Security Affairs

ASUS routers with AiCloud vulnerable to auth bypass exp...

ASUS warns of an authentication bypass vulnerability in routers with AiCloud ena...

U.S. CISA adds Apple products and Microsoft Windows NTL...

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple products...

Entertainment venue management firm Legends Internation...

Legends International disclosed a data breach from November 2024 that affected e...

China-linked APT Mustang Panda upgrades tools in its ar...

China-linked APT group Mustang Panda deployed a new custom backdoor, MQsTTang, i...

Node.js malvertising campaign targets crypto users

Microsoft warns of a malvertising campaign using Node.js to deliver info-stealin...

Apple released emergency updates for actively exploited...

Apple released emergency updates to fix iOS, iPadOS & macOS vulnerabilities acti...

U.S. CISA adds SonicWall SMA100 Appliance flaw to its K...

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall SMA1...

CISA’s 11-Month extension ensures continuity of MITRE’s...

MITRE’s U.S.-funded CVE program, a core cybersecurity tool for tracking vulnerab...

Chinese Android phones shipped with malware-laced Whats...

Cheap Chinese Android phones ship with trojanized WhatsApp and Telegram clones h...

Government contractor Conduent disclosed a data breach

The business services provider Conduent told the SEC a January cyberattack expos...

Cyber Threats Against Energy Sector Surge as Global Ten...

Resecurity warns of rising cyberattacks on the energy sector, some linked to lar...

Critical Apache Roller flaw allows to retain unauthoriz...

A critical flaw (CVE-2025-24859, CVSS 10) in Apache Roller lets attackers keep a...

Meta will use public EU user data to train its AI models

Meta announced that it will use public EU user data to train AI, resuming plans ...

Hertz disclosed a data breach following 2024 Cleo zero-...

Hertz Corporation disclosed a data breach after customer data was stolen via Cle...

Gladinet flaw CVE-2025-30406 actively exploited in the ...

Huntress reports active exploitation of Gladinet CVE-2025-30406 in the wild, aff...

New malware ‘ResolverRAT’ targets healthcare, pharmaceu...

New malware ‘ResolverRAT’ is targeting healthcare and pharmaceutical firms, usin...

Malicious NPM packages target PayPal users

Threat actors deploy malicious NPM packages to steal PayPal credentials and hija...

Tycoon2FA phishing kit rolled out significant updates

The operators of the Phishing-as-a-Service (PhaaS) platform Tycoon2FA have rolle...

South African telecom provider Cell C disclosed a data ...

Cell C, one of the biggest telecom providers in South Africa confirms a data bre...

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 41

Security Affairs Malware newsletter includes a collection of the best articles a...

Security Affairs newsletter Round 519 by Pierluigi Paga...

A new round of the weekly SecurityAffairs newsletter arrived! Every week the bes...

China admitted its role in Volt Typhoon cyberattacks on...

China admitted in a secret meeting with U.S. officials that it conducted Volt Ty...

Symbolic Link trick lets attackers bypass FortiGate pat...

Fortinet warns attackers can keep read-only access to FortiGate devices even aft...

Attackers are exploiting recently disclosed OttoKit Wor...

Threat actors are exploiting a vulnerability in the OttoKit WordPress plugin, a ...

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.