πŸ›
Cyber agencies produce β€˜long overdue’ best practices for securing Microsoft Exchange Server
⚠️
Malicious packages in npm evade dependency detection through invisible URL links: Report
⚠️
Massive Data Exposures, Insider Threats, and State-Sponsored Cyber Attacks
⚠️
New Agent-Aware Cloaking Technique Uses ChatGPT Atlas Browser to Feed Fake Content
⚠️
Aembit Introduces Identity and Access Management for Agentic AI
KEV
⚠️
Windows LNK UI Spoofing Vulnerability Weaponized for Remote Code Execution
⚠️
Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
⚠️
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
⚠️
Threat Actors Exploiting Open-Source C2 Frameworks to Deploy Malicious Payloads
⚠️
Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks
⚠️
The unified linkage model: A new lens for understanding cyber risk
⚠️
Threat Actors Exploit LANSCOPE Endpoint Manager Zero-Day Vulnerability to Steal Confidential Data
⚠️
Will AI Strengthen or Undermine Democracy?
⚠️
Windows zero-day actively exploited to spy on European diplomats
KEV
⚠️
Bug-Bounty-Programm trifft KI – ein zweischneidiges Schwert
⚠️
Beware of Fake ChatGPT Apps That Spy on Users and Steal Sensitive Data
⚠️
Claude AI vulnerability exposes enterprise data through code interpreter exploit
⚠️
CISA: High-severity Linux flaw now exploited by ransomware gangs
⚠️
New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL
⚠️
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
⚠️
CISA: High-severity Linux flaw now exploited by ransomware gangs
⚠️
Multiple Jenkins Vulnerability SAML Authentication Bypass And MCP Server Plugin Permissions
⚠️
Australia warns of BadCandy infections on unpatched Cisco devices
⚠️
UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities - Arctic Wolf
⚠️
Australia warns of BadCandy infections on unpatched Cisco devices
⚠️
AI Cheating?, O, Canada, npms, passkeys, Exchange, Solaris, the amazing Rob Allen - SWN #525
πŸ“’
CISA Publishes New Guidance to Strengthen Microsoft Exchange Server Security
πŸ“’
The MSP Cybersecurity Readiness Guide: Turning Security into Growth
πŸ“’
CISA and NSA share tips on securing Microsoft Exchange servers
πŸ“’
SonicWall security advisory (AV25-711)
πŸ“’
Progress security advisory (AV25-712)
πŸ“’
HPE security advisory (AV25-713)
πŸ”₯
Massive Great Firewall Leak Exposes 500GB of Censorship Data
πŸ”₯
Kimsuky and Lazarus Hackers Deploy New Backdoor Tools for Remote Access Attacks
πŸ”₯
Ukrainian extradited from Ireland on Conti ransomware charges
πŸ”₯
Data breach at Reputation.com: brands at risk as 120M records leak
πŸ”₯
BPO giant Conduent confirms data breach impacts 10.5 million people
πŸ”₯
Major telecom services provider Ribbon breached by state hackers
πŸ”₯
Stolen Credentials Drive the Rise of Financially Motivated Cyberattacks
πŸ”₯
Ukrainian Man Extradited From Ireland to US Over Conti Ransomware Charges
πŸ”₯
Poland mayors hit by phishing scam​ | Cybernews
πŸ”₯
Government hackers breached telecom giant Ribbon for months before getting caught
πŸ”₯
Hackers threaten to leak data after breaching University of Pennsylvania to send mass emails
πŸ”₯
β€˜We got hacked’ emails threaten to leak University of Pennsylvania data
πŸ•΅οΈ
ISC Stormcast For Friday, October 31st, 2025 https://isc.sans.edu/podcastdetail/9680, (Fri, Oct 31st)
πŸ•΅οΈ
Malicious Multilingual ZIP Files Strike Banks and Government Offices
πŸ•΅οΈ
Japan Issues OT Security Guidance for Semiconductor Factories
πŸ•΅οΈ
Researchers Develop Linux Rootkit That Evades Elastic EDR Protections
πŸ•΅οΈ
WhatsApp Implements Passkey System to Boost Backup Privacy
πŸ•΅οΈ
Agentic AI: What now, what next?
πŸ•΅οΈ
Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners
πŸ•΅οΈ
LotL Attack Hides Malware in Windows Native AI Stack
πŸ•΅οΈ
Open VSX Downplays Impact From GlassWorm Campaign
πŸ•΅οΈ
Massive surge of NFC relay malware steals Europeans’ credit cards
πŸ•΅οΈ
Google Launches New AI Security Features on Android to Block Mobile Scams
πŸ•΅οΈ
Critical Flaws Found in Elementor King Addons Affect 10,000 Sites - Infosecurity Magazine
πŸ•΅οΈ
Why password controls still matter in cybersecurity
πŸ•΅οΈ
NPM flooded with malicious packages downloaded more than 86,000 times
πŸ•΅οΈ
Kimsuky and Lazarus Hacker Groups Unveil New Tools That Enable Backdoor and Remote Access
πŸ•΅οΈ
In Other News: WhatsApp Passkey-Encrypted Backups, Russia Targets Meduza Malware, New Mastercard Solution
πŸ•΅οΈ
Aisuru Botnet Shifts from DDoS to Residential Proxies – Krebs on Security
πŸ•΅οΈ
Australian Police Use 'Crypto Safe Cracker' to Access $6M Stash - Decrypt
πŸ•΅οΈ
Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
πŸ•΅οΈ
Russia finally bites the cybercrooks it raised, arresting suspected Meduza infostealer devs
πŸ•΅οΈ
UN Convention Against Cybercrime Is a Huge Win!
πŸ•΅οΈ
Friday Squid Blogging: Giant Squid at the Smithsonian
πŸ•΅οΈ
MY TAKE: Microsoft pitches an AI β€˜protopian’ future β€” while civic groups pedal to stay upright
🌐
Alleged Meduza Stealer malware admins arrested after hacking Russian org
πŸ“‘
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
πŸ“‘
Phake phishing: Phundamental or pholly?
πŸ“‘
Google says Search AI Mode will know everything about you
πŸ“‘
Microsoft Edge gets scareware sensor for faster scam detection
πŸ“‘
OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
πŸ“‘
Windows 11 tests shared Bluetooth audio support, but only for AI PCs
πŸ“‘
This month in security with Tony Anscombe – October 2025 edition
πŸ“‘
How are you managing cloud risk?