GitHub boosts NPM security
09
Oct
2025

GitHub Copilot Chat Flaw Leaked Data From Private Repositories

Legit Security has detailed a vulnerability in the GitHub Copilot Chat AI assistant that led to sensitive data leakage and…

API Attack Awareness: Injection Attacks in APIs
09
Oct
2025

API Attack Awareness: Injection Attacks in APIs

Injection attacks are among the oldest tricks in the attacker playbook. And yet they persist. The problem is that the…

Microsoft Events Vulnerability Exposes Users Personal Data From Registration And Waitlist Databases
09
Oct
2025

Microsoft Events Vulnerability Exposes Users Personal Data From Registration And Waitlist Databases

A significant security flaw has been discovered within the Microsoft Events platform, which could have allowed attackers to access the…

PoC Released for Linux Kernel ksmbd Filesystem Vulnerability
09
Oct
2025

PoC Released for Linux Kernel ksmbd Filesystem Vulnerability

Security researcher Norbert Szetei published the final installment of his deep-dive into the ksmbd filesystem module, culminating in a working…

Ready1 for Identity Crisis Management restores operations after identity breaches
09
Oct
2025

Ready1 for Identity Crisis Management restores operations after identity breaches

Semperis released Ready1 for Identity Crisis Management, which combines its Active Directory Forest Recovery (ADFR), Disaster Recovery for Entra Tenant…

SonicWall dismisses zero-day fears after Ransomware probe
09
Oct
2025

Threat actors steal firewall configs, impacting all SonicWall Cloud Backup users

Threat actors steal firewall configs, impacting all SonicWall Cloud Backup users Pierluigi Paganini October 09, 2025 All SonicWall Cloud Backup…

Shuyal Stealer Attacking 19 Browsers to Steal Login Credentials
09
Oct
2025

Shuyal Stealer Attacking 19 Browsers to Steal Login Credentials

Shuyal Stealer has rapidly ascended as one of the most versatile credential theft tools observed in recent months. First detected…

Hackers Targeting WordPress Plugin Vulnerability to Seize Admin Access
09
Oct
2025

Hackers Targeting WordPress Plugin Vulnerability to Seize Admin Access

A critical authentication bypass in the Service Finder Bookings plugin has enabled unauthenticated attackers to assume administrator privileges on thousands…

Fake Teams Installers Dropping Oyster Backdoor (aka Broomstick)
09
Oct
2025

Fake Teams Installers Dropping Oyster Backdoor (aka Broomstick)

A major new threat is targeting everyday computer users by hiding a dangerous program inside what looks like a genuine…

Ootbi Mini delivers zero trust, immutable data protection
09
Oct
2025

Ootbi Mini delivers zero trust, immutable data protection

Object First unveiled Ootbi Mini, a new compact immutable storage appliance designed for remote and branch offices, edge environments, and…

AI Becomes Russia's New Cyber Weapon in War on Ukraine
09
Oct
2025

AI Becomes Russia’s New Cyber Weapon in War on Ukraine

Oct 09, 2025Ravie LakshmananArtificial Intelligence / Malware Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has…

Chinese hackers target law firms
09
Oct
2025

Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day

Law firm Williams & Connolly said state-sponsored hackers breached some of its systems and gained access to attorney email accounts….