Category: Securityaffairs

BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian government
01
Nov
2025

BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian government

BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian government Pierluigi Paganini November 01, 2025 Australia warns of attacks…

China-linked UNC6384 exploits Windows zero-day to spy on European diplomats
01
Nov
2025

China-linked UNC6384 exploits Windows zero-day to spy on European diplomats

China-linked UNC6384 exploits Windows zero-day to spy on European diplomats Pierluigi Paganini November 01, 2025 A China-linked APT group UNC6384…

Two Linux flaws can lead to the disclosure of sensitive data
31
Oct
2025

Old Linux Kernel flaw CVE-2024-1086 resurfaces in ransomware attacks

Old Linux Kernel flaw CVE-2024-1086 resurfaces in ransomware attacks Pierluigi Paganini October 31, 2025 CISA warns ransomware gangs exploit CVE-2024-1086,…

Ernst & Young Exposes 4TB SQL Server Backup Publicly on Microsoft Azure
31
Oct
2025

Ernst & Young Exposes 4TB SQL Server Backup Publicly on Microsoft Azure

EY Exposes 4TB SQL Server Backup Publicly on Microsoft Azure Pierluigi Paganini October 31, 2025 A massive 4TB SQL Server…

Suspected Chinese actors compromise U.S. Telecom firm Ribbon Communications
31
Oct
2025

Suspected Chinese actors compromise U.S. Telecom firm Ribbon Communications

Suspected Chinese actors compromise U.S. Telecom firm Ribbon Communications Pierluigi Paganini October 31, 2025 A nation-state actor, likely a China-nexus…

U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog
31
Oct
2025

U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog…

CVE-2025-10585 is the sixth actively exploited Chrome zero-day patched by Google in 2025
30
Oct
2025

Brush exploit can cause any Chromium browser to collapse in 15-60 seconds

Brush exploit can cause any Chromium browser to collapse in 15-60 seconds Pierluigi Paganini October 30, 2025 “Brash” flaw in…

Former developer jailed after deploying kill-switch malware at Ohio firm
30
Oct
2025

Ex-Defense contractor exec pleads guilty to selling cyber exploits to Russia

Ex-Defense contractor exec pleads guilty to selling cyber exploits to Russia Pierluigi Paganini October 30, 2025 Former US defense contractor…

Kelly Benefits December data breach impacted over 400,000 individuals
30
Oct
2025

Dentsu’s US subsidiary Merkle hit by cyberattack, staff and client data exposed

Dentsu’s US subsidiary Merkle hit by cyberattack, staff and client data exposed Pierluigi Paganini October 30, 2025 Dentsu said its…

Canada’s second-largest airline WestJet is containing a cyberattack
30
Oct
2025

Hacktivists breach Canada’s critical infrastructure, cyber Agency warns

Hacktivists breach Canada’s critical infrastructure, cyber Agency warns Pierluigi Paganini October 29, 2025 Canada’s cyber agency warns hacktivists breached critical…

Wing FTP Server flaw actively exploited shortly after technical details were made public
29
Oct
2025

Russian hackers, likely linked to Sandworm, exploit legitimate tools against Ukrainian targets

Russian hackers, likely linked to Sandworm, exploit legitimate tools against Ukrainian targets Pierluigi Paganini October 29, 2025 Russian actors, likely…

U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog
29
Oct
2025

U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Dassault Systèmes DELMIA Apriso flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini October 29, 2025 U.S….