Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: vulnerability

Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact Data

post, februari 10, 2026februari 11, 2026

The Netherlands’ Dutch Data Protection Authority (AP) and the Council for the Judiciary confirmed both agencies (Rvdr) have disclosed that their systems were impacted by cyber attacks that exploited the recently disclosed security flaws in Ivanti Endpoint Manager Mobile (EPMM), according to a notice sent to the country’s parliament on…

Continue Reading

Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

post, februari 3, 2026februari 4, 2026

In the latest illustration of how quickly attackers can exploit newly disclosed flaws, Russia’s notorious APT28 cyber-espionage group has begun abusing a recently patched Microsoft vulnerability to steal emails and deploy malicious payloads against organizations in Central and Eastern Europe. CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office…

Continue Reading

How the KGB Discovered Computer Viruses

post, februari 2, 2026februari 4, 2026

A 1989 internal memo warned the Soviet security apparatus about a new threat: malicious software that was spreading among users across the USSR and even within the KGB itself. In this post I will review an archival KGB document on computer viruses available through the Lithuanian Genocide and Resistance Research…

Continue Reading

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

post, februari 2, 2026februari 4, 2026

Russia-linked attackers are already exploiting Microsoft’s latest Office zero-day, with Ukraine’s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an alert published on Sunday, CERT-UA says the activity is being driven by UAC-0001, better…

Continue Reading

Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day

post, januari 26, 2026januari 27, 2026

Microsoft has issued emergency, out-of-band security updates to address a high-severity zero-day vulnerability in Microsoft Office that is already being exploited in real-world attacks, underscoring the persistent security challenges facing one of the world’s most widely deployed productivity platforms. The flaw, tracked as CVE-2026-21509, is classified as a security feature…

Continue Reading

Fortinet Confirms Ongoing Exploitation of Critical FortiCloud SSO Flaw Despite Patch

post, januari 24, 2026januari 26, 2026

Fortinet has confirmed that a critical authentication bypass vulnerability affecting its FortiCloud Single Sign-On (SSO) implementation has not been fully remediated, even on systems that were previously believed to be fully patched. The disclosure follows mounting evidence from customers and security researchers that attackers have continued to successfully compromise FortiGate…

Continue Reading

‘Most Severe AI Vulnerability to Date’ Hits ServiceNow

post, januari 13, 2026januari 14, 2026

Authentication issues in ServiceNow potentially opened the door for arbitrary attackers to gain full control over the entire platform and access to the various systems connected to it. ServiceNow is a Fortune 500 company that, according to its promotional materials, acts as an IT services management platform for 85% of the…

Continue Reading

Cyberaanval treft Franse banken en post in hectische kerstperiode

post, december 22, 2025januari 5, 2026

De online diensten van het Franse postbedrijf La Poste zijn maandagochtend getroffen door een cyberaanval. Ook banken in het land werden het doelwit. Daarmee zouden in totaal miljoenen Fransen zijn getroffen door de aanval. La Poste bevestigt de ddos-aanval in een verklaring. Er zijn geen gevolgen voor de klantgegevens, benadrukt…

Continue Reading

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

post, december 3, 2025december 5, 2025

Microsoft has silently plugged a security flaw that has been exploited by several threat actors since 2017 as part of the company’s November 2025 Patch Tuesday updates, according to ACROS Security’s 0patch. The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which has been described as a Windows Shortcut (LNK) file UI misinterpretation vulnerability…

Continue Reading

Chinese State-Sponsored Threat Actors Used Anthropic’s Claude To Automate Global Cyberattacks

post, november 14, 2025november 17, 2025

Anthropic has disclosed a large-scale cyber operation in which a China-aligned threat actor leveraged the Claude Code model to automate exploitation, credential harvesting, and data exfiltration across approximately 30 global targets. The incident represents one of the first documented cases in which an LLM with agentic capabilities was weaponized to…

Continue Reading
  • Previous
  • 1
  • …
  • 6
  • 7
  • 8
  • …
  • 15
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes