In a sophisticated cyber espionage campaign, North Korean state-sponsored hackers have been targeting European defense companies, particularly those involved in unmanned aerial vehicle (UAV) technology. […]
Year: 2025
ThreatsDay Bulletin: $176M Crypto Fine, Formula 1 Hacking, Chromium Vulnerabilities, AI Hijacking, and More
Cybercriminals often exploit the path of least resistance, targeting users through deceptive tactics, outdated software components, and trusted systems like OAuth and package registries. This […]
Hackers Exploit OAuth Applications to Maintain Persistent Cloud Access Despite Password Resets
In recent developments, cybercriminals and state-sponsored entities have refined their tactics to exploit OAuth applications, securing enduring access to compromised cloud environments. This method allows […]
Critical BIND 9 Vulnerabilities Expose DNS Infrastructure to Cache Poisoning and Denial-of-Service Attacks
On October 22, 2025, the Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9, the widely used Domain Name System (DNS) software. These […]
Critical Vulnerabilities in Oracle VM VirtualBox Pose Significant Security Risks
Oracle has recently disclosed multiple critical vulnerabilities in its Oracle VM VirtualBox virtualization software, potentially allowing attackers to achieve complete control over the VirtualBox environment. […]
Critical ‘TARmageddon’ Vulnerability in Rust Libraries Enables Remote Code Execution
A significant security flaw, known as TARmageddon and designated as CVE-2025-62518, has been identified in the Rust programming language’s async-tar library and its derivatives, notably […]
Impacket Tool in Kali Linux Receives Major Upgrade with Enhanced Attack Paths and Relay Techniques
The Impacket toolkit, a cornerstone in penetration testing, has undergone a significant upgrade within the Kali Linux repository. Managed by Fortra’s cybersecurity team, this latest […]
Critical Path Traversal Vulnerability in Jira Software Allows Arbitrary File Modification
Atlassian has recently identified a significant security flaw in its Jira Software Data Center and Server platforms. This vulnerability, cataloged as CVE-2025-22167, is a path […]
Critical Vulnerability in Motex LANSCOPE Endpoint Manager Exploited in Active Cyberattacks
A critical security flaw has been identified in Motex LANSCOPE Endpoint Manager, a widely used tool for managing IT assets across networks. This vulnerability, designated […]
Critical ‘SessionReaper’ Vulnerability in Adobe Magento Actively Exploited, Majority of Stores at Risk
A critical security flaw, identified as CVE-2025-54236 and dubbed SessionReaper, has been discovered in Adobe’s Magento e-commerce platform. This vulnerability allows unauthenticated attackers to hijack […]