Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year post, oktober 14, 2025 Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity, per ReliaQuest, is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and… Continue Reading
FBI Takes Down BreachForums: A Notorious Cybercrime Marketplace Tied To Salesforce Data Extortion post, oktober 10, 2025oktober 13, 2025 In a concerted cross-border operation, law enforcement agencies from the United States and France have seized control of the clearnet domain breachforums, effectively bringing down another incarnation of the infamous cybercrime marketplace, BreachForums. The domain now carries a joint seizure notice from the the U.S. Department of Justice (DOJ) and… Continue Reading
Critical Zero-Day In Oracle E-Business Suite | Patch Immediately post, oktober 6, 2025oktober 7, 2025 Oracle has released a high-urgency security alert for a newly discovered zero-day vulnerability in its E-Business Suite (EBS), tracked as CVE-2025-61882. This flaw enables unauthenticated, remote execution of arbitrary code, posing a severe risk to any exposed or unpatched installations. Oracle has classified it with a CVSS 3.1 base score… Continue Reading
Discord Confirms Major Data Breach Exposing User Info post, oktober 5, 2025oktober 7, 2025 Discord, one of the world’s leading communication platforms for gaming and online communities, has confirmed a data breach involving a third-party customer service provider that resulted in the exposure of sensitive user information. The breach affected a subset of users who had previously contacted Discord’s customer support or Trust &… Continue Reading
Signal Introduces New Post-Quantum Cryptographic Defense To Secure Messaging Against Future Quantum Threats post, oktober 4, 2025oktober 7, 2025 Signal, the widely used encrypted messaging platform, has unveiled a major step forward in safeguarding communications against the looming threat of quantum computing. The non-profit Signal Foundation announced the deployment of Sparse Post-Quantum Ratchet (SPQR), a new cryptographic system designed to ensure long-term privacy in a world where quantum computers… Continue Reading
Red Hat Confirms Major Data Breach post, oktober 2, 2025oktober 3, 2025 ech giant Red Hat has acknowledged that it is investigating a security incident affecting its consulting arm, following public claims by a hacking group, Crimson Collective, that it gained unauthorized access to internal repositories and obtained sensitive customer data. While Red Hat affirms the breach, it says it “has no… Continue Reading
Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs post, oktober 1, 2025oktober 3, 2025 The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools… Continue Reading
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware post, september 30, 2025oktober 3, 2025 Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42… Continue Reading
VMware Zero-Day Under Attack By China-Linked Hackers Since October 2024 post, september 30, 2025oktober 3, 2025 Broadcom has published security advisory VMSA-2025-0015, disclosing six vulnerabilities in VMware products — among them four rated High / Important — and urging users to apply patches immediately. One of the more serious flaws is CVE-2025-41244, a local privilege escalation vulnerability (CVSS score 7.8) Continue Reading
CISA and UK NCSC Release Joint Guidance for Securing OT Systems post, september 29, 2025oktober 3, 2025 CISA, in collaboration with the Federal Bureau of Investigation, the United Kingdom’s National Cyber Security Centre, and other international partners has released new joint cybersecurity guidance: Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture. Building on the recent Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and… Continue Reading