Zimbra Classic Web Client Vulnerability Allows Arbitrary JavaScript Execution
24
Jun
2025

Zimbra Classic Web Client Vulnerability Allows Arbitrary JavaScript Execution

A critical security flaw has been discovered and patched in the Zimbra Collaboration Suite (ZCS) Classic Web Client, exposing millions…

NinjaOne Reimagining What Is Possible In Automated Endpoint Management
24
Jun
2025

Deep Dive into Automated Security Testing Tools

Data breaches cost businesses globally an average of $4.88 million, according to IBM, but it doesn’t have to be that…

Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns
24
Jun
2025

Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns

The Department of Homeland Security has issued a critical advisory warning of escalating cyber threats from pro-Iranian hacktivist groups targeting…

NCSC Warns of SHOE RACK Malware Targeting Fortinet Firewalls via DOH & SSH Protocols
24
Jun
2025

NCSC Warns of SHOE RACK Malware Targeting Fortinet Firewalls via DOH & SSH Protocols

The National Cyber Security Centre (NCSC) has issued a critical alert regarding a newly identified malware, dubbed SHOE RACK, which…

Trojanized SonicWall NetExtender app exfiltrates VPN credentials
24
Jun
2025

Trojanized SonicWall NetExtender app exfiltrates VPN credentials

Unknown attackers have trojanized SonicWall’s SSL-VPN NetExtender application, the company has warned on Monday, and have been tricking users into…

The CTEM Conversation We All Need
24
Jun
2025

The CTEM Conversation We All Need

Jun 24, 2025Ravie LakshmananThreat Exposure Management I had the honor of hosting the first episode of the Xposure Podcast live…

Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data
24
Jun
2025

Weaponized DMV-Themed Phishing Attacking U.S. Citizens to Harvest Personal and Financial Data

A sophisticated phishing campaign emerged in May 2025, targeting U.S. citizens through a coordinated impersonation of state Department of Motor…

Critical Convoy Flaw Allows Remote Code Execution on Servers
24
Jun
2025

Critical Convoy Flaw Allows Remote Code Execution on Servers

Credential Abuse Unmasked Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our…

One year since being freed, Julian Assange still a victim of state secrecy
24
Jun
2025

One year since being freed, Julian Assange still a victim of state secrecy

It is one year since WikiLeaks founder Julian Assange became a free man again. When he addressed the Council of…

Ransomware Africa 2024, Ransomware, Africa, Interpol,
24
Jun
2025

Africa Faces A Digital Sextortion Crisis As Numbers Surge

A continent-wide takedown of 63,000 Instagram accounts in Nigeria in mid-2024 has spotlighted one of Africa’s fastest growing cyber threats:…

Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers
24
Jun
2025

Sophisticated Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers

A sophisticated malware campaign has emerged targeting WordPress and WooCommerce websites with highly obfuscated credit card skimmers and credential theft…

OPPO Clone Phone Vulnerability Leaks Sensitive Data via Weak WiFi Hotspot
24
Jun
2025

OPPO Clone Phone Vulnerability Leaks Sensitive Data via Weak WiFi Hotspot

A newly disclosed security vulnerability in OPPO’s widely used Clone Phone app has raised significant concerns over user privacy, as…