111Articles
8Categories
2025-12-18Date
๐Ÿ›
Microsoft warns MSMQ may fail after update, breaking apps
๐Ÿ›
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
KEV
๐Ÿ›
China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear
๐Ÿ›
Critical Node.js Library Flaw Lets Hackers Execute Remote Commands on Windows
๐Ÿ›
CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4
๐Ÿ›
CVE-2025-37968 iio: light: opt3001: fix deadlock due to concurrent flag access
๐Ÿ›
CVE-2025-37959 bpf: Scrub packet on bpf_redirect_peer
๐Ÿ›
CVE-2024-28863 node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
๐Ÿ›
CVE-2025-38375 virtio-net: ensure the received length does not exceed allocated size
๐Ÿ›
CVE-2025-54567 hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
๐Ÿ›
CVE-2025-38350 net/sched: Always pass notifications when child class becomes empty
๐Ÿ›
CVE-2025-38097 espintcp: remove encap socket caching to avoid reference leak
๐Ÿ›
CVE-2025-38334 x86/sgx: Prevent attempts to reclaim poisoned pages
๐Ÿ›
CVE-2025-38362 drm/amd/display: Add null pointer check for get_first_active_display()
๐Ÿ›
CVE-2025-38363 drm/tegra: Fix a possible null pointer dereference
๐Ÿ›
CVE-2025-38335 Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT
๐Ÿ›
CVE-2025-54566 hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
๐Ÿ›
CVE-2025-38095 dma-buf: insert memory barrier before updating num_fences
๐Ÿ›
CVE-2025-38371 drm/v3d: Disable interrupts before resetting the GPU
๐Ÿ›
New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit
๐Ÿ›
Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges
๐Ÿ›
Critical Apache Commons Text Flaw Lets Hackers Execute Remote Code
๐Ÿ›
CISA Warns of Exploited Flaw in Asus Update Tool
๐Ÿ›
HPE Patches Critical Flaw in IT Infrastructure Management Software
๐Ÿ›
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
๐Ÿ›
CVE-2024-6531 Rejected reason: This was not a security issue in Bootstrap. Bootstrapโ€™s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrapโ€™s security model, and the associated CVE has been rescinded.
๐Ÿ›
HPE OneView Vulnerability Allows Remote Code Execution Attacks
๐Ÿ›
Actively Exploited ASUS Vulnerability Added to CISAโ€™s KEV List
KEV
๐Ÿ›
CVE-2025-65046 Microsoft Edge (Chromium-based) Spoofing Vulnerability
๐Ÿ›
Chromium: CVE-2025-14766 Use after free in WebGPU
๐Ÿ›
Chromium: CVE-2025-14765 Out of bounds read and write in V8
๐Ÿ›
CVE-2025-64663 Custom Question Answering Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-65041 Microsoft Partner Center Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-65037 Azure Container Apps Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-64676 Microsoft Purview eDiscovery Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-64675 Azure Cosmos DB Spoofing Vulnerability
๐Ÿ›
CVE-2025-64677 Office Out-of-Box Experience Spoofing Vulnerability
โš ๏ธ
โ€˜Ink Dragonโ€™ threat group targets IIS servers to build stealthy global network
โš ๏ธ
Smashing Security podcast #448: The Kindle that got pwned
โš ๏ธ
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
KEV
โš ๏ธ
Hackers Actively Target Cisco and Palo Alto VPN Gateways to Steal Login Credentials
โš ๏ธ
Cybercriminals Registering Fake Shopping Domains to Target Users This Holiday Season
โš ๏ธ
Cisco AsyncOS 0-Day Allows Remote Execution of System Commands
โš ๏ธ
D&O liability protection rising for security leaders โ€” unless youโ€™re a midtier CISO
โš ๏ธ
SonicWall Patches Exploited SMA 1000 Zero-Day
โš ๏ธ
Cisco confirms zero-day exploitation of Secure Email products
โš ๏ธ
HPE warns of maximum severity RCE flaw in OneView software
โš ๏ธ
Human-in-the-loop isnโ€™t enough: New attack turns AI safeguards into exploits
โš ๏ธ
The Case for Dynamic AI-SaaS Security as Copilots Scale
โš ๏ธ
Motors WordPress Vulnerability Exposes Sites to Takeover - Infosecurity Magazine
โš ๏ธ
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
โš ๏ธ
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories
โš ๏ธ
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
โš ๏ธ
UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
โš ๏ธ
US seizes E-Note crypto exchange for laundering ransomware payments
โš ๏ธ
Someone Boarded a Plane at Heathrow Without a Ticket or Passport
โš ๏ธ
WhatsApp accounts targeted in โ€˜GhostPairingโ€™ attack
โš ๏ธ
A Vulnerability in Cisco AsyncOS Could Allow for Remote Code Execution
โš ๏ธ
FBI Shuts Down Crypto Exchange Linked to Criminal Money Laundering Operations
โš ๏ธ
The innovative CISOโ€™s bucket list: Human-led transformation at the core
โš ๏ธ
With AI Nothing Is Safe - PSW #905
โš ๏ธ
CISA Releases Nine Industrial Control Systems Advisories
๐Ÿ“‹
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues
๐Ÿ“ข
The Raspberry Pi wakeup call: Why enterprises must rethink physical security
๐Ÿ“ข
Russlands Einfluss โ€“ Kritik an Lรผcken bei Cybersicherheit
๐Ÿ“ข
NIS2 compliance: How to get passwords and MFA right
๐Ÿ“ข
Der Raspberry-Pi-Weckruf fรผr CISOs
๐Ÿ“ข
Mozilla security advisory (AV25-849)
๐Ÿ”ฅ
The Botting Network - 96,320 breached accounts
๐Ÿ”ฅ
Microsoft 365 Outage Disrupts Teams, Outlook, and Copilot in Japan and China
๐Ÿ”ฅ
Kimwolf Android Botnet Compromises 1.8 Million Devices Worldwide
๐Ÿ”ฅ
AUTOSUR - 487,226 breached accounts
๐Ÿ”ฅ
Chinese Ink Dragon Breaches European Government Networks, Affecting Asia and South America
๐Ÿ”ฅ
Phantom Stealer Targeting Users to Steal Sensitive Data
๐Ÿ”ฅ
France Probes โ€˜Foreign Interferenceโ€™ After Remote Control Malware Found on Passenger Ferry
๐Ÿ”ฅ
113,000 Impacted by Data Breach at Virginia Mental Health Authority
๐Ÿ”ฅ
Auto Parts Giant LKQ Confirms Oracle EBS Breach
๐Ÿ”ฅ
Tech provider for NHS England confirms data breach
๐Ÿ”ฅ
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
๐Ÿ”ฅ
I am not a robot: ClickFix used to deploy StealC and Qilin
๐Ÿ”ฅ
University of Sydney suffers data breach exposing student and staff info
๐Ÿ”ฅ
Clop ransomware targets Gladinet CentreStack in data theft attacks
๐Ÿ”ฅ
RansomHouse RaaS Enhances Double Extortion with Data Theft and Encryption
๐Ÿ”ฅ
NuGet Malware Mimic: .NET Integration Library Steals Crypto Wallets and OAuth Tokens
๐Ÿ”ฅ
Best Security Awareness Training Platforms For 2026
๐Ÿ•ต๏ธ
ISC Stormcast For Thursday, December 18th, 2025 https://isc.sans.edu/podcastdetail/9744, (Thu, Dec 18th)
๐Ÿ•ต๏ธ
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
๐Ÿ•ต๏ธ
IoT Security Firm Exein Raises โ‚ฌ100 Million
๐Ÿ•ต๏ธ
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft
๐Ÿ•ต๏ธ
New โ€œLies-in-the-Loopโ€ Attack Undermines AI Safety Dialogs - Infosecurity Magazine
๐Ÿ•ต๏ธ
BlueDeltaโ€™s Persistent Campaign Against UKR.NET
๐Ÿ•ต๏ธ
WeChat Phishing Attacks a Growing Threat Outside China
๐Ÿ•ต๏ธ
ShadyPanda: The Silent Browser Takeover Threat and How Qualys TruRisk Eliminate Helps You Stop It | Qualys
๐Ÿ•ต๏ธ
Datenbank mit 4,3 Milliarden Datensรคtzen offen im Netz
๐Ÿ•ต๏ธ
From the Hill: The AI-Cybersecurity Imperative in Financial Services
๐Ÿ•ต๏ธ
Agent Mistakes: A Logistical Challenge
๐Ÿ•ต๏ธ
New Microsoft e-book: 3 reasons point solutions are holding you back
๐Ÿ•ต๏ธ
Unmasking the Deepfake Threat: A Game-Changer for Reducing Human Risk
๐Ÿ•ต๏ธ
New Lazarus and Kimsuky Infrastructure Discovered with Active Tools and Tunneling Nodes
๐Ÿ•ต๏ธ
Beware of Malicious Scripts in Weaponized PDF Purchase Orders
๐Ÿ•ต๏ธ
APT35 Leak Reveals Spreadsheets Containing Domains, Payments, and Server Information
๐Ÿ•ต๏ธ
GachiLoader Deploys Payloads Using Obfuscated Node.js Malware
๐Ÿ•ต๏ธ
Newer RISC-V CPUs Vulnerable To Spectre V1 - Linux Mitigation Patches Posted
๐Ÿ•ต๏ธ
Firmware's Expanding Attack Surface
๐Ÿ•ต๏ธ
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
๐ŸŒ
The Stealka stealer hijacks accounts and steals crypto while masquerading as pirated software | Kaspersky official blog
๐ŸŒ
France arrests Latvian for installing malware on Italian ferry
๐ŸŒ
What Cyber Defenders Really Think About AI Risk
๐Ÿ“ก
Positive trends related to public IP ranges from the year 2025, (Thu, Dec 18th)
๐Ÿ“ก
Microsoft: Recent Windows updates break RemoteApp connections
๐Ÿ“ก
New password spraying attacks target Cisco, PAN VPN gateways