Krispy Kreme
19
Jun
2025

Krispy Kreme says November data breach impacts over 160,000 people

U.S. doughnut chain Krispy Kreme confirmed that attackers stole the personal information of over 160,000 individuals in a November 2024…

Hackers Leverage VBScript Files to Deploy Masslogger Credential Stealer Malware
19
Jun
2025

Hackers Leverage VBScript Files to Deploy Masslogger Credential Stealer Malware

A sophisticated new variant of the Masslogger credential stealer has emerged, utilizing VBScript encoded (.VBE) files to deploy a multi-stage…

Hackers Exploit Cloudflare Tunnels to Infect Windows Systems With Python Malware
19
Jun
2025

Hackers Exploit Cloudflare Tunnels to Infect Windows Systems With Python Malware

A sophisticated malware campaign dubbed SERPENTINE#CLOUD has emerged, leveraging Cloudflare Tunnel infrastructure to deliver Python-based malware to Windows systems across…

Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack
19
Jun
2025

Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack

A critical security vulnerability affecting Cisco Meraki MX and Z Series devices could allow unauthenticated attackers to launch denial of…

Microsoft Entra ID Adds Passkey (FIDO2) Support in Public Preview
19
Jun
2025

Microsoft Entra ID Adds Passkey (FIDO2) Support in Public Preview

Microsoft has announced a significant update to its identity platform, Microsoft Entra ID, with the introduction of expanded passkey (FIDO2)…

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
19
Jun
2025

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Jun 19, 2025Ravie LakshmananEmail Security / Identity Protection Threat actors with suspected ties to Russia have been observed taking advantage…

Five Uncomfortable Truths About LLMs in Production — API Security
19
Jun
2025

Five Uncomfortable Truths About LLMs in Production — API Security

Many tech professionals see integrating large language models (LLMs) as a simple process -just connect an API and let it…

Password Reset Poisoning Attack Allows Account Takeover Using the Password Reset Link
19
Jun
2025

Password Reset Poisoning Attack Allows Account Takeover Using the Password Reset Link

A critical vulnerability in password reset mechanisms has been discovered that allows attackers to completely take over user accounts by…

LogMeIn Remote Access Abused in Targeted System Compromise
19
Jun
2025

LogMeIn Remote Access Abused in Targeted System Compromise

A sophisticated cyberattack campaign has been uncovered, leveraging LogMeIn Resolve remote access software to gain unauthorized control over user systems….

Golden SAML Attack Let Attackers Gains Control of The Private Keyused by Federation Server
19
Jun
2025

Golden SAML Attack Let Attackers Gains Control of The Private Keyused by Federation Server

Cybersecurity professionals are facing a sophisticated new threat as Golden SAML attacks emerge as one of the most dangerous yet…

Cisco AnyConnect VPN Flaw Allows Attackers to Launch DoS Attacks
19
Jun
2025

Cisco AnyConnect VPN Flaw Allows Attackers to Launch DoS Attacks

A newly disclosed vulnerability in Cisco’s AnyConnect VPN implementation for Meraki MX and Z Series devices poses a significant risk…

CVE-2025-5349
19
Jun
2025

Critical Flaws In NetScaler ADC & Gateway – CVE-2025-5349

Cloud Software Group has released a security bulletin warning customers of two newly identified vulnerabilities, CVE-2025-5349 and CVE-2025-5777, affecting both…