βTaiwan Warns Public: Popular Chinese Apps (TikTok, WeChat, Rednote) Pose National Security Risk Via Data Transfer to China
https://securityonline.info/taiwan-warns-public-popular-chinese-apps-tiktok-wechat-rednote-pose-national-security-risk-via-data-transfer-to-china/
https://securityonline.info/taiwan-warns-public-popular-chinese-apps-tiktok-wechat-rednote-pose-national-security-risk-via-data-transfer-to-china/
Daily CyberSecurity
Taiwan Warns Public: Popular Chinese Apps (TikTok, WeChat, Rednote) Pose National Security Risk Via Data Transfer to China
Taiwan's National Security Bureau warns against Chinese apps like TikTok, WeChat, and Rednote, citing excessive data collection and transfer to China as national security risks.
βAPT36 Unleashes Linux Malware: Transparent Tribe Targets Indian Government with Go-Based Espionage Tools
https://securityonline.info/apt36-unleashes-linux-malware-transparent-tribe-targets-indian-government-with-go-based-espionage-tools/
https://securityonline.info/apt36-unleashes-linux-malware-transparent-tribe-targets-indian-government-with-go-based-espionage-tools/
Daily CyberSecurity
APT36 Unleashes Linux Malware: Transparent Tribe Targets Indian Government with Go-Based Espionage Tools
APT36 (Transparent Tribe) is now targeting Indian government agencies via BOSS Linux with spear-phishing. It uses malicious .desktop files to deploy Go-based malware for espionage.
βState Secrets for Sale: Chinaβs βHack-for-Hireβ Ecosystem Exposed in Massive VenusTech & Salt Typhoon Leaks
https://securityonline.info/state-secrets-for-sale-chinas-hack-for-hire-ecosystem-exposed-in-massive-venustech-salt-typhoon-leaks/
https://securityonline.info/state-secrets-for-sale-chinas-hack-for-hire-ecosystem-exposed-in-massive-venustech-salt-typhoon-leaks/
Daily CyberSecurity
State Secrets for Sale: China's "Hack-for-Hire" Ecosystem Exposed in Massive VenusTech & Salt Typhoon Leaks
SpyCloud Labs exposes VenusTech & Salt Typhoon data leaks on DarkForums, revealing contract details for Chinese hack-for-hire operations against foreign targets, including military links.
βHpingbot: New Go-Based Botnet Leverages Pastebin & Hping3 for Stealthy Attacks
https://securityonline.info/hpingbot-new-go-based-botnet-leverages-pastebin-hping3-for-stealthy-attacks/
https://securityonline.info/hpingbot-new-go-based-botnet-leverages-pastebin-hping3-for-stealthy-attacks/
Daily CyberSecurity
Hpingbot: New Go-Based Botnet Leverages Pastebin & Hping3 for Stealthy Attacks
NSFOCUS uncovers Hpingbot, a rapidly evolving Go-based botnet using Pastebin for payloads and hping3 for DDoS. It targets Windows/Linux/IoT, focusing on stealth and persistence.
βScriptCase Flaws (CVE-2025-47227/47228): Pre-Auth RCE & Admin Takeover Risk for Web Servers, PoC Published
https://securityonline.info/scriptcase-flaws-cve-2025-47227-47228-pre-auth-rce-admin-takeover-risk-for-web-servers-poc-published/
https://securityonline.info/scriptcase-flaws-cve-2025-47227-47228-pre-auth-rce-admin-takeover-risk-for-web-servers-poc-published/
Daily CyberSecurity
ScriptCase Flaws (CVE-2025-47227/47228): Pre-Auth RCE & Admin Takeover Risk for Web Servers, PoC Published
Synacktiv unveils chained flaws in ScriptCase's prod console (CVE-2025-47227/47228) allowing pre-authenticated RCE via password reset & shell injection, risking web servers.
βAppleβs Huge H2 2025 Lineup: iPhone 17 Air, Apple Watch Ultra 3 (5G/Satellite), M5 Macs & More
https://securityonline.info/apples-huge-h2-2025-lineup-iphone-17-air-apple-watch-ultra-3-5g-satellite-m5-macs-more/
https://securityonline.info/apples-huge-h2-2025-lineup-iphone-17-air-apple-watch-ultra-3-5g-satellite-m5-macs-more/
Daily CyberSecurity
Apple's Huge H2 2025 Lineup: iPhone 17 Air, Apple Watch Ultra 3 (5G/Satellite), M5 Macs & More
Apple's H2 2025 roadmap: iPhone 17 series (new Air model), Apple Watch Ultra 3 (5G/satellite), M5 Macs/iPads, and refreshed smart home devices, totaling over 15 new products.
βRedis DoS Flaw (CVE-2025-48367): Authenticated Clients Can Disrupt Service
https://securityonline.info/redis-dos-flaw-cve-2025-48367-authenticated-clients-can-disrupt-service/
https://securityonline.info/redis-dos-flaw-cve-2025-48367-authenticated-clients-can-disrupt-service/
Daily CyberSecurity
Redis DoS Flaw (CVE-2025-48367): Authenticated Clients Can Disrupt Service
Redis discloses CVE-2025-48367 (CVSSv4 7.0), a DoS flaw where authenticated clients can misuse multi-bulk commands. No direct code fix is planned; reinforce access controls.
βRedis Vulnerability Opens Door to Remote Code Execution, PoC Releases
https://securityonline.info/redis-vulnerability-opens-door-to-remote-code-execution-poc-releases/
https://securityonline.info/redis-vulnerability-opens-door-to-remote-code-execution-poc-releases/
Daily CyberSecurity
Redis Vulnerability Opens Door to Remote Code Execution, PoC Releases
A flaw (CVE-2025-48367, CVSS 7.0) in Redis HyperLogLog allows authenticated RCE via out-of-bounds writes. PoC available. Update to 8.0.3, 7.4.5, 7.2.10, or 6.2.19!
βAPT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data
https://cybersecuritynews.com/apt36-attacking-boss-linux-systems/
https://cybersecuritynews.com/apt36-attacking-boss-linux-systems/
Cyber Security News
APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data
Pakistan-based threat actor APT36, also known as Transparent Tribe, has significantly evolved its cyber-espionage capabilities by launching a sophisticated campaign specifically targeting Indian defense personnel through weaponized ZIP files designed to compromiseβ¦
β10 Best Network Security Solutions For Chief Security Officer To Consider β 2025
https://cybersecuritynews.com/network-security-solutions-for-cso/
https://cybersecuritynews.com/network-security-solutions-for-cso/
Cyber Security News
10 Best Network Security Solutions For Chief Security Officer To Consider - 2025
Best Network Security Solutions for CSO :1. Palo Alto Networks 2. Fortinet 3. Perimeter81 4. Check Point Software 5. Juniper Networks
βLinux Boot Vulnerability Lets Attackers Bypass Secure Boot Protections
https://gbhackers.com/linux-boot-vulnerability/
https://gbhackers.com/linux-boot-vulnerability/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Linux Boot Vulnerability Lets Attackers Bypass Secure Boot Protections
A newly highlighted vulnerability in the Linux boot process exposes a critical weakness in the security posture of many modern distributions.
βMicrosoft Edge Continues Aggressive Tactics to Block Chrome Downloads (Outside EU)
https://securityonline.info/microsoft-edge-continues-aggressive-tactics-to-block-chrome-downloads-outside-eu/
https://securityonline.info/microsoft-edge-continues-aggressive-tactics-to-block-chrome-downloads-outside-eu/
Daily CyberSecurity
Microsoft Edge Continues Aggressive Tactics to Block Chrome Downloads (Outside EU)
Microsoft Edge continues to actively discourage Google Chrome downloads using ads and warnings, though these tactics have ceased within the EU due to regulatory pressure.
βMicrosoft is Removing PowerShell 2.0 from Windows 11
https://securityonline.info/microsoft-is-removing-powershell-2-0-from-windows-11/
https://securityonline.info/microsoft-is-removing-powershell-2-0-from-windows-11/
Daily CyberSecurity
Microsoft is Removing PowerShell 2.0 from Windows 11
Microsoft has officially removed the outdated and vulnerable PowerShell 2.0 from Windows 11 (starting with Build 27981), streamlining the OS and bolstering security.
βTikTok Preps New βM2β App for US Launch Amid Divestment Deadline & Oracle Deal
https://securityonline.info/tiktok-preps-new-m2-app-for-us-launch-amid-divestment-deadline-oracle-deal/
https://securityonline.info/tiktok-preps-new-m2-app-for-us-launch-amid-divestment-deadline-oracle-deal/
Daily CyberSecurity
TikTok Preps New "M2" App for US Launch Amid Divestment Deadline & Oracle Deal
TikTok is launching a new "M2" app by Sept 5 to comply with US divestment law, as ByteDance nears a deal with Oracle, aiming to replace the current app by March 2026.
βMicrosoft Halts Automatic Windows 11 Upgrades via KB5001716, Shifts to Notifications Only
https://securityonline.info/microsoft-halts-automatic-windows-11-upgrades-via-kb5001716-shifts-to-notifications-only/
https://securityonline.info/microsoft-halts-automatic-windows-11-upgrades-via-kb5001716-shifts-to-notifications-only/
Daily CyberSecurity
Microsoft Halts Automatic Windows 11 Upgrades via KB5001716, Shifts to Notifications Only
Microsoft revised KB5001716 to stop automatic Windows 11 upgrades, now only showing notifications about end-of-life or hardware issues for Windows 10/11 users.
β10 Best Network Security Solutions For Chief Security Officer To Consider β 2025
https://cybersecuritynews.com/network-security-solutions-for-cso/
https://cybersecuritynews.com/network-security-solutions-for-cso/
Cyber Security News
10 Best Network Security Solutions For Chief Security Officer To Consider - 2025
Best Network Security Solutions for CSO :1. Palo Alto Networks 2. Fortinet 3. Perimeter81 4. Check Point Software 5. Juniper Networks
βNightEagle APT Attacking Industrial Systems by Exploiting 0-Days and With Adaptive Malware
https://cybersecuritynews.com/nighteagle-apt-exploiting-0-days/
https://cybersecuritynews.com/nighteagle-apt-exploiting-0-days/
Cyber Security News
NightEagle APT Attacking Industrial Systems by Exploiting 0-Days and With Adaptive Malware
A sophisticated APT group dubbed "NightEagle" (APT-Q-95) has been conducting targeted attacks against China's critical technology sectors.
βScriptCase Vulnerabilities Let Attackers Execute Remote Code and Gain Server Access
https://cybersecuritynews.com/scriptcase-vulnerabilities/
https://cybersecuritynews.com/scriptcase-vulnerabilities/
Cyber Security News
ScriptCase Vulnerabilities Let Attackers Execute Remote Code and Gain Server Access
Two critical vulnerabilities in ScriptCase's Production Environment module that can be chained together to achieve pre-authenticated remote command execution.
β8 New Malicious Firefox Extensions Steal OAuth Tokens, Passwords and Spy on Users
https://cybersecuritynews.com/malicious-firefox-extensions/
https://cybersecuritynews.com/malicious-firefox-extensions/
Cyber Security News
8 New Malicious Firefox Extensions Steal OAuth Tokens, Passwords and Spy on Users
Security researchers from the Socket Threat Research Team have uncovered a sophisticated network of 8 malicious Firefox browser extensions.
β10 Best Vulnerability Management Tools In 2025
https://cybersecuritynews.com/vulnerability-management-tools/
https://cybersecuritynews.com/vulnerability-management-tools/
Cyber Security News
10 Best Vulnerability Management Tools In 2024
Best Vulnerability Management Tools & software; 1. Intruder 2. Qualys 3. Acunetix 4. Tripwire 5. Astra Pentest 6. Rapid7 and more
βThreat Actors Abusing Signed Drivers to Launch Modern Kernel Level Attacks on Windows
https://cybersecuritynews.com/threat-actors-abusing-signed-drivers/
https://cybersecuritynews.com/threat-actors-abusing-signed-drivers/
Cyber Security News
Threat Actors Abusing Signed Drivers to Launch Modern Kernel Level Attacks on Windows
Cybercriminals are increasingly exploiting legitimate Windows driver signing processes to deploy sophisticated kernel-level malware.