China’s spy agency accuses NSA of yearslong attack on the country’s timekeeping service
20
Oct
2025

China’s spy agency accuses NSA of yearslong attack on the country’s timekeeping service

China’s Ministry of State Security accused the National Security Agency of conducting a yearslong attack on China’s national timekeeping infrastructure…

Windows
20
Oct
2025

High-severity Windows SMB flaw now exploited in attacks

CISA says threat actors are now actively exploiting a high-severity Windows SMB privilege escalation vulnerability that can let them gain…

Winos 4.0 Malware Uses Weaponized PDFs Posing as Government Departments to Infect Windows Machines
20
Oct
2025

Winos 4.0 Malware Uses Weaponized PDFs Posing as Government Departments to Infect Windows Machines

Security researchers are tracking a high-severity malware campaign that uses weaponized PDF files to distribute the Winos 4.0 malware. The…

An illustrated padlock is mounted into a microphone stand with sound waves emitting from the device.
20
Oct
2025

What does Google know about me? (Lock and Code S06E21)

This week on the Lock and Code podcast… Google is everywhere in our lives. It’s reach into our data extends…

Self-spreading GlassWorm malware hits OpenVSX,  VS Code registries
20
Oct
2025

Self-spreading GlassWorm malware hits OpenVSX, VS Code registries

A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware…

Hard-coded credentials found in Moxa industrial security appliances, routers (CVE-2025-6950)
20
Oct
2025

Hard-coded credentials found in Moxa industrial security appliances, routers (CVE-2025-6950)

Moxa has fixed 5 vulnerabilities in its industrial network security appliances and routers, including a remotely exploitable flaw (CVE-2025-6950) that…

US still prioritizing zero-trust migration to limit hacks’ damage
20
Oct
2025

Top cybersecurity conferences to attend in 2026

2026 is almost upon us, and with it comes a slate of must-attend cybersecurity conferences. Security experts from across sectors…

Judge forbids NSO Group from targeting WhatsApp users
20
Oct
2025

Judge forbids NSO Group from targeting WhatsApp users

WhatsApp has won a ruling against spyware maker NSO Group forbidding it from targeting its users, while NSO Group in…

Windows Server
20
Oct
2025

Microsoft fixes Windows Server Active Directory sync issues

Microsoft is rolling out a fix for Active Directory issues affecting some Windows Server 2025 systems after installing security updates…

Major AWS outage disrupts apps and services worldwide
20
Oct
2025

Major AWS outage disrupts apps and services worldwide

Network connectivity issues in AWS’ US-EAST-1 facility have caused widespread outages affecting thousands of websites along with some of the…

Reflected XSS: Advanced Exploitation Guide
20
Oct
2025

Reflected XSS: Advanced Exploitation Guide

Cross-site scripting vulnerabilities are, by no doubt, one of the vulnerability types that’ll keep haunting applications for a long time….

Why security awareness training doesn’t work — and how to fix it
20
Oct
2025

Why security awareness training doesn’t work — and how to fix it

Listen to the article 13 min This audio is auto-generated. Please let us know if you have feedback. Government agencies,…