89Articles
9Categories
2025-12-10Date
🚨
Hundreds of Ivanti EPM systems exposed online as critical flaw patchedIvanti has patched a critical vulnerability in Endpoint Manager that enables attackers to hijack administrator sessions without authentication and potentially control thousands of enterprise devices. The company released EPM version 2024 SU4 SR1 to address four vulnerabilities, i…
KEV
🐛
December Patch Tuesday: Windows Cloud Files Mini Filter Driver hole already being exploited
KEV
🐛
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws
🐛
CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation
🐛
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups
KEV
🐛
High-Risk Ivanti EPM Vulnerability Opens Door to Admin Session Hijacking
🐛
Windows Defender Firewall Flaw Allows Attackers to Access Sensitive Data
🐛
PeerBlight Linux Malware Abuses React2Shell for Proxy Tunneling
🐛
Microsoft Outlook Flaw Lets Attackers Execute Malicious Code Remotely
🐛
Windows PowerShell 0-Day Lets Attackers Execute Arbitrary Code
🐛
Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection), (Wed, Dec 10th)
⚠️
GitHub Action Secrets aren’t secret anymore: exposed PATs now a direct path into cloud environments
⚠️
Tools, um MCP-Server abzusichern
⚠️
Google Chrome's AI Safety Plan? More AI
⚠️
Polymorphic AI malware exists — but it’s not what you think
KEV
⚠️
Key cybersecurity takeaways from the 2026 NDAA
⚠️
Intel, AMD Processors Affected by PCIe Vulnerabilities
⚠️
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
KEV
⚠️
Salesforce Security Risks, Boards Duty of Care, and Managing CISO Risks - Justin Hazard - BSW #425
⚠️
SAP Patches Critical Vulnerabilities With December 2025 Security Updates
⚠️
Ivanti EPM Update Patches Critical Remote Code Execution Flaw
⚠️
Webinar: How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes
⚠️
KI-Browser gefährden Unternehmen
⚠️
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data
⚠️
Cybercriminals Use Fake Game Updates on Itch.io and Patreon to Push Lumma Stealer
⚠️
Gemini Zero-Click Flaw Let Attackers Access Gmail, Calendar, and Google Docs
⚠️
Microsoft Releases New Guidance to Combat the Shai-Hulud 2.0 Supply Chain Threat
⚠️
Quantum meets AI: The next cybersecurity battleground
⚠️
Cursor lacks spending caps, researchers warn ​ | Cybernews
⚠️
Report: Phishing Has Surged 400% Year-Over-Year
⚠️
Microsoft Patches 57 Vulnerabilities, Three Zero-Days - SecurityWeek
⚠️
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling
⚠️
Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer
⚠️
Why a secure software development life cycle is critical for manufacturers
⚠️
Salesforce's Evolving Data Landscape
⚠️
Vulnerability-Lookup 2.19.0
⚠️
Behind the breaches: Case studies that reveal adversary motives and modus operandi
⚠️
How can staff+ security engineers force-multiply their impact?
⚠️
Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
⚠️
HTTPS certificate industry phasing out less secure domain validation methods
⚠️
Salesforce Backups: A Hidden Risk?
⚠️
Risky Business #818 -- React2Shell is a fun one
📋
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider
📢
CISA and FBI Warn of Pro-Russia Hacktivist Attacks on Critical Infrastructure Worldwide
📢
Joint cyber security advisory on pro-Russia hacktivists conducting opportunistic attacks on global critical infrastructure
📢
Multiple India-based CCTV Cameras | CISA
📢
Ivanti security advisory (AV25-824)
📢
Adobe security advisory (AV25-823)
📢
[Control systems] Schneider Electric security advisory (AV25-825)
📢
Jenkins security advisory (AV25-826)
📢
Microsoft Teams to warn of suspicious traffic with external domains
🔥
Four years later, Irish health service offers €750 to victims of ransomware attack
🔥
Ukrainian hacker charged with helping Russian hacktivist groups
🔥
FortiGuard Team Uncovers Stealth Forensic Data Within Windows Telemetry
🔥
ChrimeraWire Trojan Fakes Chrome Activity to Manipulate Search Rankings – Hackread – Cybersecurity News, Data Breaches, AI, and More
🔥
Hackers claim Volkswagen dealer data is for sale | Cybernews
🔥
Spiderman Phishing Kit Targets European Banks with Real-Time Credential Theft – Hackread – Cybersecurity News, Data Breaches, AI, and More
🔥
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach - SecurityWeek
🔥
CEO of South Korean retail giant Coupang resigns after massive data breach
🕵️
ISC Stormcast For Wednesday, December 10th, 2025 https://isc.sans.edu/podcastdetail/9732, (Wed, Dec 10th)
🕵️
UK Sanctions Russian and Chinese Firms Suspected of Being ‘Malign Actors’ in Information Warfare
🕵️
Personal Branding geht auch ohne Agentur
🕵️
FBI Warns of Fake Video Scams
🕵️
Poland arrests Ukrainians utilizing 'advanced' hacking equipment
🕵️
Fortinet Patches Critical Authentication Bypass Vulnerabilities
🕵️
AI-Powered Analysis Exposes Massive 5,000-Domain Chinese Malware Operation
🕵️
Notepad++ updater installed malware
🕵️
US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups
🕵️
DocuSign phishing ranks as top inbox threat, analysis finds | SC Media
🕵️
Parrot 7.0 Beta Introduces Debian 13 and a Fully Redesigned Desktop
🕵️
What are You Working on Wednesday
🕵️
Virtual Event Today: Cyber AI & Automation Summit
🕵️
Israeli Cybersecurity Funding Hits $4.4 Billion Record High
🕵️
Clarity in complexity: New insights for transparent email security
🕵️
Navigating the Risks of AI-Driven Browsers
🕵️
From awareness to action: Building a security-first culture for the agentic AI era
🕵️
Social Engineering Campaign Targets Microsoft Teams Users
🕵️
Trend Vision One™ Stacks Up Against Scattered Spider and Mustang Panda in 2025 MITRE ATT&CK® Evaluations
🕵️
Malicious Apprentice | How Two Hackers Went From Cisco Academy to Cisco CVEs
🌐
Petco takes down Vetco website after exposing customers’ personal information
🌐
A stealer hiding in Blender 3D models | Kaspersky official blog
🌐
New DroidLock malware locks Android devices and demands a ransom
🌐
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware
📡
Trend Vision One™ Integration with AWS Security Hub CSPM: Unifying Cloud Security
📡
New Spiderman phishing service targets dozens of European banks
📡
Sophos achieves its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation
📡
Over 10,000 Docker Hub images found leaking credentials, auth keys
📡
Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece
📡
Implications of Russia-India-China Trilateral Cooperation