[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (13 articles)

|

// AI-powered summary generated at 16:01

> British govt agents demand action after UK mega-cyberattacks surge 50%
Warn businesses to act now as high-severity incidents keep climbing Cyberattacks that meet upper severity thresholds set by the UK government's cyber agents have risen 50 percent in the last year, despite almost zero change in the volume of cases handled.…
> ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.1.2057.3 have been released
ESET Endpoint Antivirus and ESET Endpoint Security for Windows version 12.1.2057.3 have been released and are available for download.
> Matthew Plascencia, Digital Forensic Investigator, Exhibit A Cyber
Digital Forensic Investigator Matthew Plascencia discusses his journey from data recovery to mobile forensics, the tools he trusts, and how learning in public helped launch his career.
> UK Firms Lose Average of ÂŁ2.9m to AI Risk
A new EY report claims unmanaged AI risk is causing millions of pounds’ worth of losses for UK organizations
> UK: NCSC Reports 130% Spike in "Nationally Significant" Cyber Incidents
The UK cybersecurity agency reported 204 cyber incidents of “national significance” between September 2024 and August 2025 – an all-time high
> CVE-2025-49844 - The Redis CVSS 10.0 vulnerability and how we responded
We're very public and open about our infrastructure at Report URI, having written many blog posts about how we process billions of telemetry events every single week. As a result, it's no secret that we use Redis quite heavily across our infrastructure, and some have asked
> Patching Android ARM64 library initializers for easy Frida instrumentation and debugging
Intro During both mobile security and mobile resiliency assessments, you often end up instrumenting the application to analyze its internals. By using either Frida or a classical debugger, we can get valuable insight into the data flows and also modify some data on the fly to make the application be...
> There's a hole in my bucket
...or 'Why do people leave sensitive data in unprotected AWS S3 buckets?'
> npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels
Cybersecurity researchers have identified several malicious packages across npm, Python, and Ruby ecosystems that leverage Discord as a command-and-control (C2) channel to transmit stolen data to actor-controlled webhooks. Webhooks on Discord are a way to post messages to channels in the platform wi...
> CVE-2025-48004 Microsoft Brokering File System Elevation of Privilege Vulnerability
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
> CVE-2025-50174 Windows Device Association Broker Service Elevation of Privilege Vulnerability
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
> CVE-2025-53782 Microsoft Exchange Server Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
> CVE-2025-55247 .NET Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
> CVE-2025-24990 Windows Agere Modem Driver Elevation of Privilege Vulnerability
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. **Fax modem hardware depe...
> CVE-2025-24052 Windows Agere Modem Driver Elevation of Privilege Vulnerability
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. **Fax modem hardware depe...
> CVE-2025-55325 Windows Storage Management Provider Information Disclosure Vulnerability
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
> CVE-2025-55333 Windows BitLocker Security Feature Bypass Vulnerability
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
> CVE-2025-55335 Windows NTFS Elevation of Privilege Vulnerability
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
> CVE-2025-55336 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
> CVE-2025-55338 Windows BitLocker Security Feature Bypass Vulnerability
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.