Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks
13
Aug
2025

Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks

Proofpoint researchers have uncovered a novel technique allowing threat actors to bypass FIDO-based authentication through downgrade attacks, leveraging a custom…

Croatian research institute confirms ransomware attack via ToolShell vulnerabilities
13
Aug
2025

Croatian research institute confirms ransomware attack via ToolShell vulnerabilities

The Ruđer Bošković Institute (RBI), the largest Croatian science and technology research institute, has confirmed that it was the one…

Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws
13
Aug
2025

Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE Flaws

Aug 13, 2025Ravie LakshmananVulnerability / Software Security Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows…

Over £18m stolen from Santander UK customers in first three months of year
13
Aug
2025

Santander will make AI training mandatory for all staff in 2026

Banco Santander will introduce a mandatory artificial intelligence (AI) training programme for all its staff next year, as part of…

FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control
13
Aug
2025

FortiOS, FortiProxy, and FortiPAM Auth Bypass Vulnerability Allows Attackers to Gain Full Control

A high-severity authentication bypass vulnerability affecting multiple Fortinet security products, including FortiOS, FortiProxy, and FortiPAM systems.  The flaw, designated as…

ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns
13
Aug
2025

ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns

The financially motivated threat group ShinyHunters has returned with a sophisticated series of attacks targeting Salesforce instances across high-profile enterprises…

New Brute-Force Campaign Hits Fortinet SSL VPN in Coordinated Attack
13
Aug
2025

New Brute-Force Campaign Hits Fortinet SSL VPN in Coordinated Attack

A surge in brute-force attacks on Fortinet products could signal a new vulnerability. A timeline shows a strong link between…

NIST finalizes lightweight cryptography standard for small devices
13
Aug
2025

NIST finalizes lightweight cryptography standard for small devices

The National Institute of Standards and Technology (NIST) has finalized a lightweight cryptography standard to protect even the smallest networked…

The UK’s ransomware payment ban is a strategic win
13
Aug
2025

What the UK’s ransomware crackdown signals for Europe

Cyber attacks are no longer confined to the realm of IT – they are a systemic risk to economies, governments,…

CISA is facing a tight CIRCIA deadline. Here’s how Sean Plankey can attempt to meet it
13
Aug
2025

Patch the vulnerability: Confirm Sean Plankey as CISA director

Every chief information security officer understands that unresolved vulnerabilities can eventually become entry points for threats. In the private sector,…

PowerShell
13
Aug
2025

Microsoft removes PowerShell 2.0 from Windows 11, Windows Server

Microsoft will remove PowerShell 2.0 from Windows starting in August, eight years after announcing its deprecation and keeping it around…

What is MCP Server – How it is Powering AI-Driven Cyber Defense
13
Aug
2025

What is MCP Server – How it is Powering AI-Driven Cyber Defense

MCP (Model Control Plane) Server is a centralized platform that orchestrates, manages, and secures the lifecycle of AI models deployed…