79Articles
8Categories
2025-11-10Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its  Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-21042 Samsung Mobile Devices Out-of-Bounds Write Vulnerability   This type of vulnerability is a frequent attack vector f…
KEV
🐛
Monsta FTP Remote Code Execution Flaw Being Exploited in the Wild
KEV
🐛
Hackers Abuse runc Tool to Escape Containers and Compromise Hosts
🐛
Elastic Defend for Windows Vulnerability Allows Threat Actors to Gain Elevated Access
🐛
LangGraph Deserialization Flaw Enables Execution of Malicious Python Code
🐛
Runtime bugs break container walls, enabling root on Docker hosts
🐛
Popular npm Library Used in AI and NLP Projects Exposes Systems to RCE
🐛
Just a moment...
🐛
Runc Vulnerabilities Can Be Exploited to Escape Containers
🐛
Chromium: CVE-2025-12729 Inappropriate implementation in Omnibox
🐛
Chromium: CVE-2025-12728 Inappropriate implementation in Omnibox
⚠️
US Congressional Budget Office Breach, AI in Cyber Attacks & Veterans Defend Canada
⚠️
New Whisper-Based Attack Reveals User Prompts Hidden Inside Encrypted AI Traffic
⚠️
Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
⚠️
CISOs must prove the business value of cyber — the right metrics can help
⚠️
Why you should purple team your SOC
⚠️
Hackers Exploit Websites to Inject Malicious Links for SEO Manipulation
⚠️
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs
⚠️
Researchers trick ChatGPT into prompt injecting itself
⚠️
Ransomware Operators Exploit RMM Tools to Deploy Medusa and DragonForce
⚠️
QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland
⚠️
Whisper Leak uses a side channel attack to eavesdrop on encrypted AI conversations
⚠️
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
⚠️
⚡ Weekly Recap: Hyper-V Malware, Malicious AI Bots, RDP Exploits, WhatsApp Lockdown and More
⚠️
MAD-CAT “Meow” Tool Sparks Real-World Data Corruption Attacks
⚠️
NuGet Supply-Chain Exploit Uses Timed Destructive Payloads Against ICS
⚠️
Incident Response Team (ShieldForce) Partners with AccuKnox for Zero Trust CNAPP in Latin America
⚠️
Layered security: How SMBs can protect against sophisticated cyberthreats during the holiday season.
⚠️
ATT&CK → ATLAS: A CISO’s Blueprint for AI Governance - Sandy Dunn - CSP #218
⚠️
Popular JavaScript library expr-eval vulnerable to RCE flaw
⚠️
CISA orders feds to patch Samsung zero-day used in spyware attacks
⚠️
Multiple Vulnerabilities in Google Android OS Could Allow for Remote Code Execution
📢
European Commission moves to loosen GDPR for AI and cookie tracking
📢
Dell security advisory (AV25-733)
📢
IBM security advisory (AV25-732)
📢
Ubuntu security advisory (AV25-734)
📢
Red Hat security advisory (AV25-735)
📢
[Control systems] CISA ICS security advisories (AV25–736)
📢
EU's cybersecurity agency reports surge in cyberattacks against public administrations across Europe
📢
EU's cybersecurity agency reports surge in cyberattacks against public administrations across Europe
📢
Cyber information sharing law would get extension under shutdown deal bill | CyberScoop
🔥
Data Leak Exposes Chinese State-Sponsored Cyber Arsenal and Target Database
🔥
APT Groups Target Construction Firms to Steal RDP, SSH, and Citrix Credentials
🔥
Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware
🔥
Hack halts Dutch broadcaster, forcing radio hosts back to LPs
🔥
Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
🔥
Data breach at Chinese infosec firm reveals weapons arsenal • The Register
🔥
Why a lot of people are getting hacked with government spyware
🔥
Android Users Hit by Malware Disguised as Relaxation Programs
🔥
Vibe-codierte Ransomware auf Microsoft Marketplace entdeckt
🔥
Yanluowang initial access broker to plead guilty to ransomware attacks
🔥
Nevada ransomware attack traced back to malware download by employee | Cybersecurity Dive
🔥
Cyberattacks surge against IoT, mobile devices in critical infrastructure | Cybersecurity Dive
🔥
Yanluowang initial access broker pleaded guilty to ransomware attacks
🕵️
ISC Stormcast For Monday, November 10th, 2025 https://isc.sans.edu/podcastdetail/9692, (Mon, Nov 10th)
🕵️
Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case
🕵️
Today I learned: binfmt_misc - dfir.ch - shadow suid
🕵️
HackGPT Launches as AI-Driven Penetration Testing Suite Using GPT-4 and Other Models
🕵️
OT Security Doesn't Have to be a Struggle, Spotting Red Flags, Enterprise News - ESW #432
🕵️
Australia Sanctions Hackers Supporting North Korea’s Weapons Program
🕵️
Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses
🕵️
New Attacks Against Secure Enclaves
🕵️
GlassWorm malware returns on OpenVSX with 3 new VSCode extensions
🕵️
GlassWorm Malware Returns to Open VSX, Emerges on GitHub
🕵️
Dangerous runC flaws could allow hackers to escape Docker containers
🕵️
Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted Traffic
🕵️
Quantum Route Redirect: Anonymous Tool Streamlining Global Phishing Attack
🕵️
Two New Web Application Risk Categories Added to OWASP Top 10
🕵️
Microsoft Teams’ New “Chat with Anyone” Feature Exposes Users to Phishing and Malware Attacks
🕵️
Stadtverwaltung Ludwigshafen kämpft mit IT-Ausfall
🕵️
Many Forbes AI 50 Companies Leak Secrets on GitHub
🕵️
​​Securing our future: November 2025 progress report on Microsoft’s Secure Future Initiative ​​
🕵️
APT37 hackers abuse Google Find Hub in Android data-wiping attacks
🌐
New Browser Security Report Reveals Emerging Threats for Enterprises
📡
5 reasons why attackers are phishing over LinkedIn
📡
It isn't always defaults: Scans for 3CX usernames, (Mon, Nov 10th)
📡
What is FileFix — a ClickFix variation? | Kaspersky official blog
📡
Quantum Route Redirect PhaaS targets Microsoft 365 users worldwide
📡
Mozilla Firefox gets new anti-fingerprinting defenses