[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Payload on Workers: a full-fledged CMS, running entirely on Cloudflare’s stack
We demonstrate how the open-source Payload CMS was ported to run entirely on Cloudflare's developer platform.
> Smishing Campaigns Exploit Cellular Routers to Target Belgium
New smishing attacks exploit Milesight routers to send phishing texts targeting Belgian users
> Putting staff welfare at the heart of incident response
Guidance for staff responsible for managing a cyber incident response within their organisation.
> When Audits Fail: Four Critical Pre-Auth Vulnerabilities in TRUfusion Enterprise
Despite Rocket Software's claims of regular security audits and adherence to secure coding practices, our team discovered multiple critical, pre-authentication vulnerabilities in TRUfusion Enterprise—a mission-critical software used for transferring highly sensitive data.
> New Android RAT Klopatra Targets Financial Data
New Android RAT Klopatra is targeting financial institutions using advanced evasion techniques
> Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations
Written by: Omar ElAhdan, Matthew McWhirt, Michael Rudden, Aswad Robinson, Bhavesh Dhake, Laith Al Background Protecting software-as-a-service (SaaS) platforms and applications requires a comprehensive security strategy. Drawing from analysis of UNC6040’s specific attack methodologies, this guide p...
> The AI Fix #70: AI behaves… until it knows you’re watching
In episode 70 of The AI Fix, our hosts learn that AI makes people more dishonest, Waymo's robo-cars save lives but get outsmarted by a bathroom mirror, a "rescue" bot slurps up victims head-first, and China shows off a fusion robot arm that can lift ten elephants (or 200,000 pigeons, if you’re scien...
> Google’s Latest AI Ransomware Defense Only Goes So Far
Google has launched a new AI-based protection in Drive for desktop that can shut down an attack before it spreads—but its benefits have their limits.
> US Cuts Federal Funding for MS-ISAC Cybersecurity Program
The Trump administration wants CISA to transition to a “new model” for supporting local government agencies’ cyber strategy
> Gemini Trifecta Highlights Dangers of Indirect Prompt Injection
Tenable researchers have discovered three vulnerabilities in Google’s Gemini GenAI tool
> How to Use Passkeys With Google Password Manager (2025)
Google can create and manage passkeys from your browser, but the process is more involved than it suggests.
> Dutch teens recruited on Telegram, accused of Russia-backed hacking plot
Two 17-year-olds have been arrested by Dutch authorities on suspicion of spying for pro-Russian hackers. The teenagers, who are said to have been recruited as "disposable agents" via Telegram, were reportedly arrested last week "on suspicion that are linked to government-sponsored interference."...
> Nationwide Internet shutdown in Afghanistan extends localized disruptions
On September 29, 2025, Internet connectivity was completely shut down across Afghanistan, impacting business, education, finance, and government services.
> Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite
Phantom Taurus is a previously undocumented Chinese threat group. Explore how this group's distinctive toolset lead to uncovering their existence. The post Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite appeared first on Unit 42.
> Asahi Suspends Operations in Japan After Cyber-Attack
Japanese brewery giant Asahi revealed that a cyber-attack had caused a “system failure”, with order and shipment operations suspended in Japan
> CIISec Members Say Budgets Are Falling Behind Threats
Most UK cybersecurity professionals tell CIISec that their budgets are stagnating
> CVE-2025-53132 Win32k Elevation of Privilege Vulnerability
Updated information to include CVSS scores. This is an informational change only.
> How Falcon ASPM Secures GenAI Applications and Lessons from Dogfooding
> ZDI-25-922: Ivanti Endpoint Manager EFile Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is require...
> ZDI-25-921: Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The followin...