Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access post, juni 26, 2025juni 27, 2025 Cisco has released updates to address two maximum-severity security flaws in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could permit an unauthenticated attacker to execute arbitrary commands as the root user. The vulnerabilities, assigned the CVE identifiers CVE-2025-20281 and CVE-2025-20282, carry a CVSS score of 10.0 each. Continue Reading
China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom post, juni 24, 2025 The Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation (FBI) have issued an advisory warning of cyber attacks mounted by the China-linked Salt Typhoon actors to breach major global telecommunications providers as part of a cyber espionage campaign. The attackers exploited a critical Cisco IOS XE software (CVE-2023-20198, CVSS score:… Continue Reading
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware post, juni 13, 2025augustus 21, 2025 Apple has disclosed that a now-patched security flaw present in its Messages app was actively exploited in the wild to target civil society members in sophisticated cyber attacks. The vulnerability, tracked as CVE-2025-43200, was addressed on February 10, 2025, as part of iOS 18.3.1, iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS… Continue Reading
Russische hackers ontregelden maandenlang windpark Oude Maas post, juni 10, 2025juni 11, 2025 Een Russische hack bij een Duitse windturbineproducent had in 2022 ook gevolgen voor Nederlandse windmolens. Sommige stonden maandenlang stil, waaronder die van windmolenpark Oude Maas. Een reconstructie van hoe Europa’s meest gezochte criminelen een hack uitvoerden met potentiële risico’s voor de stroomvoorziening op ons continent. Hoe zit het met de… Continue Reading
Google patches new Chrome zero-day bug exploited in attacks post, juni 3, 2025 Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year. “Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday. This high-severity vulnerability is caused by an out-of-bounds read and write weakness… Continue Reading
Google Releases Emergency Security Patch For Actively Exploited Chrome Zero-Day Vulnerability post, juni 3, 2025juni 4, 2025 Google released emergency (out-of-band) updates for its Chrome browser to address three security vulnerabilities—one of which is currently being actively exploited. The most critical of the flaws is tracked as CVE-2025-5419 (CVSS score: 8.8). It is a high-severity out-of-bounds read and write vulnerability in Chrome’s V8 JavaScript and WebAssembly engine…. Continue Reading
Exposed Automated Tank Gauge Systems (DIVD-2025-00005) post, april 29, 2025mei 19, 2025 Automated Tank Gauge (ATG) systems are widely used in gas stations and other critical facilities to monitor fuel levels, detect leaks, and manage inventory. These industrial control systems have been found exposed directly to the internet without proper authentication mechanisms, creating significant security and potential safety risks. The vulnerability affects… Continue Reading
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks post, april 17, 2025april 24, 2025 Apple on Wednesday released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two security flaws that it said have come under active exploitation in the wild. The vulnerabilities in question are listed below – Continue Reading
Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords post, april 9, 2025 Fortinet has issued urgent security updates to address a critical vulnerability in FortiSwitch that could allow attackers to change passwords without authorization. The flaw, identified as CVE-2024-48887, has been assigned a CVSS score of 9.8 out of 10. According to Fortinet’s advisory, the vulnerability lies in the FortiSwitch GUI and… Continue Reading
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages post, april 5, 2025april 7, 2025 The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and… Continue Reading