Featured

Recent 7-Zip Vulnerability Exploited in Attacks

Recent 7-Zip Vulnerability Exploited in Attacks 2025-11-20 at 13:09 By Ionut Arghire A proof-of-concept (PoC) exploit targeting the high-severity remote code execution (RCE) bug exists. The post Recent 7-Zip Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent 7-Zip Vulnerability Exploited in Attacks Read More »

Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion Deal

Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion Deal 2025-11-20 at 04:32 By SecurityWeek News The move to acquire Chronosphere is the latest of several acquisitions in recent years and follows a massive $25 billion deal to acquire CyberArk. The post Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion

Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion Deal Read More »

Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes

Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes 2025-11-19 at 20:16 By Eduard Kovacs Amazon threat intelligence experts have documented two cases in which Iran leveraged hacking to prepare for kinetic attacks. The post Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes appeared first on SecurityWeek. This

Amazon Details Iran’s Cyber-Enabled Kinetic Attacks Linking Digital Spying to Physical Strikes Read More »

Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week 2025-11-19 at 11:49 By Ionut Arghire An OS command injection flaw, the exploited zero-day allows attackers to execute arbitrary code on the underlying system. The post Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week Read More »

Cloudflare Outage Not Caused by Cyberattack

Cloudflare Outage Not Caused by Cyberattack 2025-11-18 at 20:17 By Eduard Kovacs Major online services such as ChatGPT, X, and Shopify were disrupted in a, as well as transit and city services.  The post Cloudflare Outage Not Caused by Cyberattack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cloudflare Outage Not Caused by Cyberattack Read More »

Logitech Confirms Data Breach Following Designation as Oracle Hack Victim

Logitech Confirms Data Breach Following Designation as Oracle Hack Victim 2025-11-17 at 13:10 By Eduard Kovacs Logitech was listed on the Cl0p ransomware leak website in early November, but its disclosure does not mention Oracle. The post Logitech Confirms Data Breach Following Designation as Oracle Hack Victim appeared first on SecurityWeek. This article is an

Logitech Confirms Data Breach Following Designation as Oracle Hack Victim Read More »

Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability

Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability 2025-11-14 at 23:49 By Ionut Arghire Security firms say the flaw has been actively exploited for weeks, even as Fortinet quietly shipped fixes and CISA added the bug to its KEV catalog. The post Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability appeared first on SecurityWeek. This

Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability Read More »

Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit  

Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit   2025-11-14 at 10:30 By Eduard Kovacs The cybercriminals informed customers that their cloud server was shut down due to complaints. The post Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit   appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit   Read More »

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon 2025-11-13 at 11:57 By Ionut Arghire Amazon has seen a threat actor exploiting CVE-2025-20337 and CVE-2025-5777, two critical Cisco and Citrix vulnerabilities, as zero-days. The post Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon Read More »

Virtual Event Today: CISO Forum 2025 Virtual Summit

Virtual Event Today: CISO Forum 2025 Virtual Summit 2025-11-12 at 18:16 By SecurityWeek News From the evolving role of AI to the realities of cloud risk and governance, the CISO Forum Virtual Summit brings together CISOs, researchers, and innovators to share practical insights and strategies. The post Virtual Event Today: CISO Forum 2025 Virtual Summit

Virtual Event Today: CISO Forum 2025 Virtual Summit Read More »

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit 2025-11-12 at 15:02 By Eduard Kovacs Google is targeting the threat group known as Smishing Triad, which used over 194,000 malicious domains in a campaign.  The post Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit Read More »

Microsoft Patches Actively Exploited Windows Kernel Zero-Day

Microsoft Patches Actively Exploited Windows Kernel Zero-Day 2025-11-11 at 23:07 By Eduard Kovacs Microsoft’s latest Patch Tuesday updates address more than 60 vulnerabilities in Windows and other products. The post Microsoft Patches Actively Exploited Windows Kernel Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Actively Exploited Windows Kernel Zero-Day Read More »

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics 2025-11-11 at 14:10 By Ionut Arghire Attackers intercepting network traffic can determine the conversation topic with a chatbot despite end-to-end encrypted communication. The post ‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

‘Whisper Leak’ LLM Side-Channel Attack Infers User Prompt Topics Read More »

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site 2025-11-10 at 16:49 By Eduard Kovacs The Cl0p website lists major organizations such as Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ Corporation, and Copeland. The post Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site

Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site Read More »

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz 2025-11-07 at 13:16 By Eduard Kovacs Google’s acquisition of Wiz is expected to close in 2026, but there are other reviews that need to be cleared. The post DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz appeared first on SecurityWeek. This article is

DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz Read More »

Researchers Hack ChatGPT Memories and Web Search Features

Researchers Hack ChatGPT Memories and Web Search Features 2025-11-06 at 19:09 By Eduard Kovacs Tenable researchers discovered seven vulnerabilities, including ones affecting the latest GPT model. The post Researchers Hack ChatGPT Memories and Web Search Features appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Researchers Hack ChatGPT Memories and Web Search Features Read More »

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns 2025-11-05 at 17:25 By Eduard Kovacs Google has released a report describing the novel ways in which malware has been using AI to adapt and evade detection. The post Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns Read More »

Claude AI APIs Can Be Abused for Data Exfiltration

Claude AI APIs Can Be Abused for Data Exfiltration 2025-11-03 at 15:57 By Ionut Arghire An attacker can inject indirect prompts to trick the model into harvesting user data and sending it to the attacker’s account. The post Claude AI APIs Can Be Abused for Data Exfiltration appeared first on SecurityWeek. This article is an

Claude AI APIs Can Be Abused for Data Exfiltration Read More »

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks 2025-11-03 at 12:28 By Ionut Arghire PowerShell and .NET variants of the malware abuse AirWatch’s MDM API to establish a C&C communication channel. The post Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks Read More »

Scroll to Top