Category: Securityaffairs

NSO Group must pay WhatsApp over $167M in damages for attacks on its users
07
May
2025

NSO Group must pay WhatsApp over $167M in damages for attacks on its users

NSO Group must pay WhatsApp over $167M in damages for attacks on its users Pierluigi Paganini May 07, 2025 NSO…

U.S. CISA adds FreeType flaw to its Known Exploited Vulnerabilities catalog
07
May
2025

U.S. CISA adds FreeType flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds FreeType flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini May 07, 2025 U.S. Cybersecurity and Infrastructure Security…

Samsung MagicINFO flaw exploited days after PoC publication
06
May
2025

Samsung MagicINFO flaw exploited days after PoC publication

Samsung MagicINFO flaw exploited days after PoC exploit publication Pierluigi Paganini May 06, 2025 Threat actors started exploiting a vulnerability…

SAP NetWeaver zero-day allegedly exploited by an initial access broker
06
May
2025

Experts warn of a second wave of attacks targeting SAP NetWeaver bug CVE-2025-31324

Experts warn of a second wave of attacks targeting SAP NetWeaver bug CVE-2025-31324 Pierluigi Paganini May 06, 2025 Threat actors…

U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalog
06
May
2025

U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Langflow flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini May 06, 2025 U.S. Cybersecurity and Infrastructure…

Google fixed actively exploited Android flaw CVE-2025-27363
06
May
2025

Google fixed actively exploited Android flaw CVE-2025-27363

Google fixed actively exploited Android flaw CVE-2025-27363 Pierluigi Paganini May 06, 2025 Google addressed 46 Android security vulnerabilities, including one…

New 'Bring Your Own Installer (BYOI)' technique allows to bypass EDR
06
May
2025

New ‘Bring Your Own Installer (BYOI)’ technique allows to bypass EDR

New ‘Bring Your Own Installer (BYOI)’ technique allows to bypass EDR Pierluigi Paganini May 06, 2025 A new BYOI technique…

Smishing on a Massive Scale: ‘Panda Shop’ Chinese Carding Syndicate
06
May
2025

Smishing on a Massive Scale: ‘Panda Shop’ Chinese Carding Syndicate

Smishing on a Massive Scale: ‘Panda Shop’ Chinese Carding Syndicate Pierluigi Paganini May 06, 2025 Resecurity found a new smishing…

Kelly Benefits December data breach impacted over 400,000 individuals
05
May
2025

Kelly Benefits December data breach impacted over 400,000 individuals

Kelly Benefits December data breach impacted over 400,000 individuals Pierluigi Paganini May 05, 2025 Kelly Benefits has determined that the…

A hacker stole data from TeleMessage, the firm that sells modified versions of Signal to the U.S. gov
05
May
2025

A hacker stole data from TeleMessage, the firm that sells modified versions of Signal to the U.S. gov

A hacker stole data from TeleMessage, the firm that sells modified versions of Signal to the U.S. gov Pierluigi Paganini May…

Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks
05
May
2025

Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks

Experts shared up-to-date C2 domains and other artifacts related to recent MintsLoader attacks Pierluigi Paganini May 05, 2025 MintsLoader is…

Sansec uncovered a supply chain attack via 21 backdoored Magento extensions
05
May
2025

Sansec uncovered a supply chain attack via 21 backdoored Magento extensions

Sansec uncovered a supply chain attack via 21 backdoored Magento extensions Pierluigi Paganini May 05, 2025 Supply chain attack via…