Exposed Automated Tank Gauge Systems (DIVD-2025-00005) post, april 29, 2025mei 19, 2025 Automated Tank Gauge (ATG) systems are widely used in gas stations and other critical facilities to monitor fuel levels, detect leaks, and manage inventory. These industrial control systems have been found exposed directly to the internet without proper authentication mechanisms, creating significant security and potential safety risks. The vulnerability affects… Continue Reading
Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices post, april 23, 2025april 24, 2025 Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software. “The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of… Continue Reading
Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp post, april 23, 2025april 24, 2025 Multiple suspected Russia-linked threat actors are “aggressively” targeting individuals and organizations with ties to Ukraine and human rights with an aim to gain unauthorized access to Microsoft 365 accounts since early March 2025. The highly targeted social engineering operations, per Volexity, are a shift from previously documented attacks that leveraged… Continue Reading
Voor het eerst Russische sabotage-aanval in Nederland: ‘Rusland wordt brutaler’ post, april 22, 2025april 24, 2025 Nederland wordt steeds vaker geconfronteerd met hybride aanvallen van Rusland, waarmee ze onze samenleving willen ontwrichten. Zo hebben Russische hackers afgelopen jaar voor het eerst geprobeerd een sabotage-actie uit te voeren op de computers van een openbare Nederlandse instelling. De sabotage richtte geen schade aan. Continue Reading
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks post, april 17, 2025april 24, 2025 Apple on Wednesday released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two security flaws that it said have come under active exploitation in the wild. The vulnerabilities in question are listed below – Continue Reading
U.S. Govt. Funding for MITRE’s CVE Ends April 16, Cybersecurity Community on Alert post, april 16, 2025 The U.S. government funding for non-profit research giant MITRE to operate and maintain its Common Vulnerabilities and Exposures (CVE) program will expire Wednesday, an unprecedented development that could shake up one of the foundational pillars of the global cybersecurity ecosystem. The 25-year-old CVE program is a valuable tool for vulnerability… Continue Reading
CISA Rescues MITRE’s Critical Common Vulnerabilities & Exposures (CVE) Program With Extended Funding post, april 16, 2025april 17, 2025 The United States Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that the U.S. government has extended funding for the Common Vulnerabilities and Exposures (CVE) program, ensuring uninterrupted operations. On April 15, 2025, it was reported that the U.S. government would not renew MITRE’s contract, ending on April 16. Without… Continue Reading
EC issues burner phones for visits to US post, april 15, 2025april 16, 2025 The European Commission is giving staffers visiting the US on official business burner laptops and phones to avoid espionage attempts, according to the Financial Times. The use of clean and locked-down hardware is common practice for anyone visiting China, Russia, and other states where aggressive electronic surveillance is expected. Apparently… Continue Reading
HelloKitty Ransomware Resurafced Targeting Windows, Linux, & ESXi Environments post, april 13, 2025april 14, 2025 Cybersecurity experts have detected a concerning revival of the HelloKitty ransomware, with new variants actively targeting Windows, Linux, and ESXi environments simultaneously. First observed in October 2020, HelloKitty has evolved from its origins as a DeathRansom ransomware fork, expanding its targeting capabilities and refining its attack techniques. Continue Reading
Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords post, april 9, 2025 Fortinet has issued urgent security updates to address a critical vulnerability in FortiSwitch that could allow attackers to change passwords without authorization. The flaw, identified as CVE-2024-48887, has been assigned a CVSS score of 9.8 out of 10. According to Fortinet’s advisory, the vulnerability lies in the FortiSwitch GUI and… Continue Reading