Chinese-speaking hackers exploited ESXi zero-days long before disclosure

4 months ago

Chinese-speaking attackers used a hacked SonicWall VPN to deploy ESXi zero-days that were likely exploited over a year before public…

Astaroth banking Trojan spreads in Brazil via WhatsApp worm

4 months ago

A WhatsApp worm spread the Astaroth banking trojan across Brazil by automatically sending malicious messages to victims’ contacts. Astaroth, a…

Public PoC prompts Cisco patch for ISE, ISE-PIC vulnerability

4 months ago

Cisco addressed a medium-severity vulnerability in ISE and ISE-PIC after a public PoC exploit was disclosed. Cisco addressed a medium-severity…

U.S. CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalog

4 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalog.…

China-linked groups intensify attacks on Taiwan’s critical infrastructure, NSB warns<gwmw style="display:none;"></gwmw>

4 months ago

Taiwan says China-linked cyberattacks on its energy sector rose tenfold in 2025, hitting critical infrastructure across nine sectors, with total…

Ni8mare flaw gives unauthenticated control of n8n instances

4 months ago

A critical n8n flaw (CVE-2026-21858, CVSS 10.0), dubbed Ni8mare, allows unauthenticated attackers to fully take over vulnerable instances. Researchers uncovered…

Misconfigured email routing enables internal-spoofed phishing

4 months ago

Attackers exploit misconfigured email routing to spoof internal emails, using PhaaS platforms like Tycoon2FA to steal credentials. Attackers exploit misconfigured…

Veeam resolves CVSS 9.0 RCE flaw and other security issues

4 months ago

Veeam patched a critical RCE flaw in Backup & Replication, CVE-2025-59470, rated CVSS 9.0, along with other vulnerabilities. Veeam released…

Hackers actively exploit critical RCE flaw in legacy D-Link DSL routers

4 months ago

Attackers are exploiting a critical flaw (CVE-2026-0625) in old D-Link DSL routers that allows remote command execution. Threat actors are…

Fake Booking.com lures and BSoD scams spread DCRat in European hospitality sector

4 months ago

PHALT#BLYX targets European hotels with fake Booking emails and BSoD lures, tricking staff into installing the DCRat remote access trojan.…

This website uses cookies.