Source: securityaffairs.com – Author: Pierluigi Paganini Orange Belgium revealed that a July attack resulted in the exposure of the information of 850,000 customer accounts. Orange Belgium...
Day: August 21, 2025
Apple addressed the seventh actively exploited zero-day – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Apple addressed a vulnerability impacting iOS, iPadOS, and macOS that it is under active exploitation in the wild. Apple addressed...
Hackers deploy DripDropper via Apache ActiveMQ flaw, patch systems to evade detection – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Hackers exploit Apache ActiveMQ flaw to install DripDropper on Linux, then patch it to block rivals and hide their tracks....
A Scattered Spider member gets 10 years in prison – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A 20-year-old Scattered Spider member gets 10 years in prison and $13M restitution for SIM-swapping crypto thefts. Scattered Spider hacker,...
FBI: Russia-linked group Static Tundra exploit old Cisco flaw for espionage – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini FBI warns FSB-linked group Static Tundra is exploiting a 7-year-old Cisco IOS/IOS XE flaw to gain persistent access for cyber...
US CERT/CC warns of flaws in Workhorse Software accounting software used by hundreds of municipalities in Wisconsin – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini CERT/CC disclosed serious data exposure vulnerabilities in Workhorse Software used by hundreds of U.S. cities and towns. CERT Coordination Center...
Smashing Security podcast #431: How to mine millions without paying the bill – Source: grahamcluley.com
Source: grahamcluley.com – Author: Graham Cluley Skip to content In episode 431 of the “Smashing Security” podcast, a self-proclaimed crypto-influencer calling himself CP3O thought he had...
Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks – Source:thehackernews.com
Source: thehackernews.com – Author: . Commvault has released updates to address four security gaps that could be exploited to achieve remote code execution on susceptible instances....
Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA Pages – Source:thehackernews.com
Source: thehackernews.com – Author: . Threat actors have been observed leveraging the deceptive social engineering tactic known as ClickFix to deploy a versatile backdoor codenamed CORNFLAKE.V3....
Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger – Source:thehackernews.com
Source: thehackernews.com – Author: . Cybersecurity researchers have disclosed details of a new malware loader called QuirkyLoader that’s being used to deliver via email spam campaigns...
Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: A seven-year-old vulnerability affecting end-of-life Cisco network devices is being exploited by a Russian state-sponsored cyber espionage group. Cisco Talos stated that...
Colt Admits Customer Data Likely Stolen in Cyber-Attack – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: Colt Technology Services has confirmed that cybercriminals could leak customer data. This is despite previously claiming the recent cyber incident targeted an...
Oregon Man Charged in Rapper Bot DDoS-for-Hire Case – Source: www.infosecurity-magazine.com
Source: www.infosecurity-magazine.com – Author: A 22-year-old Oregon man has been charged with administering the Rapper Bot DDoS-for-hire botnet, which was allegedly used to launch multi-terabit attacks...
Critical N-central RMM flaws actively exploited in the wild – Source: www.csoonline.com
Source: www.csoonline.com – Author: Enterprises and MSPs urged to patch on-premises deployments of N-able’s remote monitoring and management solution, with hundreds of servers still exposed to...
Russian hackers exploit old Cisco flaw to target global enterprise networks – Source: www.csoonline.com
Source: www.csoonline.com – Author: FBI and Cisco Talos warn of a sophisticated Russian FSB unit threatening enterprise network infrastructure and business continuity across critical sectors. Russian...
Hackers can slip ghost commands into the Amazon Q Developer VS Code Extension – Source: www.csoonline.com
Source: www.csoonline.com – Author: The extension can be tricked by invisible Unicode Tag Characters-special symbols unseen by humans but obeyed by AI. The Amazon Q Developer...
Microsoft restricts Chinese firms’ access to vulnerability warnings after hacking concerns – Source: www.csoonline.com
Source: www.csoonline.com – Author: The move may reassure Western customers but raises global security concerns. Microsoft has said that it has restricted certain Chinese firms from...
Lenovo-Chatbot-Lücke wirft Schlaglicht auf KI-Sicherheitsrisiken – Source: www.csoonline.com
Source: www.csoonline.com – Author: In Lenovos KI-gestütztem Chatbot für den Kundensupport wurde eine kritische Sicherheitslücke entdeckt. Über eine Schwachstelle in Lenovos Chatbot für den Kundensupport ist...
Cyberattacke auf Berlins Justizsenatorin Badenberg – Source: www.csoonline.com
Source: www.csoonline.com – Author: Die Berliner Justizsenatorin ist Ziel eines Hackerangriffs. Dabei sind sensible Daten abgeflossen. Berlins Senatorin für Justiz und Verbraucherschutz Felor Badenberg wurde von...
Enterprise passwords becoming even easier to steal and abuse – Source: www.csoonline.com
Source: www.csoonline.com – Author: Feature Aug 21, 20257 mins AuthenticationCyberattacksPasswords More effective cracking, continued reliance on weak or outdated policies, and security controls against credential leaks...
Personalie: Sotirios Siozos ist neuer CISO bei Drees & Sommer – Source: www.csoonline.com
Source: www.csoonline.com – Author: News 20. Aug. 20252 Minuten Daten- und Informationssicherheit Seit Anfang Juli ist Sotirios Siozos als CISO für die Cybersicherheit bei Drees &...
Lenovo chatbot breach highlights AI security blind spots in customer-facing systems – Source: www.csoonline.com
Source: www.csoonline.com – Author: Experts say the vulnerability in Lenovo’s GPT-4-powered chatbot reflects a broader enterprise trend: deploying AI tools without applying the same security rigor...
Forscher entdeckt offenen Zugang zu Intel-Mitarbeiterdaten – Source: www.csoonline.com
Source: www.csoonline.com – Author: Ein Security-Forscher hat massive Sicherheitslücken in Webportalen von Intel aufgedeckt. Teilweise waren sensible Daten offengelegt. Einem Sicherheitsforscher ist es gelungen, auf sensible...
Microsoft fixes the fixes that broke Windows tools – Source: www.csoonline.com
Source: www.csoonline.com – Author: Microsoft has corrected two August 2025 Patch Tuesday bugs that blocked Windows 11 upgrades and broke reset and recovery tools across Windows...
ASPM buyer’s guide: 7 products to help secure your applications – Source: www.csoonline.com
Source: www.csoonline.com – Author: Selecting the right application security posture management (ASPM) platform requires a deep understanding of your organization’s application estate and issues, as well...
Russia-linked European attacks renew concerns over water cybersecurity – Source: www.csoonline.com
Source: www.csoonline.com – Author: Suspected sabotage in Norway and a foiled cyberattack in Poland highlight the growing risk to under-protected water utilities, experts warn. Two incidents...
NIST’s attempts to secure AI yield many questions, no answers – Source: www.csoonline.com
Source: www.csoonline.com – Author: A NIST AI concept paper details the key enterprise security challenges and asks for industry comments. But what if AI agents flood...
Qilin Ransomware Gang Claims 4TB Data Breach at Nissan CBI – Source:hackread.com
Source: hackread.com – Author: Waqas. Qilin ransomware claims a 4TB data breach at Nissan CBI, leaking car design files, financial data, 3D models, and VR design...
Europol Denies $50K Reward for Qilin Ransomware, Calls It a Scam – Source:hackread.com
Source: hackread.com – Author: Deeba Ahmed. Europol has confirmed that a widely reported $50,000 reward for information on the Qilin ransomware group is a “scam.” The...
AI Browsers Can Be Tricked Into Paying Fake Stores in PromptFix Attack – Source:hackread.com
Source: hackread.com – Author: Deeba Ahmed. The PromptFix attack tricks AI browsers with fake CAPTCHAs, leading them to phishing sites and fake stores where they auto-complete...