81Articles
7Categories
2025-11-24Date
🐛
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access
🐛
PoC Published for W3 Total Cache Flaw Exposing 1M+ Sites to RCE
🐛
vLLM Flaw Allows Remote Code Execution Through Malicious Payloads
🐛
Oracle OIM zero‑day: Pre‑auth RCE forces rapid patching across enterprises
KEV
🐛
CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
KEV
🐛
NVIDIA Isaac-GROOT Flaws Let Attackers Inject Malicious Code
⚠️
The CISO’s greatest risk? Department leaders quitting
⚠️
Aligning teams for effective remediation, Anthropic's latest report, and the news - ESW #434
⚠️
Iberia Airlines Hit by Data Breach Exposing Customer Personal Details
⚠️
Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
⚠️
Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges
⚠️
Grafana warns of max severity admin spoofing vulnerability
⚠️
JPMorgan, Citi, Morgan Stanley assess fallout from SitusAMC data breach
⚠️
CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
KEV
⚠️
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More
⚠️
Invisible battles: How cybersecurity work erodes mental health in silence and what we can do about it
⚠️
Harvard University discloses data breach affecting alumni, donors
⚠️
Conflicts between URL mapping and URL based access control., (Mon, Nov 24th)
⚠️
CrowdStrike Insider Helped Hackers Falsely Claim System Breach
⚠️
What keeps CISOs awake at night — and why Zurich might hold the cure
⚠️
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions
⚠️
Tracking RondoDox: Malware Exploiting Many IoT Vulnerabilities
⚠️
Real-estate finance services giant SitusAMC breach exposes client data
⚠️
​​Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications​
⚠️
Is Your Android TV Streaming Box Part of a Botnet?
⚠️
Aligning teams for effective remediation, Anthropic's latest report, and the news - ESW #434
⚠️
Hackers Leveraging WhatsApp to Silently Harvest Logs and Contact Details
⚠️
Attackers Swap ‘m’ with ‘rn’ in Microsoft.com to Trick Users
⚠️
A Vulnerability in SonicOS Could Allow for Denial of Service (DoS)
⚠️
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
⚠️
Tracking RondoDox: Malware Exploiting Many IoT Vulnerabilities
📢
Checkout.com Takes a Bold Stance, SolarWinds Case Dismissed, and FCC Reverses Mandate
📢
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs
📢
Microsoft to remove WINS support after Windows Server 2025
📢
SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching
📢
CrowdStrike Researchers Identify Hidden Vulnerabilities in AI-Coded Software
📢
Dell security advisory (AV25-779)
📢
Ubuntu security advisory (AV25-781)
📢
IBM security advisory (AV25-780)
📢
[Control systems] CISA ICS security advisories (AV25-782)
📢
VMware security advisory (AV25-784)
📢
Red Hat security advisory (AV25-783)
🔥
146,000 Impacted by Delta Dental of Virginia Data Breach
🔥
Spanish Airline Iberia Notifies Customers of Data Breach
🔥
Zapier’s NPM Account Hacked, Multiple Packages Infected with Malware
🔥
AI: End of Cybersecurity?
🔥
Cox Enterprises discloses Oracle E-Business Suite data breach
🔥
Mazda Says No Data Leakage or Operational Impact From Oracle Hack
🔥
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
🔥
Iberia discloses customer data leak after vendor security breach
🔥
Microsoft Highlights Security Risks Introduced by New Agentic AI Feature
🔥
AWS S3-Buckets im Visier von Ransomware-Banden
🔥
US banks scramble to assess data theft after hackers breach financial tech firm
🔥
Elephant Group Launches Defense Sector Attacks Using MSBuild-Delivered Python Backdoor
🔥
APT35 Data Leak Uncovers the Iranian Hacker Group’s Operations and Tactics
🕵️
ISC Stormcast For Monday, November 24th, 2025 https://isc.sans.edu/podcastdetail/9712, (Mon, Nov 24th)
🕵️
Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims
🕵️
LLMs Tools Like GPT-3.5-Turbo and GPT-4 Fuel the Development of Fully Autonomous Malware
🕵️
Malicious PyPI Package Used by Hackers to Steal Users’ Crypto Information
🕵️
New EtherHiding Technique Uses Web Attacks to Deploy Malware and Rotate Payloads
🕵️
North Korean Scam Job Platform Targets U.S. AI Developers
🕵️
Tenda N300 Flaws Allow Attackers to Run Commands as Root
🕵️
ToddyCat APT Targeting Internal Employee Communications at Organizations
🕵️
Python-Based Malware Enables Stealthy Process Injection into Legitimate Windows Binaries
🕵️
IACR Nullifies Election Because of Lost Decryption Key
🕵️
Linux 6.18-rc7 Released With New Bug Fixes and Driver Updates
🕵️
JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack, NYT reports
🕵️
Microsoft's Limitations in Non-Employee Management
🕵️
ClickFix attack uses fake Windows Update screen to push malware
🕵️
Automating Cryptographic Inventory
🕵️
Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
🌐
Operation Endgame disrupts Rhadamanthys information-stealing malware
🌐
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
🌐
Malicious Blender model files deliver StealC infostealing malware
📡
Microsoft: Windows 11 24H2 bug crashes Explorer and Start Menu
📡
Microsoft tests File Explorer preloading for faster performance
📡
Modernizing trust: How UADY transformed campus security with Sophos
📡
The Sophos Central UAE region is now live!
📡
Introducing Sophos DNS Protection for Endpoints
📡
DOGE days are over as Trump disbands Elon Musk’s team of federal cost-cutters
📡
MDR is the answer – now, what’s the question?