Russian Hackers Exploiting 7-Year-Old Cisco Vulnerability to Collect Configs from Industrial Systems
21
Aug
2025

Russian Hackers Exploiting 7-Year-Old Cisco Vulnerability to Collect Configs from Industrial Systems

A Russian state-sponsored cyber espionage group designated as Static Tundra has been actively exploiting a seven-year-old vulnerability in Cisco networking…

CISA Issues Four ICS Advisories on Vulnerabilities and Exploits
21
Aug
2025

CISA Issues Four ICS Advisories on Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) released four critical Industrial Control Systems (ICS) advisories on August 19, 2025, alerting…

Doppel Simulation combats social engineering attacks
21
Aug
2025

Doppel Simulation combats social engineering attacks

Doppel announced Doppel Simulation, a new product and expansion to the Doppel Vision Platform that enables organizations to redefine security…

DOM‑based Extension Clickjacking Threatens User Data
21
Aug
2025

DOM‑based Extension Clickjacking Threatens User Data

A newly discovered technique, dubbed DOM-based extension clickjacking, has raised serious concerns about the security of browser-based password managers. Despite…

University of Melbourne reprimanded for using wi-fi data to identify protesters
21
Aug
2025

University of Melbourne reprimanded for using wi-fi data to identify protesters

The University of Melbourne has been reprimanded for using wi-fi location data to identify students involved in a sit-in protest…

Critical Apache Tika PDF Parser Vulnerability Allow Attackers to Access Sensitive Data
21
Aug
2025

Critical Apache Tika PDF Parser Vulnerability Allow Attackers to Access Sensitive Data

A critical security vulnerability has been discovered in Apache Tika’s PDF parser module that could enable attackers to access sensitive…

Apple Confirms Critical 0-Day Under Active Attack – Immediate Update Urged
21
Aug
2025

Apple Confirms Critical 0-Day Under Active Attack – Immediate Update Urged

Apple has issued an emergency security update for iOS 18.6.2 and iPadOS 18.6.2 to address a critical zero-day vulnerability that…

Using lightweight LLMs to cut incident response times and reduce hallucinations
21
Aug
2025

Using lightweight LLMs to cut incident response times and reduce hallucinations

Researchers from the University of Melbourne and Imperial College London have developed a method for using LLMs to improve incident…

CBA keeps pushing limits of its Workday environment
21
Aug
2025

CBA keeps pushing limits of its Workday environment

CBA has 20 apps in production that run off its now decade-old Workday system for human resources, part of a…

Google Announces New Capabilities for Enabling Defenders and Securing AI Innovation
21
Aug
2025

Google Announces New Capabilities for Enabling Defenders and Securing AI Innovation

Google Cloud has unveiled a comprehensive suite of security enhancements at its Security Summit 2025, marking a significant evolution in…

Critical Flaw in Apache Tika PDF Parser Exposes Sensitive Data to Attackers
21
Aug
2025

Critical Flaw in Apache Tika PDF Parser Exposes Sensitive Data to Attackers

A critical XML External Entity (XXE) vulnerability has been discovered in Apache Tika’s PDF parser module, potentially allowing attackers to…

Fractional vs. full-time CISO: Finding the right fit for your company
21
Aug
2025

Fractional vs. full-time CISO: Finding the right fit for your company

In this Help Net Security interview, Nikoloz Kokhreidze, Fractional CISO at Mandos, discusses why many early- and growth-stage B2B companies…