SharePoint under fire: new ToolShell attacks target enterprises

11 months ago

While SentinelOne did not attribute the attack to a specific threat actor, The Washington Post linked it to China-nexus acors.…

CrushFTP zero-day actively exploited at least since July 18

11 months ago

Hackers exploit CrushFTP zero-day, tracked as CVE-2025-54309, to gain admin access via HTTPS when DMZ proxy is off. Threat actors…

Hardcoded credentials found in HPE Aruba Instant On Wi-Fi devices

11 months ago

Hardcoded credentials in HPE Aruba Instant On Wi-Fi devices, let attackers to bypass authentication and access the web interface. HPE…

MuddyWater deploys new DCHSpy variants amid Iran-Israel conflict

11 months ago

Iran-linked APT MuddyWater is deploying new DCHSpy spyware variants to target Android users amid the ongoing conflict with Israel. Lookout…

U.S. CISA urges to immediately patch Microsoft SharePoint flaw adding it to its Known Exploited Vulnerabilities catalog

11 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…

Microsoft issues emergency patches for SharePoint zero-days exploited in “ToolShell” attacks

11 months ago

Microsoft patched an exploited SharePoint flaw (CVE-2025-53770) and disclosed a new one, warning of ongoing attacks on on-prem servers. Microsoft…

SharePoint zero-day CVE-2025-53770 actively exploited in the wild

11 months ago

Microsoft warns of ongoing active exploitation of a SharePoint zero-day vulnerability, tracked as CVE-2025-53770. Microsoft warns of a SharePoint zero-day…

Singapore warns China-linked group UNC3886 targets its critical infrastructure

11 months ago

Singapore says China-linked group UNC3886 targeted its critical infrastructure by hacking routers and security devices. Singapore accused China-linked APT group…

U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog

11 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 54

11 months ago

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape KongTuke…

This website uses cookies.