Topic: vulnerability patching
-
CISA Urges iOS Patch to Stop Crypto-Theft Exploits
U.S. authorities have issued an urgent alert for iPhone users to update their devices, as federal agencies are mandated to patch three actively exploited iOS vulnerabilities used for cryptocurrency theft and espionage. The sophisticated Coruna exploit kit leverages multiple iOS weaknesses to bypa...
Read More » -
Apple’s Newest Bug Detective: AI
Apple's latest 26.5.2 software update patches a record number of vulnerabilities, many discovered using AI-assisted tools. The update fixes 87 security flaws in iOS and iPadOS 26.6, 155 in Macs, and roughly 100 each in watchOS, tvOS, and visionOS. The surge in fixes is driven by AI coding agents ...
Read More » -
Hackers Breach Federal Agency via GeoServer Flaw, CISA Warns
A critical vulnerability (CVE-2024-36401) in GeoServer was exploited to breach a U.S. federal agency's network after attackers compromised an unpatched server. The attackers moved laterally from the initial entry point, deploying malicious tools like China Chopper and using brute force attacks to...
Read More » -
Feds Probe Mysterious iOS Vulnerabilities Under Attack
Federal agencies are mandated to patch three critical, actively exploited iOS vulnerabilities, with CISA urging all organizations to apply updates immediately to protect against confirmed threats. The attacks utilized the sophisticated Coruna toolkit, which bundled 23 iOS exploits into effective ...
Read More » -
Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)
The Interlock ransomware gang exploited a critical zero-day vulnerability (CVE-2026-20131) in Cisco's Secure Firewall Management Center for over a month before a patch was released, using it for arbitrary code execution and privilege escalation. Amazon's threat intelligence, using a honeypot, unc...
Read More » -
Top Open-Source Cybersecurity Tools for August 2025
Open-source cybersecurity tools are rapidly advancing, offering cost-effective solutions for vulnerability management, identity security, and penetration testing. Notable tools include Buttercup for AI-driven vulnerability patching, EntraGoat for safe identity management training, and LudusHound ...
Read More » -
Microsoft unveils AI security tools that beat rival platforms
Microsoft launched new AI-powered security tools, including the MAI-Cyber-1-Flash model, to automate risk detection and vulnerability remediation at scale, drawing on its experience from processing over 1 trillion security signals daily. The announcement comes shortly after OpenAI lost control of...
Read More » -
Russian Hackers Exploit Patched Microsoft Office Flaw
A Russian state-sponsored hacking group is actively exploiting a patched Microsoft Office vulnerability (CVE-2026-21509) through phishing campaigns to install backdoors on targeted systems. The attacks use two methods: one deploys a malicious VBA project to steal emails, while the other uses a mu...
Read More » -
Exploit Alert: Critical Adobe Experience Manager Flaw (CVE-2025-54253)
A critical security flaw (CVE-2025-54253) in Adobe Experience Manager Forms allows unauthenticated attackers to execute remote code, prompting CISA to flag it due to active exploitation. The vulnerability arises from Apache Struts "devMode" being enabled in the administrative interface combined w...
Read More » -
Google discovers first AI-crafted zero-day exploit, thwarts attack pre-launch
Google's Threat Intelligence Group discovered what is believed to be the first zero-day exploit created by AI, designed for a mass attack but neutralized before deployment through collaboration with the software vendor. This event marks a significant escalation in the cybersecurity arms race, as ...
Read More » -
CISA Retires 10 Emergency Cyber Directives in Bulk Move
CISA has retired ten Emergency Directives, as their required security measures are now fully implemented or superseded by the broader Binding Operational Directive 22-01. BOD 22-01 mandates federal agencies to patch vulnerabilities from CISA's Known Exploited Vulnerabilities catalog, with deadlin...
Read More » -
DoorDash Email Spoofing Sparks Heated Security Disclosure Feud
A security flaw in DoorDash's corporate platform allowed unauthorized users to send authentic-looking phishing emails from the company's official address, bypassing spam filters. The vulnerability was discovered by a researcher who demonstrated how to inject malicious HTML into emails, but DoorDa...
Read More » -
Microsoft GoAnywhere Flaw Fuels Ransomware Attacks
A critical vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT platform is being exploited by ransomware attackers, allowing remote access without user interaction. The cybercrime group Storm-1175, linked to Medusa ransomware, is actively using this flaw to gain initial access, deploy remot...
Read More » -
GlobalLogic Hit by Cl0p Ransomware Following Oracle EBS Breach
GlobalLogic, a Hitachi-owned software firm, notified 10,471 current and former employees that their personal and financial data was stolen due to a breach in its Oracle E-Business Suite platform. The breach exploited a zero-day vulnerability in Oracle's system, leading to data exfiltration on Oct...
Read More » -
New Gladinet Triofox Flaw Exploited by Attackers (CVE-2025-12480)
A critical security flaw (CVE-2025-12480) in Gladinet Triofox allows unauthenticated attackers to bypass access controls and gain administrative privileges, which has been exploited by the threat group UNC6485 since late August 2025. Attackers used an HTTP Host header attack to access the configu...
Read More » -
ChatGPT Agent Aided Gmail Security Breach by Researchers
A new attack called Shadow Leak exploited AI agents to access sensitive Gmail data without triggering alerts, highlighting vulnerabilities in AI systems with data permissions. The breach used prompt injection to manipulate OpenAI's Deep Research tool into extracting confidential emails, bypassing...
Read More » -
0-day researcher threatens 'bone shattering drop' after Microsoft calls police
A disgruntled security researcher known as Nightmare Eclipse has released six Windows zero-days, three of which are already being actively exploited, and has threatened a major disclosure event on July 14. Microsoft’s blog post condemned the uncoordinated disclosures and included a legal warning ...
Read More » -
NCSC Warns of Severe Cyber-Attacks on Critical Infrastructure
The UK's National Cyber Security Centre (NCSC) has issued an urgent warning to critical national infrastructure providers, citing severe and disruptive cyber-attacks as a present danger, following incidents like those against energy networks in Poland. These sophisticated threats aim to cause hig...
Read More » -
Firestarter malware evades Cisco firewall updates and patches
U.S. and U.K. cybersecurity authorities warn of the custom-built Firestarter backdoor persisting on Cisco Firepower and Secure Firewall appliances, linked to threat actor UAT-4356, which exploited vulnerabilities CVE-2025-20333 and CVE-2025-20362 for initial access. The malware survives reboots, ...
Read More » -
Logitech Data Breach Exposes User Information
Logitech experienced a data breach due to a zero-day vulnerability in third-party software, leading to unauthorized data copying, but the company promptly patched the issue after a fix was released. The stolen data includes information on employees, consumers, customers, and suppliers, but sensit...
Read More »