Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely
21
Oct
2025

Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely

Microsoft has disclosed a serious security flaw in ASP.NET Core that enables authenticated attackers to smuggle HTTP requests and evade…

CISA Warns of Actively Exploited Windows SMB Vulnerability
21
Oct
2025

CISA Warns of Actively Exploited Windows SMB Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows Server Message Block (SMB) vulnerability to its…

Snappybee Malware and Citrix Flaw
21
Oct
2025

Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network

Oct 21, 2025Ravie LakshmananCyber Espionage / Network Security A European telecommunications organization is said to have been targeted by a…

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration
21
Oct
2025

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

A critical vulnerability in Zyxel’s ATP and USG series firewalls that allows attackers to bypass authorization controls and access sensitive…

Cavalry Werewolf APT Targets Multiple Sectors Using FoalShell and StallionRAT
21
Oct
2025

Cavalry Werewolf APT Targets Multiple Sectors Using FoalShell and StallionRAT

From May to August 2025, an advanced persistent threat group known as Cavalry Werewolf—also tracked as YoroTrooper and Silent Lynx—executed…

Cybersecurity jobs available right now: October 21, 2025
21
Oct
2025

Cybersecurity jobs available right now: October 21, 2025

CISO Open-Xchange | Germany | Remote – View job details As a CISO, you will lead the development and implementation…

Home Depot logo
21
Oct
2025

Home Depot Halloween phish gives users a fright, not a freebie

We received a timely phishing email pretending to come from Home Depot. It claimed we’d won a Gorilla Carts dump…

Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
21
Oct
2025

Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers

Oct 21, 2025Ravie LakshmananCyber Espionage / Threat Intelligence A new malware attributed to the Russia-linked hacking group known as COLDRIVER…

AdaptixC2 Emerges in npm Supply-Chain Exploit Against Developers
21
Oct
2025

AdaptixC2 Emerges in npm Supply-Chain Exploit Against Developers

Cybersecurity researchers at Kaspersky have uncovered a sophisticated supply chain attack targeting the npm ecosystem, where threat actors distributed the…

Agentic AI security: Building the next generation of access controls
21
Oct
2025

Agentic AI security: Building the next generation of access controls

As artificial intelligence (AI) solutions continue to evolve, the rise of agentic AI—intelligent systems that can act autonomously on behalf…

CISA Warns of Oracle E-Business Suite SSRF Vulnerability Actively Exploited in Attacks
21
Oct
2025

CISA Warns of Oracle E-Business Suite SSRF Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle E-Business Suite vulnerability to its Known Exploited Vulnerabilities…

When everything's connected, everything's at risk
21
Oct
2025

When everything’s connected, everything’s at risk

In this Help Net Security interview, Ken Deitz, CISO at Brown & Brown, discusses how the definition of cyber risk…