Category: CyberSecurityNews

How to Radically Cut Response Time for Each Security Incident 
18
Sep
2025

How to Radically Cut Response Time for Each Security Incident 

When an incident happens, there’s no time to waste.  SOC teams must react fast to protect their organization, and this…

Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure
18
Sep
2025

Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure

Cloudflare has published a detailed post-mortem explaining the significant outage on September 12, 2025, that made its dashboard and APIs…

BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen
18
Sep
2025

BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen

The infamous Everest ransomware group has reportedly included Bayerische Motoren Werke AG (BMW) as a high-profile target, claiming the theft…

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks
18
Sep
2025

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks

SquareX first discovered and disclosed Last Mile Reassembly attacks at DEF CON 32 last year, warning the security community of…

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail
18
Sep
2025

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail

A zero-click vulnerability discovered in ChatGPT’s Deep Research agent allowed attackers to exfiltrate sensitive data from a user’s Gmail account…

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text
18
Sep
2025

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text

Microsoft is integrating free, on-device artificial intelligence capabilities into the classic Notepad application for Windows 11 users with Copilot+ PCs….

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens
18
Sep
2025

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens

Attackers injected malicious code into GitHub Actions workflows in a widespread campaign to steal Python Package Index (PyPI) publishing tokens….

Critical Microsoft's Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control
18
Sep
2025

Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control

A critical vulnerability in Microsoft’s Entra ID could have allowed an attacker to gain complete administrative control over any tenant…

New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments
18
Sep
2025

New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments

Emerging in mid-2025, the shinysp1d3r ransomware-as-a-service (RaaS) platform represents the next evolution of cloud-focused extortion tools. Unlike traditional ransomware that…

PureVPN Vulnerability Exposes Users IPv6 Address While Toggling Wi-Fi
18
Sep
2025

PureVPN Vulnerability Exposes Users IPv6 Address While Toggling Wi-Fi

PureVPN’s Linux clients leak users’ IPv6 addresses when Wi-Fi reconnections or system resumes occur, and also obliterate host firewall rules…

SonicWall Urges Customers to Reset Login Credentials After Configuration Backup Files Exposed
18
Sep
2025

SonicWall Urges Customers to Reset Login Credentials After Configuration Backup Files Exposed

SonicWall has issued an urgent advisory urging all customers to perform an Essential Credential Reset after security researchers discovered that…

Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service
18
Sep
2025

Jenkins Patches Multiple Vulnerabilities that Allow Attackers to Cause a Denial of Service

Jenkins has released critical updates addressing four security flaws that unauthenticated and low-privileged attackers could exploit to disrupt service or…