65Articles
8Categories
2025-12-22Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Vulnerability  This type of vulnerability is a frequent attack vector for malicious…
KEV
🐛
Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374
🐛
Microsoft Brokering File System Vulnerability Enables Local Privilege Escalation
🐛
PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel POSIX CPU Timers
🐛
CISA flags ASUS Live Update CVE, but the attack is years old
🐛
AL25-020 – Vulnerability Impacting WatchGuard Fireware OS - CVE-2025-14733
🐛
CVE-2025-12105 Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
🐛
Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component
⚠️
Podcast: Die IT-Tops und -Flops 2025
⚠️
What CISOs should know about the SolarWinds lawsuit dismissal
⚠️
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
KEV
⚠️
WatchGuard Patches Firebox Zero-Day Exploited in the Wild
KEV
⚠️
Hackers exploit Microsoft OAuth device codes to hijack enterprise accounts
⚠️
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More
⚠️
How to Browse the Web More Sustainably With a Green Browser
⚠️
Nissan Discloses Data Breach Linked to Compromised Red Hat Infrastructure
⚠️
Sleeping Bouncer Vulnerability Impacts Gigabyte, MSI, ASRock, and ASUS Motherboards
⚠️
Docker Releases Free, Production-Grade Hardened Container Images
⚠️
New BlackForce Phishing Kit Bypasses Multifactor Authentication
⚠️
Coupang breach affecting 33.7 million users raises data protection questions
⚠️
2025 Year in Review at Cloud Security Podcast by Google
KEV
⚠️
Scammers use AI to make fake art seem real
⚠️
Microsoft Is Finally Killing RC4
⚠️
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens
⚠️
NIST and CISA Release Draft Interagency Report on Protecting Tokens and Assertions from Tampering Theft and Misuse for Public Comment
📢
Leading Global Research and Advisory Firm Recommends Against Using AI Browsers
📢
UK government was hacked in October, minister confirms - iTnews
📢
Romanian water authority hit by ransomware attack over weekend
📢
Cloud Security: False Sense of Security
📢
[Control systems] CISA ICS security advisories (AV25–854)
📢
IBM security advisory (AV25-855)
📢
Dell security advisory (AV25-856)
📢
n8n security advisory (AV25-857)
🔥
Arrests In 0365 Scheme: Cybersecurity Today With David Shipley
🔥
UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports
🔥
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
🔥
Internal threats are the hole in Cybersecurity’s donut - Frank Vukovits - ESW #438
🔥
Ukrainian Nefilim Ransomware Affiliate Pleads Guilty in US
🔥
Think you can beat ransomware? RansomHouse just made it a lot harder
🔥
Auto Credit Check Company Breach Affects 5.6 Million | Robinson+Cole Data Privacy + Security Insider - JDSupra
🔥
Blind Eagle Hackers Target Government Agencies Using PowerShell Scripts
🔥
SideWinder APT Launches Cyberattacks on Indian Entities Posing as the Income Tax Department
🔥
Wonderland Android Malware Targets OTPs Through Two-Way SMS Hijacking
🔥
University of Phoenix data breach impacts nearly 3.5 million individuals
🔥
Pirate activists have copied Spotify’s entire music library
🔥
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
🔥
Nissan says thousands of customers exposed in Red Hat breach
🕵️
ISC Stormcast For Monday, December 22nd, 2025 https://isc.sans.edu/podcastdetail/9748, (Mon, Dec 22nd)
🕵️
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale
🕵️
Gambit Cyber Raises $3.4 Million in Seed Funding
🕵️
MacSync macOS Malware Distributed via Signed Swift Application
🕵️
Criminals impersonate senior US officials in messaging scams | Cybernews
🕵️
Arcane Werewolf Hacker Group Expands Arsenal with Loki 2.1 Malware Toolkit
🕵️
DIG AI: New Darknet AI Platform Enhancing Capabilities of Cybercriminals
🕵️
Europol: brace for robot-enabled crime surge by 2035 | Cybernews
🕵️
North Korea “industrializes” crypto thefts as losses hit billions | Cybernews
🕵️
54 Charged in US Over ATM Attacks Involving ‘Ploutus’ Malware
🕵️
Italian Ferry Malware Attack Sparks International Probe
🕵️
Rising Tides: When Cybersecurity Becomes Personal – Inside the Work of an OSINT Investigator
🕵️
The Security Donut: Filling the Hole
🌐
New MacSync malware dropper evades macOS Gatekeeper checks
🌐
What Does it Take to Manage Cloud Risk?
📡
Malicious npm package steals WhatsApp accounts and messages
📡
OpenAI says AI browsers may always be vulnerable to prompt injection attacks
📡
Digital Threat Detection Tools & Best Practices