Google Warns Salesloft Drift Breach Impacts All Drift Integrations Beyond Salesforce post, augustus 29, 2025september 4, 2025 Google has revealed that the recent wave of attacks targeting Salesforce instances via Salesloft Drift is much broader in scope than previously thought, stating it impacts all integrations. “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially… Continue Reading
Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks post, augustus 21, 2025 Apple has released security updates to address a security flaw impacting iOS, iPadOS, and macOS that it said has come under active exploitation in the wild. The zero-day out-of-bounds write vulnerability, tracked as CVE-2025-43300, resides in the ImageIO framework that could result in memory corruption when processing a malicious image. Continue Reading
The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived post, augustus 14, 2025augustus 18, 2025 The breach of the US Courts records system came to light more than a month after the attack was discovered. Details about what was exposed—and who’s responsible—remain unclear. Continue Reading
Russian hackers took control of Norwegian dam, police chief says post, augustus 13, 2025september 1, 2025 The Norwegian Police Security Service suspects pro-Russian hackers sabotaged a dam in southwestern Norway in April. Norwegian daily newspaper VG reported that the hackers breached the dam’s control system, opening valves for four hours, sending large amounts of water gushing forth until the valves could be shut. Continue Reading
Encryption Made for Police and Military Radios May Be Easily Cracked post, augustus 7, 2025augustus 25, 2025 Two years ago, researchers in the Netherlands discovered an intentional backdoor in an encryption algorithm baked into radios used by critical infrastructure–as well as police, intelligence agencies, and military forces around the world–that made any communication secured with the algorithm vulnerable to eavesdropping. When the researchers publicly disclosed the issue in 2023, the… Continue Reading
Sterke signalen dat Russen achter hack OM zitten, zaten mogelijk weken in systeem post, juli 24, 2025juli 25, 2025 Er zijn sterke aanwijzingen dat de hack bij het Openbaar Ministerie gelinkt is aan Rusland. Dat zeggen goed ingevoerde bronnen binnen justitie tegen deze site. De hackers hebben mogelijk wekenlang toegang gehad tot computers van justitie. Continue Reading
Casus: Citrix kwetsbaarheid post, juli 23, 2025 Op deze pagina gaat het NCSC verder in op de situatie omtrent de kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway. Ook bieden we extra duiding en handelingsperspectief in het omgaan met deze kwetsbaarheden. Continue Reading
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks post, juli 21, 2025juli 23, 2025 Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called “ToolShell,” which enabled them to achieve remote code execution in Microsoft SharePoint. These… Continue Reading
3,500 Websites Hijacked to Secretly Mine Crypto Using Stealth JavaScript and WebSocket Tactics post, juli 21, 2025 A new attack campaign has compromised more than 3,500 websites worldwide with JavaScript cryptocurrency miners, marking the return of browser-based cryptojacking attacks once popularized by the likes of CoinHive. Although the service has since shuttered after browser makers took steps to ban miner-related apps and add-ons, researchers from the c/side said they found… Continue Reading
Global hack on Microsoft product hits U.S., state agencies, researchers say post, juli 20, 2025juli 21, 2025 Unknown attackers exploited a “significant vulnerability” in Microsoft’s SharePoint collaboration software, hitting targets around the world. Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities,… Continue Reading