78Articles
9Categories
2025-11-21Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-61757 Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability  This type of vulnerability is a frequent …
KEV
🐛
Critical Grafana Flaw Lets Attackers Escalate Privileges
🐛
Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ShadowPad Malware
🐛
Windows Graphics Flaw Lets Hackers Take Over with Just One Image
🐛
Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day
🐛
Critical Azure Bastion Vulnerability Lets Attackers Bypass Login and Gain Higher Privileges
🐛
Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
🐛
Grafana warns of max severity admin spoofing vulnerability
🐛
CISA warns Oracle Identity Manager RCE flaw is being actively exploited
KEV
⚠️
Sneaky2FA phishing tool adds ability to insert legit-looking URLs
⚠️
Major CloudFlare Outages, Black Friday Phishing Surge, AI Privacy Breach at Ontario Hospital, and Salesforce Data Theft Investigation
⚠️
Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity
⚠️
Root causes of security breaches remain elusive — jeopardizing resilience
⚠️
Salesforce Confirms Customer Data Was Exposed in Gainsight Breach
⚠️
Clop Ransomware Claims Oracle Breach Using E-Business Suite 0-Day
⚠️
Ransomware Attacks Poised to Hit Retailers Hard This Holiday Season
⚠️
Salesforce Instances Hacked via Gainsight Integrations
⚠️
SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability
⚠️
Ransomware gangs find a new hostage: Your AWS S3 buckets
⚠️
SonicWall Patches High-Severity Flaws in Firewalls, Email Security Appliance
⚠️
OAuth token compromise hits Salesforce ecosystem again, Gainsight impacted
⚠️
Salesforce flags another third-party security incident • The Register
⚠️
How to turn threat intel into real security wins
KEV
⚠️
North Korean Kimsuky and Lazarus Teams Target Critical Sectors with Zero-Day Exploits
⚠️
Hackers Adopt Matrix Push C2 for Browser-Based Malware and Phishing Attacks
⚠️
Clop Ransomware Claims Broadcom Breach Through E-Business Suite 0-Day
⚠️
From code to boardroom: A GenAI GRC approach to supply chain risk
⚠️
Google says hackers stole data from 200 companies following Gainsight breach
⚠️
Cloud Security Shock: How Hackers Exploit AWS Features!
⚠️
Mercedes F1 Team Principal Toto Wolff Sells 15% Stake to CrowdStrike CEO George Kurtz
⚠️
Risky Biz Soap Box: Greynoise knows when bad bugs are coming
📋
Nvidia confirms October Windows updates cause gaming issues
📢
Recognizing and responding to cyber threats: What differentiates NDR, EDR and XDR
📢
[Control systems] ABB security advisory (AV25-776)
📢
Grafana security advisory (AV25-778)
📢
HPE security advisory (AV25-777)
📢
In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring
🔥
APT24 Deploys New BadAudio Malware, Hijacks Legitimate Public Sites to Launch Attacks
🔥
AI as Cyberattacker
🔥
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains
🔥
Layered Defense: Proactive & Reactive
🔥
'Scattered Spider' teens plead not guilty to UK transport hack
🔥
CrowdStrike fires ‘suspicious insider’ who passed information to hackers
🕵️
ISC Stormcast For Friday, November 21st, 2025 https://isc.sans.edu/podcastdetail/9710, (Fri, Nov 21st)
🕵️
Schatten-IT: Viele Fachkräfte nutzen KI ohne Erlaubnis
🕵️
Operation DreamJob Attacks on Manufacturing via WhatsApp Web
🕵️
Runlayer Emerges From Stealth Mode With $11 Million in Funding
🕵️
Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks
🕵️
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign
🕵️
Hackerangriff auf Music Store
🕵️
New SonicWall SonicOS flaw allows hackers to crash firewalls
🕵️
SolarWinds Patches Three Critical Serv-U Vulnerabilities - SecurityWeek
🕵️
New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices
🕵️
Over 370 Organizations Take Part in GridEx VIII Grid Security Exercise
🕵️
Hacker claims to steal 2.3TB data from Italian rail group, Almaviva
🕵️
Report: Deepfake Attacks Are on the Rise
🕵️
Xillen Stealer: Advanced Features Bypass AI Detection and Steal Password Manager Data
🕵️
AI-Driven Obfuscated Malicious Apps Bypassing Antivirus Detection to Deliver Malicious Payloads
🕵️
Dark Web Job Market Evolved – Prioritizes Practical Skills Over Formal Education
🕵️
Windows 11 to Prevent BSOD Error Messages from Showing Publicly
🕵️
UNC2891 Hackers Use Raspberry Pi and Fake Cards to Steal ATM Cash
🕵️
The Tsundere botnet uses the Ethereum blockchain to infect its targets
🕵️
CrowdStrike catches insider feeding information to hackers
🕵️
AI-Driven Personalized Interventions
🕵️
Microsoft named a Leader in the Gartner® Magic Quadrant™ for Access Management for the ninth consecutive year
🕵️
More on Rewiring Democracy
🕵️
Friday Squid Blogging: New “Squid” Sneaker
🕵️
Emoticons, Sonicwall, Global Protect, Pop ups, WhatsApp, 7Zip, Roblox, Josh Marpet - SWN #531
🌐
SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny
🌐
Syncro + Lovable: RAT delivery via AI-generated websites | Kaspersky official blog
📡
Use of CSS stuffing as an obfuscation technique?, (Fri, Nov 21st)
📡
Why IT Admins Choose Samsung for Mobile Security
📡
Google begins showing ads in AI Mode (AI answers)
📡
Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security
📡
Despite Chinese hacks, Trump’s FCC votes to scrap cybersecurity rules for phone and internet companies
📡
Avast Makes AI-Driven Scam Defense Available for Free Worldwide
📡
FCC rolls back cybersecurity rules for telcos, despite state-hacking risks
📡
Microsoft: Out-of-band update fixes Windows 11 hotpatch install loop