English-Speaking Cybercriminal Ecosystem 'The COM' Drives a Wide Spectrum of Cyberattacks
13
Nov
2025

English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks

The English-speaking cybercriminal ecosystem, commonly known as “The COM,” has transformed from a niche community of social media account traders…

Authorities Takedown 1,025 Servers Linked to Rhadamanthys, VenomRAT, and Elysium
13
Nov
2025

Authorities Takedown 1,025 Servers Linked to Rhadamanthys, VenomRAT, and Elysium

Between November 10 and 14, 2025, law enforcement agencies executed one of the most significant coordinated operations against cybercriminals in…

A computer from the 1990s
13
Nov
2025

We opened a fake invoice and fell down a retro XWorm-shaped wormhole

Somebody forwarded an “invoice” email and asked me to check the attachment because it looked suspicious. Good instinct—it was, and…

WatchGuard
13
Nov
2025

CISA warns of WatchGuard firewall flaw exploited in attacks

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has warned government agencies to patch an actively exploited vulnerability impacting WatchGuard…

New ClickFix Attack Tricks Users with 'Fake OS Update' to Execute Malicious Commands
13
Nov
2025

New ClickFix Attack Tricks Users with ‘Fake OS Update’ to Execute Malicious Commands

A new ClickFix campaign is tricking users with a fake Windows update that runs in their browser. Called “Fake OS…

Kibana Vulnerabilities Expose Systems to SSRF and XSS Attacks
13
Nov
2025

Kibana Vulnerabilities Expose Systems to SSRF and XSS Attacks

Elastic has released a security advisory addressing an origin validation error in Kibana that could expose systems to Server-Side Request Forgery (SSRF)…

Post Office contract with Fujitsu has option to extend into 2028
13
Nov
2025

Post Office contract with Fujitsu has option to extend into 2028

The Post Office’s contract with Fujitsu for the supplier’s Horizon system has a built-in option to continue into 2028. The…

advanced threat actor exploits Cisco ISE & Citrix NetScaler zero-days
13
Nov
2025

advanced threat actor exploits Cisco ISE & Citrix NetScaler zero-days

Amazon alerts: advanced threat actor exploits Cisco ISE & Citrix NetScaler zero-days Pierluigi Paganini November 13, 2025 Amazon warns that…

Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges
13
Nov
2025

Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges

Dell Technologies has disclosed a critical security vulnerability in its Data Lakehouse platform that could allow remote attackers to escalate…

Malicious Chrome Extension Grants Full Control Over Ethereum Wallet
13
Nov
2025

Malicious Chrome Extension Grants Full Control Over Ethereum Wallet

Security researchers have uncovered a sophisticated supply chain attack disguised as a legitimate cryptocurrency wallet. Socket’s Threat Research Team discovered…

43K Malicious Npm Packages Exposed
13
Nov
2025

43K Malicious Npm Packages Exposed

Security researchers have uncovered a large-scale spam campaign within the npm ecosystem, now known as the IndonesianFoods worm. The attack…

CISA Warns WatchGuard Firebox Out-of-Bounds Write Vulnerability Exploited Attacks
13
Nov
2025

CISA Warns WatchGuard Firebox Out-of-Bounds Write Vulnerability Exploited Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has released a warning about a serious vulnerability affecting WatchGuard Firebox security appliances….