97Articles
9Categories
2025-11-05Date
🚨
CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation EvidenceThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerabilities in que…
KEV
🚨
CISA Issues Alert on Gladinet CentreStack and Triofox Vulnerabilities Under Active ExploitationThe Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Gladinet CentreStack and Triofox to its Known Exploited Vulnerabilities catalog, signaling active exploitation in the wild. The flaw, tracked as CVE-2025-11371, exposes sensit…
KEV
🐛
Critical RCE Bug in Leading React Native NPM Module Could Allow Full System Compromise
🐛
CISA Warns of CWP Vulnerability Exploited in the Wild
KEV
🐛
AI Engine WordPress Plugin Exposes 100,000 WordPress Sites to Privilege Escalation Attacks
🐛
CISA Alerts of Control Web Panel Command Injection Flaw Actively Exploited
KEV
🐛
Office sandbox file security to disappear from enterprise Windows by late 2027, Microsoft confirms
⚠️
Crowdstrike cybersecurity report highlights a spike in physical attacks on privileged users
⚠️
How crooks use IT to enable cargo theft
⚠️
DragonForce Cartel Surfaces from Leaked Conti v3 Ransomware Source Code
⚠️
Ransomware Insider Threats, AI Vulnerabilities, and Major Security Gaffes
⚠️
Attackers Exploit Microsoft Teams Flaws to Manipulate Messages and Fake Notifications
⚠️
Hackers Abuse OneDrive.exe via DLL Sideloading to Run Malicious Code
⚠️
10 promising cybersecurity startups CISOs should know about
⚠️
Security Professionals Charged for Using BlackCat Ransomware Against American Businesses
KEV
⚠️
Jupyter Misconfiguration Exposes Systems to Root Privilege Escalation
⚠️
Hackers Exploit AI Tools to Intensify Ransomware Attacks on European Organizations
⚠️
Defense Against Configurations as CIOs and CISOs Show Value Through Risks and Metrics - BSW #420
⚠️
APT-C-60 Campaign: Malicious VHDX Hosted on Google Drive Lures Job Applicants
⚠️
Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover
⚠️
NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards
⚠️
I wanted the Signal protocol implementation in javascript, but couldnt find one suitable... so i tried to create it myself.
⚠️
Scientists Need a Positive Vision for AI
⚠️
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces
⚠️
Hackers exploit WordPress plugin Post SMTP to hijack admin accounts
⚠️
Three Infamous Hacker Groups Join Forces as the ‘Scattered LAPSUS$ Hunters
⚠️
Norway discovers that its Chinese electric buses can be remotely disabled
⚠️
Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data
⚠️
Exploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed Microsoft Teams Vulnerabilities Uncovered
⚠️
Clop Ransomware Group Exploits New 0-Day Vulnerabilities in Active Attacks
⚠️
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
⚠️
Human Error is Still a Top Contributor to Cyberattacks
⚠️
CISA warns of critical CentOS Web Panel bug exploited in attacks
⚠️
WordPress plugin hole enables account takeover
⚠️
Russian APT abuses Windows Hyper-V for persistence and malware execution
⚠️
250 Episodes of Cloud Security Podcast by Google: From Confidential Computing to AI-Ready SOC
KEV
⚠️
Risky Business #813 -- FFmpeg has a point
📋
Microsoft: October Windows updates trigger BitLocker recovery
📋
Microsoft Issues Alert: BitLocker Recovery Risk After October 2025 Updates
📢
Louvre-Raubzug offenbart jahrzehntelanges Security-Versagen
📢
​​Securing critical infrastructure: Why Europe’s risk-based regulations matter
📢
Cisco security advisory (AV25-726)
🔥
Curly COMrades Hacker Group Deploys New Tools for Stealthy Remote Access on Compromised Windows 10 Systems
🔥
Swedish IT Company Data Breach Exposes Personal Details of 1.5 Million Users
🔥
Nikkei Says 17,000 Impacted by Data Breach Stemming From Slack Account Hack
🔥
Mysterious 'SmudgedSerpent' Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions
🔥
Why SOC Burnout Can Be Avoided: Practical Steps
🔥
Apache OpenOffice disputes data breach claims by ransomware gang
🔥
Data breach at major Swedish software supplier impacts 1.5 million
🔥
University of Pennsylvania confirms hacker stole data during cyberattack
🔥
University of Pennsylvania confirms data stolen in cyberattack
🔥
SonicWall says state-sponsored hackers behind security breach in September
🔥
5 ways to strengthen your firewall and endpoint’s defenses against ransomware
🔥
Hyundai AutoEver America data breach exposes SSNs, drivers licenses
🔥
2 Billion Email Addresses Were Exposed, and We Indexed Them All in Have I Been Pwned
🕵️
ISC Stormcast For Wednesday, November 5th, 2025 https://isc.sans.edu/podcastdetail/9686, (Wed, Nov 5th)
🕵️
Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials
🕵️
FIN7 Hackers Leverage Windows SSH Backdoor for Stealthy Remote Access and Persistence
🕵️
US Sanctions North Korean Bankers Accused of Laundering Stolen Cryptocurrency
🕵️
US sanctions North Korean bankers linked to cybercrime, IT worker fraud
🕵️
Portal26 Raises $9 Million for Gen-AI Adoption Platform
🕵️
U.S. Sanctions 10 North Korean Entities for Laundering $12.7M in Crypto and IT Fraud
🕵️
Daylight Raises $33 Million for AI-Powered MDR Platform
🕵️
Google Warns: AI Makes Cyber Threats Faster and Smarter by 2026
🕵️
ConductorOne Raises $79 Million in Series B Funding
🕵️
Microsoft pulls 200 Rhysida certificates​ | Cybernews
🕵️
Malanta Emerges from Stealth with $10 Million Seed Funding
🕵️
Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks - SecurityWeek
🕵️
Beware: 239 Dangerous Android Apps Found on Google Play with 40M+ Installs
🕵️
Armis Raises $435 Million in Pre-IPO Funding Round at $6.1 Billion Valuation
🕵️
Pro-Russian Hackers Use Linux VMs to Hide in Windows
🕵️
Flare Raises $30 Million for Threat Exposure Management Platform
🕵️
Solving the AI Black Box Problem with Prisma AIRS 2.0
🕵️
What are You Working on Wednesday
🕵️
Webinar Today: Scattered Spider Exposed – Critical Takeaways for Cyber Defenders
🕵️
Operation Peek-a-Baku: Silent Lynx APT Targets Dushanbe with Espionage Campaign
🕵️
The Rapid Advancement of Malicious AI Is Changing Cyberdefense Forevermore
🕵️
Fehlendes KI-Training wird zum Sicherheitsrisiko
🕵️
Google warns of new AI-powered malware families deployed in the wild
🕵️
Detecting fraudulent North Korean hires: A CISO playbook
🕵️
Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns
🕵️
Updates to Domainname API, (Wed, Nov 5th)
🕵️
Rogue Negotiators, Gemini Pulled, Apple’s AI Shift, Disappearing CAPTCHAs, and More! - SWN #526
🕵️
New Study Warns of AI-Driven Extortion Attacks
🕵️
The limits of zero-knowledge for age-verification | Brave
🌐
Faster, safer, stronger: Sophos Firewall v22 security enhancements
🌐
Gootloader malware is back with new tricks after 7-month break
📡
Securing the Open Android Ecosystem with Samsung Knox
📡
Police busts credit card fraud rings with 4.3 million victims
📡
Armis raises $435M pre-IPO round at $6.1B valuation after refusing M&A offers
📡
Google gets the US government’s green light to acquire Wiz for $32B
📡
Cyber theory vs practice: Are you navigating with faulty instruments?
📡
UK carriers to block spoofed phone numbers in fraud crackdown
📡
Windows 11 Store gets Ninite-style multi-app installer feature
📡
Half of the world's satellite traffic is unencrypted | Kaspersky official blog
📡
Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming
📡
How Workers VPC Services connects to your regional private networks from anywhere in the world