VMware CVE-2025-41244 Exploited: What You Need to Know About the Lates...
VMware CVE-2025-41244 Exploited: What You Need to Know About the Latest Flaws [Update] VMware Aria Operations & Tools Vulnerability (CVE-2025-41244) Added to CISA KEV Cybersecurity researchers hav...
Cisco ASA, FTD Devices Under Active Attack via Zero-Days CVE-2025-2033...
Cisco ASA, FTD Devices Under Active Attack via Zero-Days CVE-2025-20333 & CVE-2025-20362 A newly disclosed wave of zero-day attacks is targeting Cisco firewall products, raising urgent concerns fo...
CVE-2025-20352: Zero-Day in Cisco IOS & IOS XE SNMP Exploited, Allows ...
CVE-2025-20352: Zero-Day in Cisco IOS & IOS XE SNMP Exploited, Allows DoS and Root RCE [Update] Attackers Exploit CVE-2025-20352 to Deploy Rootkits in Operation Zero Disco [Update] CVE-2025-20352...
CVE-2025-26399: Critical RCE in SolarWinds Web Help Desk Receives a Ho...
CVE-2025-26399: Critical RCE in SolarWinds Web Help Desk Receives a Hotfix Another critical security vulnerability has emerged in SolarWinds’ widely used Web Help Desk software. Marked with a near-max...
CVE-2025-10035: Critical GoAnywhere MFT Vulnerability Could Lead to Co...
CVE-2025-10035: Critical GoAnywhere MFT Vulnerability Could Lead to Command Injection [Update] October 7, 2025: Added details on active exploitation of CVE-2025-10035 by Storm-1175 to deploy Medusa ra...
Heathrow Airport Cyberattack: What Happened, Who's Affected, and What ...
Heathrow Airport Cyberattack: What Happened, Who’s Affected, and What CISOs Should Know [Update] October 22, 2025: Everest Group Claims Responsibility and Shares Alleged Proof of Collins Aerospace Bre...
CVE-2025-10585: New Chrome V8 Zero-Day Exploited in the Wild
CVE-2025-10585: New Chrome V8 Zero-Day Exploited in the Wild Google has released a security update for Chrome users, involving a serious vulnerability that is exploited in the wild. The flaw, identifi...
Shai-Hulud npm Supply Chain Attack: What You Need to Know
Shai-Hulud npm Supply Chain Attack: What You Need to Know In September 2025, the open-source ecosystem experienced a significant threat: the Shai-Hulud npm supply chain attack. Malicious packages were...
August 2025: SaaS Supply Chain Breaches, Telecom Data Exposures, and R...
August 2025: SaaS Supply Chain Breaches, Telecom Data Exposures, and Ransomware Campaigns August 2025 saw a wave of high-impact cyber incidents affecting millions worldwide. SaaS supply chain threats ...
RCE Risk in Cursor AI Code Editor When Opening Folders
RCE Risk in Cursor AI Code Editor When Opening Folders Imagine opening a code project and instantly triggering a background script without touching a key or clicking “run.” That’s not a feature. That’...
FinalDraft Malware: The Stealthy Threat Using Microsoft Services
FinalDraft Malware: The Stealthy Threat Using Microsoft Services Designed for covert, long-term espionage, FinalDraft malware masterfully blends into legitimate Microsoft services to avoid detection, ...
September 2025 Patch Tuesday: 2 Zero-Days (CVE-2025-55234 & CVE-2024-2...
September 2025 Patch Tuesday: 2 Zero-Days (CVE-2025-55234 & CVE-2024-21907), 81 Microsoft Flaws Microsoft has released its September 2025 Patch Tuesday updates, addressing 81 vulnerabilities acros...
Massive npm Supply Chain Attack Exposes Millions to Crypto-Stealing Ma...
Massive npm Supply Chain Attack Exposes Millions to Crypto-Stealing Malware Yesterday, researchers issued a warning about a major npm supply chain attack that has disrupted the JavaScript ecosystem. A...
CVE-2025-53690: Sitecore Deployments Targeted via WEEPSTEEL Malware
CVE-2025-53690: Sitecore Deployments Targeted via WEEPSTEEL Malware Organizations running older Sitecore deployments are now in the crosshairs of attackers exploiting a newly disclosed security issue,...
Salesloft Drift Breach: Everything You Need to Know
Salesloft Drift Breach: Everything You Need to Know [Update] September 8, 2025: “Salesloft’s Official Update: GitHub Breach Led to Drift Token Theft” In August 2025, Salesloft’s Drift chatbot service ...
September 2025 Android Security Bulletin Highlights Exploited Flaws: C...
September 2025 Android Security Bulletin Highlights Exploited Flaws: CVE-2025-38352 & CVE-2025-48543 Google has published the September 2025 Android Security Bulletin, which includes a wide set of...
CVE-2025-55177: Zero-Click WhatsApp Exploit Leveraged in Targeted Spyw...
CVE-2025-55177: Zero-Click WhatsApp Exploit Leveraged in Targeted Spyware Attacks on Apple Devices [Update] October 1, 2025: Researchers Trigger the WhatsApp Zero-Click Exploit Chain (CVE-2025-55177 a...
CVE-2025-7775: Citrix Zero-Day Exploit Hits NetScaler Devices
CVE-2025-7775: Citrix Zero-Day Exploit Hits NetScaler Devices A newly discovered zero-day vulnerability in Citrix NetScaler devices, tracked as CVE-2025-7775, is already being exploited in the wild, p...
CVE-2025-9074: Docker Desktop Vulnerability Allows Host Compromise
CVE-2025-9074: Docker Desktop Vulnerability Allows Host Compromise Containers are designed to provide isolation, but a newly disclosed flaw shows just how fragile that boundary can be when misconfigur...
July 2025: Allianz, Qantas, M&S, Co-op Breaches, $140M Bank Hack & Sha...
July 2025: Allianz, Qantas, M&S, Co-op Breaches, $140M Bank Hack & SharePoint 0-Day Exploits From airlines and insurers to banks and retailers, July 2025 showed no sector was off-limits for cy...