ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach
22
Nov
2025

ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration…

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
22
Nov
2025

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability

Nov 22, 2025Ravie LakshmananZero-Day / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical…

Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks
22
Nov
2025

Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks

Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a…

Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities
22
Nov
2025

Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This…

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination
22
Nov
2025

Fired Techie Admits Hacking Employer’s Network in Retaliation for Termination

A former IT contractor from Ohio has admitted to launching a cyberattack against his employer’s network in retaliation for being…

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers
22
Nov
2025

CrowdStrike Fires Insider for Sharing Internal System Details with Hackers

Cybersecurity giant CrowdStrike has confirmed the termination of an insider who allegedly provided sensitive internal system details to a notorious…

Oracle
22
Nov
2025

CISA warns Oracle Identity Manager RCE flaw is being actively exploited

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757…

Judge AI by Outputs, not Mechanism
22
Nov
2025

Judge AI by Outputs, not Mechanism

This song captures extraordinarily well why arguments about AI understanding are completely misguided and empty. This is a blues version…

Startup firm called Factory disrupts campaign designed to hijack development platform
22
Nov
2025

Startup firm called Factory disrupts campaign designed to hijack development platform

Factory, a San Francisco-based startup, said it disrupted an attack by at least one state-linked threat group that attempted to…

CrowdStrike denies breach after insider sent internal screenshots to hackers
22
Nov
2025

CrowdStrike denies breach after insider sent internal screenshots to hackers

CrowdStrike denies breach after insider sent internal screenshots to hackers Pierluigi Paganini November 21, 2025 CrowdStrike says an insider shared…

Operation DreamJob Attacking Manufacturing Industries Using Job-related WhatsApp Web Message
22
Nov
2025

Operation DreamJob Attacking Manufacturing Industries Using Job-related WhatsApp Web Message

In August 2025, a sophisticated cyber attack targeted an Asian subsidiary of a large European manufacturing organization through a deceptive…

Clop Ransomware Claims Broadcom Breach Through E-Business Suite 0-Day
22
Nov
2025

Clop Ransomware Claims Broadcom Breach Through E-Business Suite 0-Day

The notorious Cl0p ransomware gang has publicly claimed responsibility for breaching Broadcom, a leading semiconductor and infrastructure software company. According…