Category: Securityaffairs

DraftKings thwarts credential stuffing attack, but urges password reset and MFA
08
Oct
2025

DraftKings thwarts credential stuffing attack, but urges password reset and MFA

DraftKings thwarts credential stuffing attack, but urges password reset and MFA Pierluigi Paganini October 08, 2025 DraftKings warns of credential…

Redis patches 13-Year-Old Lua flaw enabling Remote Code Execution
08
Oct
2025

Redis patches 13-Year-Old Lua flaw enabling Remote Code Execution

Redis patches 13-Year-Old Lua flaw enabling Remote Code Execution Pierluigi Paganini October 08, 2025 Redis warns of CVE-2025-49844, a Lua…

U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
08
Oct
2025

U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini October 07, 2025…

Fortra addressed a maximum severity flaw in GoAnywhere MFT software
07
Oct
2025

GoAnywhere MFT zero-day used by Storm-1175 in Medusa ransomware campaigns

GoAnywhere MFT zero-day used by Storm-1175 in Medusa ransomware campaigns Pierluigi Paganini October 07, 2025 Storm-1175 exploits GoAnywhere MFT flaw…

CrowdStrike ties Oracle EBS RCE (CVE-2025-61882) to Cl0p attacks began Aug 9, 2025
07
Oct
2025

CrowdStrike ties Oracle EBS RCE (CVE-2025-61882) to Cl0p attacks began Aug 9, 2025

CrowdStrike ties Oracle EBS RCE (CVE-2025-61882) to Cl0p attacks began Aug 9, 2025 Pierluigi Paganini October 07, 2025 CrowdStrike links…

U.S. CISA adds CISCO Secure Firewall ASA and Secure FTD flaws to its Known Exploited Vulnerabilities catalog
07
Oct
2025

U.S. CISA adds Oracle, Mozilla, Microsoft Windows, Linux Kernel, and Microsoft IE flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Oracle, Mozilla, Microsoft Windows, Linux Kernel, and Microsoft IE flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini…

Discord discloses third-party breach affecting customer support data
07
Oct
2025

Discord discloses third-party breach affecting customer support data

Discord discloses third-party breach affecting customer support data Pierluigi Paganini October 06, 2025 Discord reported a data breach at a…

LinkedIn sues ProAPIs for $15K/Month LinkedIn data scraping scheme
06
Oct
2025

LinkedIn sues ProAPIs for $15K/Month LinkedIn data scraping scheme

LinkedIn sues ProAPIs for $15K/Month LinkedIn data scraping scheme Pierluigi Paganini October 06, 2025 LinkedIn sued ProAPIs and its CEO…

Oracle patches critical E-Business Suite flaw exploited by Cl0p hackers
06
Oct
2025

Oracle patches critical E-Business Suite flaw exploited by Cl0p hackers

Oracle patches critical E-Business Suite flaw exploited by Cl0p hackers Pierluigi Paganini October 06, 2025 Oracle fixed a critical flaw…

Zimbra users targeted in zero-day exploit using iCalendar attachments
06
Oct
2025

Zimbra users targeted in zero-day exploit using iCalendar attachments

Zimbra users targeted in zero-day exploit using iCalendar attachments Pierluigi Paganini October 06, 2025 Threat actors exploited a Zimbra zero-day…

EU agency ENISA says ransomware attack behind airport disruptions
06
Oct
2025

Reading the ENISA Threat Landscape 2025 report

Reading the ENISA Threat Landscape 2025 report Pierluigi Paganini October 06, 2025 ENISA Threat Landscape 2025: Rising ransomware, AI phishing,…

Weaponizing AWS X-Ray for Command & Control
05
Oct
2025

Weaponizing AWS X-Ray for Command & Control

Ghost in the Cloud: Weaponizing AWS X-Ray for Command & Control Pierluigi Paganini October 05, 2025 Attackers can weaponize AWS…