84Articles
9Categories
2025-11-04Date
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-11371 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability CVE-2025-48703 CWP Control Web…
KEV
🐛
Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit
🐛
Android Hit by 0-Click RCE Vulnerability in Core System Component
🐛
Critical WordPress Post SMTP Plugin Vulnerability Puts 400,000 Sites at Risk of Account Takeover
🐛
Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks
⚠️
MY TAKE: From AOL-Time Warner to OpenAI-Amazon — is the next tech bubble already inflating?
⚠️
Cybercriminals Exploit RMM Tools to Target Trucking Firms and Hijack Freight
⚠️
Hackers Can Manipulate Claude AI APIs with Indirect Prompts to Steal User Data
⚠️
SesameOp: Using the OpenAI Assistants API for Covert C2 Communication
⚠️
Microsoft Detects "SesameOp" Backdoor Using OpenAI's API as a Stealth Command Channel
⚠️
Gen AI success requires an AI champions network
⚠️
Modern supply-chain attacks and their real-world impact
⚠️
165: Tanya
⚠️
Ransomware-Bande missbraucht Microsoft-Zertifikate
⚠️
Balancer DeFi Platform Hit by Major Exploit Resulting in $100M+ in Losses
⚠️
‘SleepyDuck’ Malware in Open VSX Lets Attackers Remotely Control Windows PCs
⚠️
Hackers exploit critical auth bypass flaw in JobMonster WordPress theme
⚠️
Android Update Patches Critical Remote Code Execution Flaw
⚠️
RondoDox Botnet Swells Its Arsenal — 650% Jump in Enterprise-Focused Exploits
⚠️
Researching and Remediating RCEs via GitHub Actions - Bar Kaduri, Roi Nisimi - ASW #355
⚠️
New backdoor ‘SesameOp’ abuses OpenAI Assistants API for stealthy C2 operations
⚠️
Ransomware Defense Using the Wazuh Open Source Platform
⚠️
Apple Patches Everything, Again, (Tue, Nov 4th)
⚠️
Cybersecurity experts charged with running BlackCat ransomware operation
KEV
⚠️
New GDI Flaws Could Enable Remote Code Execution in Windows - Infosecurity Magazine
⚠️
Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed
⚠️
Police arrests suspects linked to €600 million crypto fraud ring
⚠️
The Top 3 Browser Sandbox Threats That Slip Past Modern Security Tools
⚠️
Critical React Native CLI Flaw Exposed Millions of Developers to Remote Attacks
⚠️
Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep
⚠️
CISA Releases Five Industrial Control Systems Advisories
⚠️
DragonForce Cartel Emerges as Conti-Derived Ransomware Threat
⚠️
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces
⚠️
Hackers exploit WordPress plugin Post SMTP to hijack admin accounts
⚠️
A Vulnerability in CWP (aka Control Web Panel or CentOS Web Panel) Could Allow for Remote Code Execution
⚠️
How social engineering works | Unlocked 403 cybersecurity podcast (S2E6)
📋
Apple Releases Security Update Addressing Critical Flaws in iOS 26.1 and iPadOS 26.1
📋
Microsoft’s WSUS Patch Causes Hotpatching Failures on Windows Server 2025
📋
Louvre delayed Windows security updates ahead of burglary
📢
Apple security advisory (AV25-722)
📢
Android security advisory – November 2025 monthly rollup (AV25-723)
📢
Bob Flores, Former CTO of the CIA, Joins Brinker
📢
VMware security advisory (AV25-724)
📢
Tenable security advisory (AV25-725)
🔥
Malicious PuTTY Ads Deliver OysterLoader, Allowing Attackers Full Device and Network Access
🔥
U.S. Prosecutors Indict Cybersecurity Insiders Accused of BlackCat Ransomware Attacks
KEV
🔥
Microsoft Plans to Remove Entra Accounts from Authenticator on Jailbroken Devices
🔥
Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense Sectors
🔥
Hackers hit Polish loan site​ | Cybernews
🔥
New Dante Spyware Linked to Rebranded Hacking Team, Now Memento Labs – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
🔥
2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks
🔥
Transportation Companies Hacked to Steal Cargo
🔥
Media giant Nikkei reports data breach impacting 17,000 people
🔥
Data breach at major Swedish software supplier impacts 1.5 million
🔥
​​Learn what generative AI can do for your security operations center
🔥
Former ransomware negotiators allegedly targeted US firms with ALPHV/BlackCat ransomware - Help Net Security
🔥
Apache OpenOffice disputes data breach claims by ransomware gang
🕵️
ISC Stormcast For Tuesday, November 4th, 2025 https://isc.sans.edu/podcastdetail/9684, (Tue, Nov 4th)
🕵️
Zscaler Acquires AI Security Company SPLX
🕵️
Anatomy of Tycoon 2FA Phishing: Tactics Targeting M365 and Gmail
🕵️
Apple Patches 19 WebKit Vulnerabilities
🕵️
Cybercriminals Targeting Payroll Sites
🕵️
Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks
🕵️
Android Malware Mutes Alerts, Drains Crypto Wallets
🕵️
Zscaler Acquires SPLX to Strengthen AI-Powered Zero Trust Security
🕵️
XLoader Malware Analyzed Using ChatGPT’s AI, Breaks RC4 Encryption Layers in Hours
🕵️
Bugcrowd Acquires Application Security Firm Mayhem
🕵️
Hacker steals over $120 million from Balancer DeFi crypto protocol
🕵️
Data Theft Hits Behavioral Health Network in 3 States
🕵️
SesameOp Malware Abuses OpenAI API
🕵️
Hacker Conversations: Kunal Agarwal and the DNA of a Hacker
🕵️
Russian hackers abuse Hyper-V to hide malware in Linux VMs
🕵️
Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files
🕵️
CyberheistNews Vol 15 #44 [Mystery] Tough One: Is It or Is It Not an HP Scam?
🕵️
Prisma SASE as Your New Blueprint for Modern Branch Security
🕵️
How to check if Tor Onion Service is alive?
🕵️
How to check if Tor Onion Service is alive?
🕵️
How to check if Tor Onion Service is alive?
🕵️
News alert: Insider risk report finds behavioral blind spots leave most orgs exposed, confidence low
🎙️
The AI Fix #75: Claude’s existential battery crisis, and why ChatGPT is a terrible therapist
📡
Windows 10 update bug triggers incorrect end-of-support alerts
📡
Phone location data of top EU officials for sale, report finds
📡
Microsoft removing Defender Application Guard from Office
📡
Malicious Android apps on Google Play downloaded 42 million times