97Articles
8Categories
2025-12-19Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-14733 WatchGuard Firebox Out-of-Bounds Write Vulnerability  This type of vulnerability is a frequent attack vector for malicious cyb…
KEV
🐛
HPE OneView vulnerable to remote code execution attack
🐛
React2Shell is the Log4j moment for front end development
🐛
CVE-2025-37951 drm/v3d: Add job to pending list if the reset was skipped
🐛
CVE-2025-38063 dm: fix unconditional IO throttle caused by REQ_PREFLUSH
🐛
CVE-2025-38071 x86/mm: Check return value from memblock_phys_alloc_range()
🐛
CVE-2025-38074 vhost-scsi: protect vq->log_used with vq->mutex
🐛
CVE-2025-38067 rseq: Fix segfault on registration when rseq_cs is non-zero
🐛
CVE-2025-38118 Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
🐛
CVE-2025-38126 net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping
🐛
CVE-2025-38131 coresight: prevent deactivate active config while enabling the config
🐛
New Linux Kernel Rust Vulnerability Triggers System Crashes
🐛
WatchGuard Zero-Day Actively Exploited to Seize Control of Firewalls
KEV
🐛
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability
🐛
WatchGuard fixes ‘critical’ zero-day allowing firewall takeover
KEV
🐛
Hackers Leverage Gladinet Triofox 0-Day Vulnerability to Run Malicious Code
🐛
Apache Log4j Flaw Enables Interception of Sensitive Logging Data
🐛
New Kibana Vulnerabilities Allow Attackers to Embed Malicious Scripts
🐛
Vulnerability-Lookup 2.20.0
⚠️
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
⚠️
On the Zero Day of Christmas - Cisco Devices Under Attack
⚠️
Managing agentic AI risk: Lessons from the OWASP Top 10
⚠️
News alert: INE expands partnerships to scale hands-on cyber training across Middle East, Asia
⚠️
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
⚠️
Microsoft Patches MSMQ Flaw That Affects IIS Web Servers
⚠️
Roundcube Flaws Let Attackers Execute Malicious Scripts
⚠️
Clop Ransomware Group Targets Gladinet CentreStack Servers to Exfiltrate Data
⚠️
OpenAI’s GPT-5.2 Codex Boosts Agentic Coding and Cyber Vulnerability Detection
⚠️
New critical WatchGuard Firebox firewall flaw exploited in attacks
KEV
⚠️
Cisco bestätigt Zero-Day-Exploit für Secure Email
⚠️
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks
⚠️
Attackers bring their own passwords to Cisco and Palo Alto VPNs
⚠️
AI Advertising Company Hacked
⚠️
CISA Warns of Exploited Flaw in Asus Update Tool - SecurityWeek
⚠️
HPE warns of maximum severity RCE flaw in OneView software
⚠️
Docker Makes 1,000 Hardened Images Free and Open Source
⚠️
Be Careful of That Warrant for Your Arrest
⚠️
Over 25,000 FortiCloud SSO devices exposed to remote attacks
⚠️
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
⚠️
81% of Small Businesses Sustained a Cyber Incident Over the Past Year
⚠️
CISO's Top Priority: Mandatory Cybersecurity Policy
⚠️
Hundreds of Cisco customers are vulnerable to new Chinese hacking campaign, researchers say
⚠️
Mapping the Emerging Alliance Between Qilin, DragonForce, and LockBit
⚠️
Cloud Atlas Exploits Office Vulnerabilities to Execute Malicious Code
⚠️
Iranian APT Prince of Persia returns with new malware and C2 infrastructure
⚠️
Can chatbots craft correct code?
📢
Amazon Identified North Korean IT Worker by Tracking Keystroke Activity
📢
US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator
📢
France confirms Interior Ministry cyberattack as hackers claim 16M people exposed​ | Cybernews
📢
Dismantling Defenses: Trump 2.0 Cyber Year in Review
📢
WatchGuard security advisory (AV25-850)
📢
Google Chrome security advisory (AV25-851)
📢
Microsoft Edge security advisory (AV25-852)
📢
HPE security advisory (AV25-853)
📢
CISA and Partners Release Update to Malware Analysis Report BRICKSTORM Backdoor
🔥
University of Sydney Suffers Cyberattack, Student and Staff Data Exposed
🔥
Clop ransomware targets Gladinet CentreStack in data theft attacks
🔥
US seizes E-Note crypto exchange for laundering ransomware payments
🔥
University of Sydney Data Breach Affects 27,000 Individuals
🔥
University of Sydney suffers data breach exposing student and staff info
🔥
Denmark blames Russia for destructive cyberattack on water utility
🔥
Hackers breach internal servers of tech provider for Britain’s health service | The Record from Recorded Future News
🔥
113,000 Impacted by Data Breach at Virginia Mental Health Authority - SecurityWeek
🔥
Hacks, thefts and disruption: The worst data breaches of 2025
🔥
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
🔥
Denmark Blames Russia for Cyberattacks Ahead of Elections and on Water Utility
🔥
In Other News: Docker AI Attack, Google Sues Chinese Cybercriminals, Coupang Hacked by Employee
🔥
Nigeria arrests dev of Microsoft 365 'Raccoon0365' phishing platform
🔥
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers
🔥
Iranian APT Targeting Networks and Critical Infrastructure Organizations
🔥
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
🕵️
ISC Stormcast For Friday, December 19th, 2025 https://isc.sans.edu/podcastdetail/9746, (Fri, Dec 19th)
🕵️
WhatsApp, Signal, untraceable security risk
🕵️
Targeted Phishing Attack Strikes HubSpot Users
🕵️
North Korean Hackers Set Record with $2 Billion Crypto Heist in 2025
🕵️
North Korea’s Digital Surge: $2B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers
🕵️
DLLs & TLS Callbacks, (Fri, Dec 19th)
🕵️
New BeaverTail Malware Variant Linked to Lazarus Group - Infosecurity Magazine
🕵️
‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices
🕵️
Dormant Iran APT is Still Alive, Spying on Dissidents
🕵️
New password spraying attacks target Cisco, PAN VPN gateways
🕵️
OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365 - Infosecurity Magazine
🕵️
Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments
🕵️
Handheld Linux Hacking Device
🕵️
AI Security Firm Ciphero Emerges From Stealth With $2.5 Million in Funding
🕵️
Palo Alto Networks, Google Cloud Strike Multibillion-Dollar AI and Cloud Security Deal
🕵️
Microsoft 365 accounts targeted in wave of OAuth phishing attacks
🕵️
Thailand Conference Launches International Initiative to Fight Online Scams
🕵️
BlueDelta Hackers Target Users of Popular Ukrainian Webmail and News Service
🕵️
Scripted Sparrow Utilizes Automation to Generate and Dispatch Attack Messages
🕵️
Auld Lang Syne, Ghostpairing, Centerstack, WAFS, React2Shell, Crypto, Josh Marpet - SWN #539
🕵️
Friday Squid Blogging: Petting a Squid
🕵️
AI Risks: OWASP's Top 10
🌐
FTC: Instacart to refund $60M over deceptive subscription tactics
🌐
New cybersecurity laws and trends in 2026 | Kaspersky official blog
📡
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
📡
Microsoft confirms Teams is down and messages are delayed