⚠️Important Security Alerts (CVSS > 7.5)⚠️
🚨 Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT 🚨 Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed
Table of Contents
- Deepfake Defense in the Age of AI
- North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress
- Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
- Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
- ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files
- ⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams
- The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That
- Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures
- Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection
- Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
- Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
- ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files
- ⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams
- The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That
- Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures
- Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection
- Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
- Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
- 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
- Security Tools Alone Don’t Protect You — Control Effectiveness Does
- SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root
- Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures
- MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware
- Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware
- Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT
- Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks
- OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple Flaws
- SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
- Reevaluating SSEs: A Technical Gap Analysis of Last-Mile Protection
- Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization
- Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times
- NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware
- Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet
- New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims
- Third Parties and Machine Credentials: The Silent Drivers Behind 2025’s Worst Breaches
- Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks
- Entra ID Data Protection: Essential or Overkill?
- Update ASAP: Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers
- Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
- Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi
- Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed
- ⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors
- Perfection is a Myth. Leverage Isn’t: How Small Teams Can Secure Their Google Workspace
- Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data
- Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack
- Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and Malware
- U.S. Charges Yemeni Hacker Behind Black Kingdom Ransomware Targeting 1,500 Systems
- TikTok Slammed With €530 Million GDPR Fine for Sending E.U. Data to China
- How to Automate CVE and Vulnerability Advisory Response with Tines
- MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks
🤖 Deepfake Defense in the Age of AI 🤖
La sécurité cybernétique est radicalement transformée par l’avènement de l’IA générative. Les attaquants…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-13
🇰🇵 North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress 🇰🇵
L’acteur de menace lié à la Corée du Nord, connu sous le nom de Konni APT, a été attribué à une campagne de phishing…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-13
🇲🇩 Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency 🇲🇩
Les autorités policières moldaves ont arrêté un homme étranger de 45 ans soupçonné d’être impliqué…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-13
🇹🇷 Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers 🇹🇷
Un acteur de menace affilié à la Turquie a exploité une faille de sécurité zero-day dans un outil de communication d’entreprise indien…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-13
💻 ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files 💻
ASUS a publié des mises à jour pour corriger deux failles de sécurité affectant ASUS DriverHub qui, en cas de succès…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-12
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams ⚡
Qu’ont en commun un éditeur de code source, un panneau d’affichage intelligent et un serveur web ? Ils sont tous devenus…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-12
🔑 The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change That 🔑
Détecter les identifiants divulgués n’est que la moitié de la bataille. Le véritable défi – et souvent la moitié négligée…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-12
🤖 Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures 🤖
Des acteurs de menace ont été observés utilisant de faux outils basés sur l’intelligence artificielle (IA) comme appât…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-12
💰 Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection 💰
Google a accepté de verser près de 1,4 milliard de dollars à l’État américain du Texas pour régler deux poursuites judiciaires…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-10
🇩🇪 Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data 🇩🇪
Le Bureau fédéral de police criminelle allemand (aka Bundeskriminalamt ou BKA) a saisi l’infrastructure en ligne…
- 🔎 CVE: N/A
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-10
🚨 Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT 🚨
Cisco a publié des correctifs logiciels pour corriger une faille de sécurité de gravité maximale dans son IOS XE Wireless…
- 🔎 CVE: CVE-2025-20188
- 📊 CVSS: 10.0
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-09
🚨 Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed 🚨
La Cybersecurity and Infrastructure Security Agency (CISA) des États-Unis a ajouté une faille de sécurité de gravité maximale…
- 🔎 CVE: CVE-2025-34028
- 📊 CVSS: N/A
- 🛡️ EPSS: N/A
- 📅 Date de publication : 2025-05-05