TARmageddon Security Flaw in Rust Library Could Lead to Config Tampering and RCE
23
Oct
2025

TARmageddon Security Flaw in Rust Library Could Lead to Config Tampering and RCE

The Edera security team has discovered a critical vulnerability in the async-tar Rust library and its descendants, including the widely-used…

BIND 9 Vulnerabilities Expose DNS Servers to Cache Poisoning and DoS
23
Oct
2025

BIND 9 Vulnerabilities Expose DNS Servers to Cache Poisoning and DoS

The Internet Systems Consortium (ISC) has disclosed three critical vulnerabilities in BIND 9, the most widely deployed DNS software globally….

How Lazarus Group used fake job ads to spy on Europe's drone and defense sector
23
Oct
2025

How Lazarus Group used fake job ads to spy on Europe’s drone and defense sector

ESET researchers have uncovered a fresh wave of Operation DreamJob, a long-running campaign linked to North Korea’s Lazarus Group. This…

Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms
23
Oct
2025

Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms

Oct 23, 2025Ravie LakshmananVulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical…

Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial Of Service Attacks
23
Oct
2025

Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial Of Service Attacks

The Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9 on October 22, 2025, potentially allowing remote attackers…

PhantomCaptcha RAT Uses Weaponized PDFs and “ClickFix” Cloudflare CAPTCHA Pages to Deliver Malware
23
Oct
2025

PhantomCaptcha RAT Uses Weaponized PDFs and “ClickFix” Cloudflare CAPTCHA Pages to Deliver Malware

A sophisticated spearphishing campaign has targeted humanitarian organizations working on Ukrainian war relief efforts, employing weaponized PDFs and fake Cloudflare…

Faster LLM tool routing comes with new security considerations
23
Oct
2025

Faster LLM tool routing comes with new security considerations

Large language models depend on outside tools to perform real-world tasks, but connecting them to those tools often slows them…

Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw
23
Oct
2025

Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw

Oct 23, 2025Ravie LakshmananData Breach / Vulnerability E-commerce security company Sansec has warned that threat actors have begun to exploit…

Optus brings in ex-NBN Co CIO to run technology
23
Oct
2025

Optus brings in ex-NBN Co CIO to run technology

Optus’ chief information officer of four years Mark Potter is set to leave the telco in March of next year,…

Intigriti partners with Shield to empower security within healthcare
23
Oct
2025

Intigriti partners with Shield to empower security within healthcare

Antwerp, Belgium, Oct. 23, 2025.  Intigriti, a global crowdsourced security provider, is delighted to announce its latest partnership with non-profit Shield…

Critical MCP Server Flaw Exposes Over 3,000 Servers and Thousands of API Keys
23
Oct
2025

Critical MCP Server Flaw Exposes Over 3,000 Servers and Thousands of API Keys

A critical vulnerability in Smithery.ai, a popular Model Context Protocol (MCP) server hosting service, exposed over 3,000 AI servers and…

Your wearable knows your heartbeat, but who else does?
23
Oct
2025

Your wearable knows your heartbeat, but who else does?

Smartwatches, glucose sensors, and connected drug-monitoring devices are common in care programs. Remote monitoring helps detect changes early and supports…