89Articles
7Categories
2025-11-20Date
🐛
7-Zip RCE Vulnerability Actively Exploited by Hackers
KEV
🐛
Oracle Identity Manager Exploit Observation from September (CVE-2025-61757), (Thu, Nov 20th)
🐛
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
🐛
Fortinet criticized for ‘silent’ patching after disclosing second zero-day vulnerability in same equipment
KEV
🐛
CISA Alerts Users to Active Attacks on Chrome 0-Day Vulnerability
KEV
🐛
CVE-2025-64656 Application Gateway Elevation of Privilege Vulnerability
🐛
CVE-2025-64655 Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability
🐛
CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability
🐛
CVE-2025-49752 Azure Bastion Elevation of Privilege Vulnerability
🐛
CVE-2025-62207 Azure Monitor Elevation of Privilege Vulnerability
🐛
CVE-2025-64660 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
🐛
CVE-2025-62459 Microsoft Defender Portal Spoofing Vulnerability
🐛
CVE-2025-64657 Azure Application Gateway Elevation of Privilege Vulnerability
⚠️
Eurofiber - 10,003 breached accounts
⚠️
Vultr - 187,872 breached accounts
⚠️
Attack Surface Management – ein Kaufratgeber
⚠️
Der große KI-Risiko-Guide
⚠️
Selling to the CISO: An open letter to the cybersecurity industry
⚠️
SolarWinds Patches Three Critical Serv-U Vulnerabilities
⚠️
Beckett Collectibles - 541,132 breached accounts
⚠️
Chinese APT Group Exploits DLL Sideloading to Breach Government and Media Targets
⚠️
Ollama Flaws Let Hackers Run Any Code Using Malicious Model Files
⚠️
Recent 7-Zip Vulnerability Exploited in Attacks
⚠️
Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts
⚠️
New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices
⚠️
Scam USPS and E-Z Pass Texts and Websites
⚠️
China‑linked PlushDaemon hijacks DNS via ‘EdgeStepper’ to weaponize software updates
⚠️
Broadcom's Academic License Shock
⚠️
3 ways CISOs can win over their boards this budget season
⚠️
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves
⚠️
Over 50,000 Asus Routers Hacked in ‘Operation WrtHug’
⚠️
API-Exploit für AI-Browser Comet entdeckt
⚠️
D-Link warns of new RCE flaws in end-of-life DIR-878 routers
⚠️
Salesforce investigates customer data theft via Gainsight breach
⚠️
CISA Releases Six Industrial Control Systems Advisories
⚠️
Apple vs Linux: Freedom vs Security
⚠️
ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build Self-Spreading GPU Cryptomining Botnet
⚠️
Salesforce says some of its customers’ data was accessed after Gainsight breach
⚠️
Emerging Ransomware Variants Exploit Amazon S3 Misconfigurations
⚠️
TamperedChef Campaign Exploits Everyday Apps to Deploy Malware and Enable Remote Access
⚠️
Milvus Proxy Flaw Lets Attackers Forge Headers and Skip Authorization
⚠️
Be Prepared: Mobile Phishing Expected to Surge Fourfold During the Holiday Season
⚠️
Give Me Liberty or Linux, Badge Hacking Interview - Bryce Owen - PSW #901
⚠️
The OSINT playbook: Find your weak spots before attackers do
📢
Critical Twonky Server Flaws Let Hackers Bypass Login Protection
📢
NSA Issues New Guidance to Help ISPs and Defenders Stop Malicious Activity
📢
SonicWall security advisory (AV25-774)
📢
VMware security advisory (AV25-775)
📢
UK’s new cybersecurity bill takes aim at ransomware gangs and state-backed hackers
🔥
Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
🔥
Hackers Launch 2.3 Million Attacks on Palo Alto GlobalProtect VPN Portals
🔥
Smashing Security podcast #444: We’re sorry. Wait, did a company actually say that?
🔥
Wind farm worker sentenced after turning turbines into a secret crypto mine
🔥
Turn your Windows 11 migration into a security opportunity
🔥
Hacker claims to steal 2.3TB data from Italian rail group, Almavia
🔥
Report: Ransomware Attacks Surged Globally in October
🔥
Massive Hacking Operation WrtHug Compromises Thousands of ASUS Routers Worldwide
🔥
Authorities Sanction Russia-Based Bulletproof Hosting Provider for Aiding Ransomware
🔥
International Kiteboarding Organization - 340,349 breached accounts
🔥
Hacker claims to steal 2.3TB data from Italian rail group, Almaviva
🕵️
Moving Beyond the NPM elliptic Package
🕵️
ISC Stormcast For Thursday, November 20th, 2025 https://isc.sans.edu/podcastdetail/9708, (Thu, Nov 20th)
🕵️
Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion Deal
🕵️
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign
🕵️
News alert: Seraphic evolves browser security for the AI era with first-of-its-kind Electron protection
🕵️
The Rise of AI-Enhanced Cyber Scams: How GenAI Empowers Criminals
🕵️
The Rise of Hybrid Threat Actors: Digital Meets Physical
🕵️
Researchers Detail Rhadamanthys Loader’s Advanced Anti-Sandboxing and Anti-AV Emulation Techniques
🕵️
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
🕵️
US and Allies Sanction Russian Bulletproof Hosting Service Providers
🕵️
Doppel Raises $70 Million at $600 Million Valuation
🕵️
3.5 Billion Accounts: Complete WhatsApp Directory Retrieved and Evaluated
🕵️
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages
🕵️
Tsundere Botnet Targets Windows, Linux & macOS via Node.js Packages
🕵️
Samourai Wallet Founders Jailed for $237M Crypto Laundering
🕵️
Sturnus Malware Hijacks Signal and WhatsApp, Taking Full Device Control
🕵️
Pi GPT Tool Turns Raspberry Pi into a ChatGPT-Powered Smart Device
🕵️
Google exposes BadAudio malware used in APT24 espionage campaigns
🕵️
Russian Hacking Suspect Wanted by the FBI Arrested on Thai Resort Island
🕵️
Navigating AI: Security Challenges Ahead
🌐
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat
🌐
Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows
📡
Trend & AWS Partner on Cloud IPS: One-Click Protection
📡
Crypto mixer founders sent to prison for laundering over $237 million
📡
TV streaming piracy service with 26M yearly visits shut down
📡
New SonicWall SonicOS flaw allows hackers to crash firewalls
📡
GlobalProtect VPN portals probed with 2.3 million scan sessions
📡
WhatsApp compromise leads to Astaroth deployment
📡
Mozilla Says It’s Finally Done With Two-Faced Onerep