117Articles
9Categories
2025-12-03Date
๐Ÿšจ
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-26828 OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability  This type of vulnerability is a frequent attackโ€ฆ
KEV
๐Ÿ›
CISA Alerts on Iskra iHUB Authentication Flaw Allowing Remote Device Reconfiguration
๐Ÿ›
Critical Elementor Plugin Flaw Allows Attackers to Seize WordPress Admin Control
๐Ÿ›
Angular Platform Vulnerability Lets Attackers Execute Code Through Malicious SVG Animations
๐Ÿ›
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
๐Ÿ›
CISA Issues Alert on Actively Exploited Android Zero-Day Vulnerability
KEV
๐Ÿ›
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation
๐Ÿ›
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution
๐Ÿ›
Critical flaw in WordPress add-on for Elementor exploited in attacks
๐Ÿ›
CVE-2025-38659 gfs2: No more self recovery
๐Ÿ›
CVE-2025-38626 f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode
๐Ÿ›
CVE-2025-38643 wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
๐Ÿ›
CVE-2025-38615 fs/ntfs3: cancle set bad inode after removing name fails
๐Ÿ›
CVE-2025-38597 drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port
๐Ÿ›
CVE-2025-11494 GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds
๐Ÿ›
CVE-2025-58183 Unbounded allocation when parsing GNU sparse map in archive/tar
๐Ÿ›
CVE-2022-24736 A Malformed Lua script can crash Redis
๐Ÿ›
CVE-2022-24735 Lua scripts can be manipulated to overcome ACL rules in Redis
๐Ÿ›
CVE-2025-12888 Constant Time Issue with Xtensa-based ESP32 and X22519
๐Ÿ›
CVE-2025-11931 Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt
๐Ÿ›
CVE-2025-11932 Timing Side-Channel in PSK Binder Verification
๐Ÿ›
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
๐Ÿ›
CVE-2025-61915 OpenPrinting CUPS vulnerable to stack based out-of-bound write
๐Ÿ›
CVE-2025-11936 Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
๐Ÿ›
CVE-2025-12889 TLS 1.2 Client Can Downgrade Digest Used
๐Ÿ›
CVE-2025-64505 LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
๐Ÿ›
CVE-2025-64506 LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images
๐Ÿ›
CVE-2025-66221 Werkzeug safe_join() allows Windows special device names
๐Ÿ›
CVE-2025-12638 Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()
โš ๏ธ
News alert: Report warns AI is acting as an ungoverned identity with scant data oversight
โš ๏ธ
Cyber Startup Frenetik Launches with Patented Deception Technology That Bets Against the AI Arms Race
โš ๏ธ
How CISOs can prepare for the new era of short-lived TLS certificates
โš ๏ธ
Water Saci Hackers Exploit AI Tools to Target WhatsApp Web Users
โš ๏ธ
Multiple Django Vulnerability Expose Applications to SQL Injection and DoS Attacks
โš ๏ธ
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Code
โš ๏ธ
Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems
โš ๏ธ
Authorities Seize Domains Linked to Tai Chang Cryptocurrency Investment Scam
โš ๏ธ
New โ€œExecutive Awardโ€ Scam Exploits ClickFix to Deliver Stealerium Malware
โš ๏ธ
Shadow Risks in SaaS, Cybersecurity Market Has Lost Its Mind, and Rise of the CTrO - BSW #424
โš ๏ธ
AI, automation, and integration: The foundation for cyber protection in 2026
โš ๏ธ
Microsoft Silently Mitigated Exploited LNK Vulnerability
โš ๏ธ
Letโ€™s Encrypt Cutting Certificate Lifespan from 90 Days to 45 Days
โš ๏ธ
Longwatch RCE Flaw Allows Attackers to Run Remote Code with Elevated Privileges
โš ๏ธ
Massive Phishing Attack Uses Parking Ticket and Medical Test Themes, Attributed to Storm-0900
โš ๏ธ
Critical King Addons Vulnerability Exploited to Hack WordPress Sites
โš ๏ธ
Neue bรถsartige Browser-Erweiterungen entdeckt
โš ๏ธ
Two Android 0-day bugs patched, plus 105 more fixes โ€ข The Register
โš ๏ธ
Deep dive into DragonForce ransomware and its Scattered Spider connection
โš ๏ธ
Get poetic in prompts and AI will break its guardrails
โš ๏ธ
CISA, Australia, and Partners Author Joint Guidance on Securely Integrating Artificial Intelligence in Operational Technology
โš ๏ธ
Microsoft "mitigates" Windows LNK flaw exploited as zero-day
โš ๏ธ
Android expands pilot for in-call scam protection for financial apps
โš ๏ธ
Freedom Mobile discloses data breach exposing customer data
โš ๏ธ
RCE flaw in OpenAIโ€™s Codex CLI highlights new risks to dev environments
โš ๏ธ
BRICKSTORM Backdoor
๐Ÿ“‹
Risky Business #817 -- Less carnage than your usual Thanksgiving
๐Ÿ“ข
After intense backlash, India pulls mandate to pre-install government app on smartphones
๐Ÿ“ข
GitHub security advisory (AV25-803)
๐Ÿ“ข
Google Chrome security advisory (AV25-802)
๐Ÿ“ข
Splunk security advisory (AV25-805)
๐Ÿ”ฅ
Living off the Land Attacks and Emerging Cyber Threats
๐Ÿ”ฅ
Researchers Catch Lazarus Groupโ€™s Recruitment Workflow on Camera via Honeypot
๐Ÿ”ฅ
Threat Actors Using Matanbuchus Downloader to Deliver Ransomware and Maintain Persistence
๐Ÿ”ฅ
MuddyWater Targets Critical Infrastructure With Custom Malware and Evolving Tactics
๐Ÿ”ฅ
Penn and Phoenix Universities Disclose Data Breach After Oracle Hack
๐Ÿ”ฅ
Shai-Hulud 2.0 Cyberattack Compromises 30,000 Repos and Exposes 500 GitHub Accounts
๐Ÿ”ฅ
University of Phoenix discloses data breach after Oracle hack
๐Ÿ”ฅ
Everest Ransomware Claims ASUS Breach and 1TB Data Theft โ€“ Hackread โ€“ Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
๐Ÿ”ฅ
The State of Ransomware in Manufacturing and Production 2025
๐Ÿ”ฅ
Hybrid 2FA phishing kits are making attacks harder to detect
๐Ÿ”ฅ
Examining the Risk of AI-Assisted MedusaLocker Ransomware Attacks
๐Ÿ”ฅ
Fintech firm Marquis alerts dozens of US banks and credit unions of a data breach after ransomware attack
๐Ÿ”ฅ
French DIY retail giant Leroy Merlin discloses a data breach
๐Ÿ”ฅ
ValleyRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
๐Ÿ”ฅ
Fintech firm Marquis alerts dozens of US banks and credit unions of a data breach after ransomware attack
๐Ÿ”ฅ
Marquis data breach impacts over 74 US banks, credit unions
๐Ÿ”ฅ
Why Does Have I Been Pwned Contain "Fake" Email Addresses?
๐Ÿ•ต๏ธ
ISC Stormcast For Wednesday, December 3rd, 2025 https://isc.sans.edu/podcastdetail/9722, (Wed, Dec 3rd)
๐Ÿ•ต๏ธ
BPFDoor and Symbiote: Advanced eBPF-Based Rootkits Target Linux Systems
๐Ÿ•ต๏ธ
Chrome 143 Update Patches 13 Security Vulnerabilities Allowing Arbitrary Code Execution
๐Ÿ•ต๏ธ
Cybersicherheit fรผr viele Nebensache
๐Ÿ•ต๏ธ
Glassworm's resurgence - Secure Annex
๐Ÿ•ต๏ธ
Chrome 143 Patches High-Severity Vulnerabilities
๐Ÿ•ต๏ธ
New Stealth K.G.B RAT Marketed by Threat Actors on Underground Forums
๐Ÿ•ต๏ธ
re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities
๐Ÿ•ต๏ธ
ServiceNow to Acquire Identity Security Firm Veza in Reported $1 Billion Deal
๐Ÿ•ต๏ธ
AI: A Research Assistant, Not a Replacement
๐Ÿ•ต๏ธ
Arizona Attorney General Sues Chinese Online Retailer Temu Over Data Theft Claims
๐Ÿ•ต๏ธ
New Calendly-Inspired Phishing Attack Aims to Steal Google Workspace Credentials
๐Ÿ•ต๏ธ
Malicious Rust โ€œevm-unitsโ€ Impersonator Deploys OS-Specific Payloads
๐Ÿ•ต๏ธ
Niobium Raises $23 Million for FHE Hardware Acceleration
๐Ÿ•ต๏ธ
Researchers Capture Lazarus APT's Remote-Worker Scheme Live on Camera
๐Ÿ•ต๏ธ
Critical PickleScan Vulnerabilities Expose AI Model Supply Chains - Infosecurity Magazine
๐Ÿ•ต๏ธ
Fake Calendly invites spoof top brands to hijack ad manager accounts
๐Ÿ•ต๏ธ
OBR WordPress plugin blunder caused UK budget leak| Cybernews
๐Ÿ•ต๏ธ
KnowBe4 Is a Leader In the Gartnerยฎ Magic Quadrantโ„ข for Email Security For the Second Consecutive Year
๐Ÿ•ต๏ธ
What are You Working on Wednesday
๐Ÿ•ต๏ธ
Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud
๐Ÿ•ต๏ธ
Microsoft Confirms Windows 11 25H2 UI Features Broken also Along With 24H2 Following Update
๐Ÿ•ต๏ธ
Beware of the New 'Executive Award' Campaign That Uses ClickFix to Deliver Stealerium Malware
๐Ÿ•ต๏ธ
AI Browsers: New Attack Surface
๐Ÿ•ต๏ธ
New Criminal Toolkit Abuses Browser Push Notifications
๐Ÿ•ต๏ธ
Incentivizing Change in OT Communities
๐Ÿ•ต๏ธ
The Maturity Gap: The Next Frontier in Threat Intelligence
๐ŸŒ
Aisuru botnet behind new record-breaking 29.7 Tbps DDoS attack
๐ŸŒ
Intellexaโ€™s Global Corporate Web
๐Ÿ“ก
Chopping AI Down to Size: Turning Disruptive Technology into a Strategic Advantage
๐Ÿ“ก
Discover the AI Tools Fueling the Next Cybercrime Wave โ€” Watch the Webinar
๐Ÿ“ก
New Joint Guide Advances Secure Integration of Artificial Intelligence in Operational Technology
๐Ÿ“ก
FBI warns of surge in account takeover (ATO) fraud schemes โ€“ what you need to know
๐Ÿ“ก
Google expands Android scam protection feature to Chase, Cash App in U.S.
๐Ÿ“ก
Russia blocks Roblox over distribution of LGBT "propaganda"
๐Ÿ“ก
Joint guidance on principles for the secure integration of artificial intelligence in operational technology
๐Ÿ“ก
Attempts to Bypass CDNs, (Wed, Dec 3rd)
๐Ÿ“ก
โ€˜End-to-end encryptedโ€™ smart toilet camera is not actually end-to-end encrypted
๐Ÿ“ก
React security advisories (AV25-804)
๐Ÿ“ก
[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)