Featured

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon 2025-11-13 at 11:57 By Ionut Arghire Amazon has seen a threat actor exploiting CVE-2025-20337 and CVE-2025-5777, two critical Cisco and Citrix vulnerabilities, as zero-days. The post Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon Read More »

Virtual Event Today: CISO Forum 2025 Virtual Summit

Virtual Event Today: CISO Forum 2025 Virtual Summit 2025-11-12 at 18:16 By SecurityWeek News From the evolving role of AI to the realities of cloud risk and governance, the CISO Forum Virtual Summit brings together CISOs, researchers, and innovators to share practical insights and strategies. The post Virtual Event Today: CISO Forum 2025 Virtual Summit

Virtual Event Today: CISO Forum 2025 Virtual Summit Read More »

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit 2025-11-12 at 15:02 By Eduard Kovacs Google is targeting the threat group known as Smishing Triad, which used over 194,000 malicious domains in a campaign.  The post Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit Read More »

Microsoft Patches Actively Exploited Windows Kernel Zero-Day

Microsoft Patches Actively Exploited Windows Kernel Zero-Day 2025-11-11 at 23:07 By Eduard Kovacs Microsoft’s latest Patch Tuesday updates address more than 60 vulnerabilities in Windows and other products. The post Microsoft Patches Actively Exploited Windows Kernel Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Actively Exploited Windows Kernel Zero-Day Read More »

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics 2025-11-11 at 14:10 By Ionut Arghire Attackers intercepting network traffic can determine the conversation topic with a chatbot despite end-to-end encrypted communication. The post ‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics Read More »

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site 2025-11-10 at 16:49 By Eduard Kovacs The Cl0p website lists major organizations such as Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ Corporation, and Copeland. The post Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site Read More »

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz 2025-11-07 at 13:16 By Eduard Kovacs Google’s acquisition of Wiz is expected to close in 2026, but there are other reviews that need to be cleared. The post DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz appeared first on SecurityWeek. This article is

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz Read More »

Researchers Hack ChatGPT Memories and Web Search Features

Researchers Hack ChatGPT Memories and Web Search Features 2025-11-06 at 19:09 By Eduard Kovacs Tenable researchers discovered seven vulnerabilities, including ones affecting the latest GPT model. The post Researchers Hack ChatGPT Memories and Web Search Features appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Researchers Hack ChatGPT Memories and Web Search Features Read More »

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns 2025-11-05 at 17:25 By Eduard Kovacs Google has released a report describing the novel ways in which malware has been using AI to adapt and evade detection. The post Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns Read More »

Claude AI APIs Can Be Abused for Data Exfiltration

Claude AI APIs Can Be Abused for Data Exfiltration 2025-11-03 at 15:57 By Ionut Arghire An attacker can inject indirect prompts to trick the model into harvesting user data and sending it to the attacker’s account. The post Claude AI APIs Can Be Abused for Data Exfiltration appeared first on SecurityWeek. This article is an

Claude AI APIs Can Be Abused for Data Exfiltration Read More »

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks 2025-11-03 at 12:28 By Ionut Arghire PowerShell and .NET variants of the malware abuse AirWatch’s MDM API to establish a C&C communication channel. The post Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks Read More »

Japan Issues OT Security Guidance for Semiconductor Factories

Japan Issues OT Security Guidance for Semiconductor Factories 2025-10-31 at 11:45 By Eduard Kovacs The 130-page document covers several important aspects and it’s available in both Japanese and English. The post Japan Issues OT Security Guidance for Semiconductor Factories appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Japan Issues OT Security Guidance for Semiconductor Factories Read More »

Major US Telecom Backbone Firm Hacked by Nation-State Actors

Major US Telecom Backbone Firm Hacked by Nation-State Actors 2025-10-30 at 15:46 By Eduard Kovacs Ribbon Communications provides technology for communications networks and its customers include the US government and major telecom firms.  The post Major US Telecom Backbone Firm Hacked by Nation-State Actors appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Major US Telecom Backbone Firm Hacked by Nation-State Actors Read More »

Former US Defense Contractor Executive Admits to Selling Exploits to Russia

Former US Defense Contractor Executive Admits to Selling Exploits to Russia 2025-10-30 at 11:32 By Ionut Arghire Peter Williams stole trade secrets from his US employer and sold them to a Russian cybersecurity tools broker. The post Former US Defense Contractor Executive Admits to Selling Exploits to Russia appeared first on SecurityWeek. This article is

Former US Defense Contractor Executive Admits to Selling Exploits to Russia Read More »

New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs 

New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  2025-10-29 at 10:23 By Eduard Kovacs Intel and AMD have published advisories after academics disclosed details of the new TEE.fail attack method. The post New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  appeared first on SecurityWeek. This

New Attack Targets DDR5 Memory to Steal Keys From Intel and AMD TEEs  Read More »

Hackers Target Swedish Power Grid Operator

Hackers Target Swedish Power Grid Operator 2025-10-28 at 12:32 By Ionut Arghire The hackers stole information from a file transfer solution and the country’s power supply was not affected. The post Hackers Target Swedish Power Grid Operator appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Target Swedish Power Grid Operator Read More »

$1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal

$1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal 2025-10-25 at 23:58 By Eduard Kovacs WhatsApp told SecurityWeek that the two low-impact vulnerabilities cannot be used for arbitrary code execution.  The post $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal appeared first on SecurityWeek. This article

$1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal Read More »

Critical Windows Server WSUS Vulnerability Exploited in the Wild 

Critical Windows Server WSUS Vulnerability Exploited in the Wild  2025-10-24 at 17:56 By Eduard Kovacs CVE-2025-59287 allows a remote, unauthenticated attacker to execute arbitrary code and a PoC exploit is available. The post Critical Windows Server WSUS Vulnerability Exploited in the Wild  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Critical Windows Server WSUS Vulnerability Exploited in the Wild  Read More »

Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta

Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta 2025-10-24 at 12:43 By Eduard Kovacs Questions have been raised over the technical viability of the purported WhatsApp exploit, but the researcher says he wants to keep his identity private. The post Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta appeared first on SecurityWeek. This

Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta Read More »

Scroll to Top