National Guard hacked by Chinese ‘Salt Typhoon’ campaign for nearly a year, DHS memo says post, juli 15, 2025juli 24, 2025 An elite Chinese cyberspy group hacked at least one state’s National Guard network for nearly a year, the Department of Defense has found. The hackers, already responsible for one of the most expansive cyberespionage campaigns against the U.S. to date, are alleged to have burrowed even further than previously known… Continue Reading
Israel Says Iran Is Hacking Security Cameras for Spying post, juli 11, 2025 Israeli officials said this week that Iran is compromising private security cameras around Israel to conduct espionage as the two countries exchange missile strikes after an initial Israeli barrage. A former Israeli cybersecurity official warned on public radio this week that Israelis should confirm that their home security cameras are… Continue Reading
Manufacturing Security: Why Default Passwords Must Go post, juli 7, 2025 If you didn’t hear about Iranian hackers breaching US water facilities, it’s because they only managed to control a single pressure station serving 7,000 people. What made this attack noteworthy wasn’t its scale, but how easily the hackers gained access — by simply using the manufacturer’s default password “1111.” This narrow escape… Continue Reading
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros post, juli 4, 2025 Cybersecurity researchers have disclosed two security flaws in the Sudo command-line utility for Linux and Unix-like operating systems that could enable local attackers to escalate their privileges to root on susceptible machines. A brief description of the vulnerabilities is below – Continue Reading
CVE 2025 32711 is a turning point post, juli 4, 2025juli 25, 2025 Last week, we saw the first confirmed zero click prompt injection breach against a production AI assistant.No malware. No links to click. No user interaction.Just a cleverly crafted email quietly triggering Microsoft 365 Copilot to leak sensitive org data as part of its intended behavior. Continue Reading
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms post, juli 3, 2025 The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The campaign, detected… Continue Reading
Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials post, juli 3, 2025 Cisco has released security updates to address a maximum-severity security flaw in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) that could permit an attacker to login to a susceptible device as the root user, allowing them to gain elevated privileges. The vulnerability,… Continue Reading
GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool post, juni 28, 2025juni 30, 2025 The threat actor behind the GIFTEDCROOK malware has made significant updates to turn the malicious program from a basic browser data stealer to a potent intelligence-gathering tool. “Recent campaigns in June 2025 demonstrate GIFTEDCROOK’s enhanced ability to exfiltrate a broad range of sensitive documents from the devices of targeted individuals,… Continue Reading
Hackers Make Hay? Smart Tractors Vulnerable to Full Takeover post, juni 27, 2025juni 30, 2025 Hackers can spy on tens of thousands of connected tractors in the latest IoT threat, and brick them too, thanks to poor security in an aftermarket steering system. Researchers have figured out how to simultaneously spy on tens of thousands of smart tractors around the world, and even take full… Continue Reading
Meldingen van misbruik van kwetsbaarheid in Citrix NetScaler ADC en NetScaler Gateway post, juni 26, 2025juni 27, 2025 Softwarebedrijf Citrix heeft een kwetsbaarheid verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid wordt aangeduid met het kenmerk CVE-2025-6543. Er zijn al meldingen van misbruik op systemen die niet zijn bijgewerkt. Het is daarom belangrijk om deze kwetsbaarheid serieus te nemen. Ook het Nationaal Cyber Security Centrum (NCSC) schaalt… Continue Reading