103Articles
10Categories
2025-11-12Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Vulnerability CVE-2025-12480 Gladinet Triofox Improper Access Control Vulnerability CVE-2…
KEV
🐛
November Patch Tuesday: Zero day Windows kernel flaw in servers, controllers, and PCs
KEV
🐛
Mozilla Issues Urgent Firefox Update to Patch Critical Code Execution Flaws
🐛
Windows Kernel 0-Day Under Active Exploitation for Privilege Escalation
🐛
Chrome Security Update Fixes Improper Implementation in V8 JavaScript Engine
🐛
Microsoft SQL Server Vulnerability Allows Privilege Escalation
🐛
Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
🐛
CVE-2024-12649: vulnerability in the Canon TTF interpreter
🐛
Update: Implementation Guidance for Emergency Directive on Cisco ASA and Firepower Device Vulnerabilities
⚠️
WhatsApp Malware 'Maverick' Hijacks Browser Sessions to Target Brazil's Biggest Banks
⚠️
Lite XL Vulnerability Allows Attackers to Execute Arbitrary Code
⚠️
New Phishing Scam Targets iPhone Owners After Device Loss
⚠️
The security leaders who turned their frustrations into companies
⚠️
Enterprise network security blighted by legacy and unpatched systems
⚠️
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider
⚠️
GitHub Copilot and Visual Studio Flaws Let Attackers Bypass Security Protections
⚠️
Authentication Coercion: How Windows Machines Are Tricked into Leaking Credentials
⚠️
Beyond the checklist: Shifting from compliance frameworks to real-time risk assessments
⚠️
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
⚠️
Rhadamanthys Stealer Servers Reportedly Seized; Admin Urges Immediate Reinstallation
⚠️
Hackers Exploit SSRF Flaw in Custom GPTs to Steal ChatGPT Secrets
⚠️
Malicious npm package sneaks into GitHub Actions builds
⚠️
North Korean hackers exploit Google’s safety tools for remote wipe | CSO Online
⚠️
MastaStealer Exploits Windows LNK to Launch PowerShell and Bypass Defender
⚠️
UK cybersecurity bill brings tougher rules for critical infrastructure
⚠️
Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
⚠️
SecureVibes Introduces Multi-Language Vulnerability Scanner Powered by Claude AI
⚠️
Weekly Update 477
⚠️
Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws
⚠️
How TTP-based Defenses Outperform Traditional IoC Hunting
⚠️
DanaBot malware is back to infecting Windows after 6-month break
⚠️
Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform
⚠️
Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
📋
Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel
📋
Microsoft releases KB5068781 — The first Windows 10 extended security update
📋
AppleScript Used to Deliver macOS Malware Disguised as Zoom & Teams Updates
📋
November Patch Tuesday does its chores
📢
IBM Infrastructure: Continuous Risk & Compliance
📢
Securing Model Context Protocol as Companies Plan to Replace Entry Roles with AI - BSW #421
📢
New UK laws to strengthen critical infrastructure cyber defenses
📢
GitHub security advisory (AV25-737)
📢
SAP security advisory – November 2025 monthly rollup (AV25-738)
📢
Microsoft security advisory – November 2025 monthly rollup (AV25-739)
📢
Adobe security advisory (AV25-741)
📢
Citrix security advisory (AV25-740)
📢
Google Chrome security advisory (AV25-742)
📢
HPE security advisory (AV25-743)
📢
Intel security advisory (AV25-744)
📢
Microsoft Edge security advisory (AV25-745)
📢
Ivanti security advisory (AV25-746)
📢
CISA Identifies Ongoing Cyber Threats to Cisco ASA and Firepower Devices
📢
Mozilla security advisory (AV25-747)
📢
Palo Alto Networks security advisory (AV25-748)
📢
[Control systems] Siemens security advisory (AV25-749)
🔥
Industrial Phishing Kit QRR Discovered: New Cyber Threats Unveiled | Cybersecurity Today
🔥
Tor Browser 15.0.1 Update Patches Several High-Risk Security Flaws
🔥
English-Speaking Cybercriminal Network ‘The COM’ Drives Global Cyberattacks
🔥
Russian hacker admits helping Yanluowang ransomware infect companies
🔥
Synnovis notifies of data breach after 2024 ransomware attack
🔥
Cl0p Ransomware Lists NHS UK as Victim, Days After Washington Post Breach – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
🔥
Have I Been Pwned Adds 1.96B Accounts From Synthient Credential Data – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
🔥
Qilin Ransomware Activity Surges as Attacks Target Small Businesses - Infosecurity Magazine
🔥
Wie ChatGPT sich selbst eine Prompt Injection zufügt
🔥
Synnovis notifies of data breach after 2024 ransomware attack
🕵️
ISC Stormcast For Wednesday, November 12th, 2025 https://isc.sans.edu/podcastdetail/9696, (Wed, Nov 12th)
🕵️
Chinese National Sentenced for Laundering Over £5 Billion from 128,000 Victims
🕵️
Phishing Attack Impersonates Travel Brands Using 4,300 Malicious Domains
🕵️
Google Paid Out $458,000 at Live Hacking Event
🕵️
Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case
🕵️
On Hacking Back
🕵️
High-Severity Vulnerabilities Patched by Ivanti and Zoom
🕵️
Phishers target 5K Facebook advertisers with fake biz pages • The Register
🕵️
Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit
🕵️
Australian spy chief warns Chinese hackers are ‘probing’ critical networks for espionage and sabotage
🕵️
A Policy Roadmap for Secure AI by Design
🕵️
Sweet Security Raises $75 Million for Cloud and AI Security
🕵️
Npm Package Targeting GitHub-Owned Repositories Flagged as Red Team Exercise
🕵️
Miniatur Wunderland Hamburg warnt vor Datendiebstahl
🕵️
Hackers abuse Triofox antivirus feature to deploy remote access tools
🕵️
Virtual Event Today: CISO Forum 2025 Virtual Summit
🕵️
China’s Cyber Silence is More Worrying Than Russia’s Noise, Chief Cybersecurity Strategist Says
🕵️
What are You Working on Wednesday
🕵️
DanaBot malware is back to infecting Windows after 6-month break
🕵️
Warning: ClickFix Attacks are Growing More Sophisticated
🌐
Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security
🎙️
Risky Business #814 -- It's a bad time to be a scam compound operator
📡
Red Bull Racing’s secret weapon? An engineer who treats workflows like lap times
📡
Google Launches 'Private AI Compute' — Secure AI Processing with On-Device-Level Privacy
📡
Microsoft fixes Windows Task Manager bug affecting performance
📡
[Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR
📡
Sophos Firewall v22: Your top-requested features
📡
Defending the future: Our commitment to responsible AI in cybersecurity
📡
Microsoft fixes bug causing false Windows 10 end-of-support alerts
📡
Extending Zero Trust to AI Agents: “Never Trust, Always Verify” Goes Autonomous
📡
Leading AI companies accidentally leak their passwords and digital keys on GitHub – what you need to know
📡
Lawmakers warn Democratic governors that states are sharing drivers’ data with ICE
📡
Windows 11 now supports 3rd-party apps for native passkey management
📡
From Data Loss Prevention (DLP) to Modern Data Security
📡
Elon Musk’s X botched its security key switchover, locking users out
📡
Cybersecurity firm Deepwatch lays off dozens, citing move to “accelerate” AI investment
📡
Google sues to dismantle Chinese platform behind global toll scams
📡
Google sues to dismantle Chinese phishing platform behind US toll scams
📡
SmartApeSG campaign uses ClickFix page to push NetSupport RAT, (Wed, Nov 12th)