200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypass

3 hours ago
Pierluigi Paganini

About 200K Linux systems from Framework shipped with signed UEFI components vulnerable to Secure Boot bypass, allowing bootkit installation and…

SAP fixed maximum-severity bug in NetWeaver

7 hours ago

SAP addressed 13 new flaws, including a maximum severity vulnerability in SAP NetWeaver, which could lead to arbitrary command execution. SAP…

Unencrypted satellites expose global communications

10 hours ago

Researchers found nearly half of geostationary satellites leak unencrypted data, exposing consumer, corporate, and military communications. A group of researchers…

Flax Typhoon APT exploited ArcGIS server for over a year as a backdoor

10 hours ago

China-linked cyberespionage group Flax Typhoon hijacked an ArcGIS system for over a year and used it as a backdoor. China-linked…

Researchers warn of widespread RDP attacks by 100K-node botnet

23 hours ago

A botnet of 100K+ IPs from multiple countries is attacking U.S. RDP services in a campaign active since October 8.…

Harvard University hit in Oracle EBS cyberattack, 1.3 TB of data leaked by Cl0p group

1 day ago

Harvard University confirmed being targeted in the Oracle EBS campaign after the Cl0p ransomware group leaked 1.3 TB of data.…

UK NCSC Reports 429 cyberattacks in a year, with nationally significant cases more than doubling

1 day ago

The UK’s NCSC handled 429 cyberattacks from Sept 2024–Aug 2025, including 204 nationally significant cases, over double the previous year’s…

Unverified COTS hardware enables persistent attacks in small satellites via SpyChain<gwmw style="display:none;"></gwmw>

1 day ago

SpyChain shows how unverified COTS hardware in small satellites can enable persistent, multi-component supply chain attacks using NASA’s NOS3 simulator.…

Oracle issued an emergency security update to fix new E-Business Suite flaw CVE-2025-61884

1 day ago

Oracle issued an emergency security update to address a new E-Business Suite (EBS) vulnerability tracked as CVE-2025-61884. Oracle released an emergency…

Customer payment data stolen in Unity Technologies’s SpeedTree website compromise

2 days ago

Malicious code on Unity Technologies’s SpeedTree site skimmed sensitive data from hundreds of customers, the company confirmed. Video game software…

This website uses cookies.