Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2025

CVE 2025 32711 is a turning point

post, juli 4, 2025juli 25, 2025

Last week, we saw the first confirmed zero click prompt injection breach against a production AI assistant.No malware. No links to click. No user interaction.Just a cleverly crafted email quietly triggering Microsoft 365 Copilot to leak sensitive org data as part of its intended behavior.

Continue Reading

Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms

post, juli 3, 2025

The French cybersecurity agency on Tuesday revealed that a number of entities spanning governmental, telecommunications, media, finance, and transport sectors in the country were impacted by a malicious campaign undertaken by a Chinese hacking group by weaponizing several zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices. The campaign, detected…

Continue Reading

Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials

post, juli 3, 2025

Cisco has released security updates to address a maximum-severity security flaw in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) that could permit an attacker to login to a susceptible device as the root user, allowing them to gain elevated privileges. The vulnerability,…

Continue Reading

Esse Health Data Breach Exposes 263,000 Patients Personal and Health Information

post, juli 3, 2025

A significant cybersecurity incident at Esse Health has compromised the personal and health information of approximately 263,000 patients, marking one of the most substantial healthcare data breaches of 2025. The Missouri-based healthcare provider discovered suspicious network activity on April 21, 2025, which led to the immediate engagement of external cybersecurity…

Continue Reading

Qantas Hit By Major Cyber-Attack, Exposing Data of Up To 6 Million Customers

post, juli 3, 2025

Qantas, Australia’s largest airline, has disclosed a significant cyberattack that compromised customer data via a third-party service platform. The breach was detected on Monday after threat actors gained access through a call centre platform used by the airline, potentially compromising the personal data of up to six million customers. Qantas…

Continue Reading

Mexican Cartel Hackers Exploited FBI Agent’s Phone + Public Surveillance Cameras To locate & kill Informants

post, juli 3, 2025juli 4, 2025

Sinaloa drug cartel hackers managed to access the phone records of an FBI agent and used surveillance cameras in Mexico City to track down and assassinate informants, according to a new report from the U.S. Department of Justice titled: Audit of the Federal Bureau of Investigation’s Efforts to Mitigate the…

Continue Reading

A Group of Young Cybercriminals Poses the ‘Most Imminent Threat’ of Cyberattacks Right Now

post, juli 2, 2025juli 4, 2025

The Scattered Spider hacking group has caused chaos among retailers, insurers, and airlines in recent months. Researchers warn that its flexible structure poses challenges for defense. Empty grocery store shelves and grounded planes tend to signal a crisis, whether it’s an extreme weather event, public health crisis, or geopolitical emergency. But these scenes of…

Continue Reading

GIFTEDCROOK Malware Evolves: From Browser Stealer to Intelligence-Gathering Tool

post, juni 28, 2025juni 30, 2025

The threat actor behind the GIFTEDCROOK malware has made significant updates to turn the malicious program from a basic browser data stealer to a potent intelligence-gathering tool. “Recent campaigns in June 2025 demonstrate GIFTEDCROOK’s enhanced ability to exfiltrate a broad range of sensitive documents from the devices of targeted individuals,…

Continue Reading

APT-C-36 Hackers Attacking Government Institutions, Financial Organizations, and Critical Infrastructure

post, juni 27, 2025juli 3, 2025

Since 2018, the advanced persistent threat group APT-C-36, commonly known as Blind Eagle, has emerged as a formidable cyber adversary targeting critical sectors across Latin America. This sophisticated threat actor has demonstrated persistent focus on Colombian organizations, launching coordinated attacks against government institutions, financial organizations, and critical infrastructure through carefully orchestrated phishing…

Continue Reading

‘Cyber Fattah’ Hacktivist Group Leaks Saudi Games Data

post, juni 27, 2025

As tensions in the Middle East rise, hacktivist groups are coming out of the woodwork with their own agendas, leading to notable shifts in the hacktivist threat landscape. A pro-Iranian hacktivist group known as Cyber Fattah leaked thousands of records containing information about visitors and athletes from past Saudi Games events. Saudi…

Continue Reading
  • Previous
  • 1
  • …
  • 7
  • 8
  • 9
  • …
  • 16
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes