Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App.
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation.
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks.
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances.
Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports.
CISA has added 3 vulnerabilities to the KEV Catalog
CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability
CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability
CVE-2025-20393: Cisco Multiple Products Improper Input Validation Vulnerability
CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability
CVE-2025-40602: SonicWall SMA1000 Missing Authorization Vulnerability
CVE-2025-20393: Cisco Multiple Products Improper Input Validation Vulnerability
ESET has identified a China-aligned cyber espionage group, LongNosedGoblin, active since 2023 and targeting government networks in Southeast Asia and Japan.
It spreads malware via Windows Group Policy and uses OneDrive and Google Drive as C2, with full backdoors deployed only on select targets.
It spreads malware via Windows Group Policy and uses OneDrive and Google Drive as C2, with full backdoors deployed only on select targets.
HPE patched a CRITICAL CVSS 10.0 flaw in OneView that allows unauthenticated remote code execution.
All versions before 11.00 are affected, with hotfixes for 5.20–10.20.
No active exploits reported, but patching is urgent.
All versions before 11.00 are affected, with hotfixes for 5.20–10.20.
No active exploits reported, but patching is urgent.