Category: CyberSecurityDive

Researchers back claim of Oracle Cloud breach despite company’s denials
27
Mar
2025

Researchers back claim of Oracle Cloud breach despite company’s denials

Dive Brief: Security researchers said they confirmed a breach of Oracle Cloud after a previously unknown threat actor posted an…

Critical vulnerabilities put Kubernetes environments in jeopardy
27
Mar
2025

Critical vulnerabilities put Kubernetes environments in jeopardy

Dive Brief: Wiz researchers on Monday disclosed the technical details of four critical vulnerabilities — CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974…

Russian threat actor weaponized Microsoft Management Console flaw
27
Mar
2025

Russian threat actor weaponized Microsoft Management Console flaw

A prolific Russian threat actor is exploiting a zero-day flaw in the Microsoft Management Console (MMC) framework to execute malicious…

DrayTek routers face active exploitation of older vulnerabilities
27
Mar
2025

DrayTek routers face active exploitation of older vulnerabilities

Dive Brief: Researchers warn that three older vulnerabilities in DrayTek routers have been actively exploited in recent weeks, which coincides…

SuperBlack ransomware strain used in attacks targeting Fortinet vulnerabilities
24
Mar
2025

Critical Apache Tomcat RCE vulnerability exploited

Dive Brief: Researchers from GreyNoise on Thursday reported active exploitation of CVE-2025-24813, a critical remote code execution vulnerability in Apache Tomcat…

How ASPM gives you control over complex architectures
24
Mar
2025

How ASPM gives you control over complex architectures

As organizations embrace more dynamic and complex application architectures—such as microservices, hybrid cloud infrastructures, and rapid CI/CD pipelines—securing these environments…

Coinbase originally targeted during GitHub Action supply chain attack
21
Mar
2025

Coinbase originally targeted during GitHub Action supply chain attack

Dive Brief:  The threat actors in the GitHub Action supply chain attack were targeting Coinbase as part of their initial…

Medusa ransomware using malicious driver as EDR killer
21
Mar
2025

Medusa ransomware using malicious driver as EDR killer

A Medusa ransomware campaign is using a malicious driver to disrupt and even delete endpoint detection and response (EDR) products…

Cisco Smart Licensing Utility flaws under attack
20
Mar
2025

Cisco Smart Licensing Utility flaws under attack

Dive Brief: Johannes Ullrich of the SANS Internet Storm Center reported exploitation attempts this week against two critical Cisco vulnerabilities…

GitHub Action compromise linked to previously undisclosed attack
20
Mar
2025

GitHub Action compromise linked to previously undisclosed attack

Dive Brief: The GitHub Action supply chain compromise that threatened the security of more than 23,000 repositories appears to be…

11 nation-state groups exploit unpatched Microsoft zero-day
19
Mar
2025

11 nation-state groups exploit unpatched Microsoft zero-day

At least 11 state-sponsored threat groups since 2017 have been actively exploiting a Microsoft zero-day flaw allowing for abuse of…

Google acquisition of Wiz driven by enterprise embrace of multicloud
19
Mar
2025

Google acquisition of Wiz driven by enterprise embrace of multicloud

After previously being left at the altar, Alphabet Inc. reached a deal Tuesday through its Google business to buy Wiz…