In a recent and sophisticated supply chain attack, cybercriminals have targeted cryptocurrency developers by introducing malicious Rust crates into the ecosystem. These fraudulent packages, named […]
Month: September 2025
Critical Cisco Vulnerability Allows Remote Code Execution on Firewalls and Routers
Cisco has recently identified a critical security vulnerability, designated as CVE-2025-20363, affecting multiple platforms, including Adaptive Security Appliance (ASA), Firepower Threat Defense (FTD), IOS, IOS […]
Active Directory Breach: Exfiltration of NTDS.dit Leads to Full Domain Compromise
Active Directory (AD) serves as the cornerstone for authentication and authorization within Windows environments. Its central database, NTDS.dit, contains critical information, including user credentials and […]
Chinese State-Sponsored Hackers Target Global Telecommunications Infrastructure to Harvest Sensitive Data
In late 2024, a sophisticated cyber espionage campaign emerged, targeting telecommunications infrastructure worldwide. The group behind these operations, identified as Salt Typhoon, is believed to […]
CISA Issues Emergency Directive to Mitigate Active Exploitation of Cisco Firewall Zero-Day Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Emergency Directive in response to the active exploitation of two critical zero-day vulnerabilities—CVE-2025-20333 and CVE-2025-20362—affecting […]
First Malicious MCP Server Discovered: AI Agents Exploited to Steal Emails
In a significant cybersecurity development, researchers have identified the first-known malicious Model-Context-Prompt (MCP) server actively exploiting AI agents to exfiltrate sensitive email data. The compromised […]
Critical Zero-Day Vulnerability in Fortra’s GoAnywhere MFT Exploited Prior to Patch Release
A critical vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution, identified as CVE-2025-10035, has been actively exploited as a zero-day at least a week […]
Emerging XCSSET Malware Variant Targets macOS Developers with Advanced Techniques
In September 2025, cybersecurity researchers identified a new variant of the XCSSET malware, marking a significant evolution in threats targeting macOS developers. This sophisticated malware […]
GitLab Releases Critical Security Patches to Address High-Severity Vulnerabilities
GitLab, a leading DevOps platform, has recently issued critical security updates for its Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. […]
North Dakota to Introduce Digital Driver’s Licenses in Apple Wallet
North Dakota is set to become the latest state to integrate digital driver’s licenses and state IDs into Apple Wallet, allowing residents to store and […]