Category: CyberSecurityNews

SolarWinds Releases Advisory on Salesloft Drift Security Incident
19
Sep
2025

SolarWinds Releases Advisory on Salesloft Drift Security Incident

SolarWinds has released an advisory regarding a security incident involving the Salesloft Drift integration for Salesforce, which led to unauthorized…

GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware
19
Sep
2025

GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware

The cyberthreat landscape has witnessed the emergence of another sophisticated ransomware operation as GOLD SALEM, a new threat actor group…

Russian Fake-News Network CopyCop Added 200+ New Websites to Targets US, Canada and France
18
Sep
2025

Russian Fake-News Network CopyCop Added 200+ New Websites to Targets US, Canada and France

The Russian covert influence network CopyCop has significantly expanded its disinformation campaign, establishing over 200 new fictional media websites since…

How to Radically Cut Response Time for Each Security Incident 
18
Sep
2025

How to Radically Cut Response Time for Each Security Incident 

When an incident happens, there’s no time to waste.  SOC teams must react fast to protect their organization, and this…

Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure
18
Sep
2025

Cloudflare API Outage Linked to React useEffect Bug Causes Service Overload and Recovery Failure

Cloudflare has published a detailed post-mortem explaining the significant outage on September 12, 2025, that made its dashboard and APIs…

BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen
18
Sep
2025

BMW Allegedly Breached by Everest Ransomware Group, Internal Documents Reportedly Stolen

The infamous Everest ransomware group has reportedly included Bayerische Motoren Werke AG (BMW) as a high-profile target, claiming the theft…

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks
18
Sep
2025

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks

SquareX first discovered and disclosed Last Mile Reassembly attacks at DEF CON 32 last year, warning the security community of…

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail
18
Sep
2025

0-Click ChatGPT Agent Vulnerability Allows Sensitive Data Exfiltration from Gmail

A zero-click vulnerability discovered in ChatGPT’s Deep Research agent allowed attackers to exfiltrate sensitive data from a user’s Gmail account…

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text
18
Sep
2025

Windows 11 Notepad to Get AI Support for Free to Generate and Summarize Text

Microsoft is integrating free, on-device artificial intelligence capabilities into the classic Notepad application for Windows 11 users with Copilot+ PCs….

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens
18
Sep
2025

Hackers Injecting Malicious Code into GitHub Actions Workflows to Steal PyPI Publishing Tokens

Attackers injected malicious code into GitHub Actions workflows in a widespread campaign to steal Python Package Index (PyPI) publishing tokens….

Critical Microsoft's Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control
18
Sep
2025

Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control

A critical vulnerability in Microsoft’s Entra ID could have allowed an attacker to gain complete administrative control over any tenant…

New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments
18
Sep
2025

New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments

Emerging in mid-2025, the shinysp1d3r ransomware-as-a-service (RaaS) platform represents the next evolution of cloud-focused extortion tools. Unlike traditional ransomware that…