Shai-Hulud npm Supply Chain Attack: What You Need to Know
Shai-Hulud npm Supply Chain Attack: What You Need to Know In September 2025, the open-source ecosystem experienced a significant threat: the Shai-Hulud npm supply chain attack. Malicious packages were...
August 2025: SaaS Supply Chain Breaches, Telecom Data Exposures, and R...
August 2025: SaaS Supply Chain Breaches, Telecom Data Exposures, and Ransomware Campaigns August 2025 saw a wave of high-impact cyber incidents affecting millions worldwide. SaaS supply chain threats ...
RCE Risk in Cursor AI Code Editor When Opening Folders
RCE Risk in Cursor AI Code Editor When Opening Folders Imagine opening a code project and instantly triggering a background script without touching a key or clicking “run.” That’s not a feature. That’...
FinalDraft Malware: The Stealthy Threat Using Microsoft Services
FinalDraft Malware: The Stealthy Threat Using Microsoft Services Designed for covert, long-term espionage, FinalDraft malware masterfully blends into legitimate Microsoft services to avoid detection, ...
September 2025 Patch Tuesday: 2 Zero-Days (CVE-2025-55234 & CVE-2024-2...
September 2025 Patch Tuesday: 2 Zero-Days (CVE-2025-55234 & CVE-2024-21907), 81 Microsoft Flaws Microsoft has released its September 2025 Patch Tuesday updates, addressing 81 vulnerabilities acros...
Massive npm Supply Chain Attack Exposes Millions to Crypto-Stealing Ma...
Massive npm Supply Chain Attack Exposes Millions to Crypto-Stealing Malware Yesterday, researchers issued a warning about a major npm supply chain attack that has disrupted the JavaScript ecosystem. A...
CVE-2025-53690: Sitecore Deployments Targeted via WEEPSTEEL Malware
CVE-2025-53690: Sitecore Deployments Targeted via WEEPSTEEL Malware Organizations running older Sitecore deployments are now in the crosshairs of attackers exploiting a newly disclosed security issue,...
Salesloft Drift Breach: Everything You Need to Know
Salesloft Drift Breach: Everything You Need to Know [Update] September 8, 2025: “Salesloft’s Official Update: GitHub Breach Led to Drift Token Theft” In August 2025, Salesloft’s Drift chatbot service ...
September 2025 Android Security Bulletin Highlights Exploited Flaws: C...
September 2025 Android Security Bulletin Highlights Exploited Flaws: CVE-2025-38352 & CVE-2025-48543 Google has published the September 2025 Android Security Bulletin, which includes a wide set of...
CVE-2025-55177: Zero-Click WhatsApp Exploit Leveraged in Targeted Spyw...
CVE-2025-55177: Zero-Click WhatsApp Exploit Leveraged in Targeted Spyware Attacks on Apple Devices [Update] October 1, 2025: Researchers Trigger the WhatsApp Zero-Click Exploit Chain (CVE-2025-55177 a...
CVE-2025-7775: Citrix Zero-Day Exploit Hits NetScaler Devices
CVE-2025-7775: Citrix Zero-Day Exploit Hits NetScaler Devices A newly discovered zero-day vulnerability in Citrix NetScaler devices, tracked as CVE-2025-7775, is already being exploited in the wild, p...
CVE-2025-9074: Docker Desktop Vulnerability Allows Host Compromise
CVE-2025-9074: Docker Desktop Vulnerability Allows Host Compromise Containers are designed to provide isolation, but a newly disclosed flaw shows just how fragile that boundary can be when misconfigur...
July 2025: Allianz, Qantas, M&S, Co-op Breaches, $140M Bank Hack & Sha...
July 2025: Allianz, Qantas, M&S, Co-op Breaches, $140M Bank Hack & SharePoint 0-Day Exploits From airlines and insurers to banks and retailers, July 2025 showed no sector was off-limits for cy...
CVE-2025-20265: RCE Flaw in Cisco Secure Firewall FMC RADIUS Authentic...
CVE-2025-20265: RCE Flaw in Cisco Secure Firewall FMC RADIUS Authentication Cisco has disclosed a critical vulnerability affecting Secure Firewall Management Center Software, along with 28 additional ...
MadeYouReset: New HTTP/2 DoS Vulnerability Explained
MadeYouReset: New HTTP/2 DoS Vulnerability Explained A newly disclosed technique called “MadeYouReset” lets attackers coax HTTP/2 servers into resetting their own streams, slipping past many Rapid Res...
CVE-2025-25256: FortiSIEM Flaw Enables Unauthenticated RCE
CVE-2025-25256: FortiSIEM Flaw Enables Unauthenticated RCE A new critical vulnerability in Fortinet’s FortiSIEM platform is drawing urgent attention. With exploit code already circulating in the wild ...
August 2025 Patch Tuesday: Microsoft Fixes 111 CVEs & Publicly Disclos...
August 2025 Patch Tuesday: Microsoft Fixes 111 CVEs & Publicly Disclosed Kerberos Zero-Day (CVE-2025-53779) [Update] “Post-Patch Findings on BadSuccessor (CVE-2025-53779)” Microsoft has rolled out...
Salesforce-Related Data Breach Affecting Multiple Companies
Salesforce-Related Data Breach Affecting Multiple Companies [Update] August 12, 2025: “ShinyHunters Reopens Telegram Channel, Claims BreachForums Is Law Enforcement–Run” In mid-2025, a series of coord...
CVE-2025-8088: WinRAR Zero-Day Exploited in Targeted Attacks
CVE-2025-8088: WinRAR Zero-Day Exploited in Targeted Attacks A newly discovered zero-day vulnerability in the popular file archive tool WinRAR, tracked as CVE-2025-8088, has been actively exploited in...
CVE-2025-53786: CISA Issues Emergency Directive for Critical Microsoft...
CVE-2025-53786: CISA Issues Emergency Directive for Critical Microsoft Exchange Hybrid Vulnerability On August 7, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an Emerg...
