βAsahi Cyberattack Brings Japanβs Top Brewer to Its Knees During Peak Beer Season
https://thecyberexpress.com/asahi-cyberattack-japan-operations-crippled/
https://thecyberexpress.com/asahi-cyberattack-japan-operations-crippled/
The Cyber Express
Asahi Cyberattack Cripples Japanβs Largest Brewer
The Asahi cyberattack halts beer production, drops shipments by 90%, and lets rivals like Kirin and Sapporo gain ground amid Japanβs peak season.
βResearchers Uncover Critical runC Bugs Allowing Full Container Escape
https://thecyberexpress.com/cve-2025-31133-runc-container-security/
https://thecyberexpress.com/cve-2025-31133-runc-container-security/
The Cyber Express
Critical RunC Flaws Reported: CVE-2025-31133, 52565 & 52881
CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 let attackers escape containers and access hosts.
βNew Yorkβs First-of-Its-Kind Algorithmic Pricing Law Goes Into Effect
https://thecyberexpress.com/personalized-algorithmic-pricing-law/
https://thecyberexpress.com/personalized-algorithmic-pricing-law/
The Cyber Express
Personalized Algorithmic Pricing Law Takes Effect In New York
Businesses operating in or serving customers within New York must disclose if they use personalized algorithmic pricing.
βCritical Synology BeeStation Zero-Day (CVE-2025-12686) Found at Pwn2Own Allows Remote Code Execution
https://securityonline.info/critical-synology-beestation-zero-day-cve-2025-12686-found-at-pwn2own-allows-remote-code-execution/
https://securityonline.info/critical-synology-beestation-zero-day-cve-2025-12686-found-at-pwn2own-allows-remote-code-execution/
Daily CyberSecurity
Critical Synology BeeStation Zero-Day (CVE-2025-12686) Found at Pwn2Own Allows Remote Code Execution
Synology patched a Critical (CVSS 9.8) RCE zero-day flaw (CVE-2025-12686) in BeeStation OS. The vulnerability, found during Pwn2Own, allows remote attackers to execute arbitrary code. Update to v1.3.2-65648.
βSAP November 2025 Patch Day Fixes 3 Critical Flaws (CVSS 10) β Including Code Injection and Insecure Key Management
https://securityonline.info/sap-november-2025-patch-day-fixes-3-critical-flaws-cvss-10-including-code-injection-and-insecure-key-management/
https://securityonline.info/sap-november-2025-patch-day-fixes-3-critical-flaws-cvss-10-including-code-injection-and-insecure-key-management/
Daily CyberSecurity
SAP November 2025 Patch Day Fixes 3 Critical Flaws (CVSS 10) β Including Code Injection and Insecure Key Management
SAP released its Patch Day update fixing 18 flaws, including two Critical (CVSS 10.0) vulnerabilities: RMI-P4 RCE and Hard-Coded Credentials in SQL Anywhere Monitor, risking unauthenticated takeover.
βU.S. CISA adds Samsung mobile devices flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/184452/hacking/u-s-cisa-adds-samsung-mobile-devices-flaw-to-its-known-exploited-vulnerabilities-catalog.html
https://securityaffairs.com/184452/hacking/u-s-cisa-adds-samsung-mobile-devices-flaw-to-its-known-exploited-vulnerabilities-catalog.html
Security Affairs
U.S. CISA adds Samsung mobile devices flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Samsung mobile devices flaw to its Known Exploited Vulnerabilities catalog.
βWatchGuard Firebox Flaw Allows Attackers to Gain Unauthorized SSH Access
https://gbhackers.com/watchguard-firebox-flaw/
https://gbhackers.com/watchguard-firebox-flaw/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
WatchGuard Firebox Flaw Allows Attackers to Gain Unauthorized SSH Access
A security vulnerability has been discovered in WatchGuard Firebox devices that could allow attackers to bypass authentication mechanisms.
βNew VanHelsing Ransomware-as-a-Service Hits Windows, Linux, BSD, ARM and ESXi
https://gbhackers.com/vanhelsing-ransomware/
https://gbhackers.com/vanhelsing-ransomware/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New VanHelsing Ransomware-as-a-Service Hits Windows, Linux, BSD, ARM and ESXi
A sophisticated new ransomware operation dubbed VanHelsing has emerged as a rapidly expanding threat in the cybercriminal landscape.
βDevolutions Server Flaw Allows Attackers to Impersonate Users via Pre-MFA Cookie
https://gbhackers.com/devolutions-server-flaw/
https://gbhackers.com/devolutions-server-flaw/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Devolutions Server Flaw Allows Attackers to Impersonate Users via Pre-MFA Cookie
Devolutions Server has been found vulnerable to a critical security flaw that allows low-privileged authenticated users.
βAttackers Use Quantum Route Redirect to Launch Instant Phishing on M365
https://gbhackers.com/quantum-route-redirect/
https://gbhackers.com/quantum-route-redirect/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Attackers Use Quantum Route Redirect to Launch Instant Phishing on M365
KnowBe4 Threat Labs has uncovered a sophisticated phishing campaign that marks a turning point in cybercriminal capabilities.
βCritical Zimbra Flaw Fixed: Patch Addresses Multiple Stored XSS and Unauthenticated LFI in Mail Client
https://securityonline.info/critical-zimbra-flaw-fixed-patch-addresses-multiple-stored-xss-and-unauthenticated-lfi-in-mail-client/
https://securityonline.info/critical-zimbra-flaw-fixed-patch-addresses-multiple-stored-xss-and-unauthenticated-lfi-in-mail-client/
Daily CyberSecurity
Critical Zimbra Flaw Fixed: Patch Addresses Multiple Stored XSS and Unauthenticated LFI in Mail Client
Zimbra fixes Critical Stored XSS and an Unauthenticated LFI flaw, urging users to update immediately to mitigate session hijacking and data exfiltration risks.
βFerocious Kitten APT Uses MarkiRAT for Keystroke and Clipboard Surveillance
https://gbhackers.com/ferocious-kitten-apt/
https://gbhackers.com/ferocious-kitten-apt/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Ferocious Kitten APT Uses MarkiRAT for Keystroke and Clipboard Surveillance
Ferocious Kitten, a covert cyber-espionage group active since at least 2015, has emerged as a persistent threat to Persian-speaking dissidents and activists within Iran.
βNorth Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
https://securityaffairs.com/184474/intelligence/north-korea-konni-apt-used-google-find-hub-to-erase-data-and-spy-on-defectors.html
https://securityaffairs.com/184474/intelligence/north-korea-konni-apt-used-google-find-hub-to-erase-data-and-spy-on-defectors.html
Security Affairs
North Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
North Korea-linked APT Konni posed as counselors to steal data and wipe Android phones via Google Find Hub in Sept 2025.
βNew Phishing Campaign Targets Meta Business Suite Users
https://gbhackers.com/meta-business-suite/
https://gbhackers.com/meta-business-suite/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New Phishing Campaign Targets Meta Business Suite Users
With more than 5.4 billion social media users worldwide, Facebook remains a critical marketing channel for businesses of all sizes.
βNew βKomeXβ Android RAT Hits Hacker Forums with Tiered Subscriptions
https://gbhackers.com/komex-android-rat/
https://gbhackers.com/komex-android-rat/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New βKomeXβ Android RAT Hits Hacker Forums with Tiered Subscriptions
A sophisticated Android remote-access trojan named KomeX RAT has emerged on underground hacking forums.
βSAP Releases Security Update to Fix Critical Code Execution and Injection Flaws
https://gbhackers.com/sap-releases-security-update-to-fix-critical-code-execution/
https://gbhackers.com/sap-releases-security-update-to-fix-critical-code-execution/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
SAP Releases Security Update to Fix Critical Code Execution and Injection Flaws
SAP has released an update addressing 18 new vulnerabilities, including several critical flaws related to code execution and data injection.
βWinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies
https://gbhackers.com/winrar-vulnerability-2/
https://gbhackers.com/winrar-vulnerability-2/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
WinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies
The notorious APT-C-08 hacking group, also known as BITTER, has been observed weaponizing a critical WinRAR directory traversal vulnerability.
βZoom Workplace for Windows Flaw Allows Local Privilege Escalation
https://gbhackers.com/zoom-workplace-for-windows-flaw/
https://gbhackers.com/zoom-workplace-for-windows-flaw/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Zoom Workplace for Windows Flaw Allows Local Privilege Escalation
A security vulnerability has been discovered in Zoom Workplace's VDI Client for Windows that could allow attackers to escalate their privileges.
βFantasy Hub: Russian-sold Android RAT boasts full device espionage as MaaS
https://securityaffairs.com/184488/malware/fantasy-hub-russian-sold-android-rat-boasts-full-device-espionage-as-maas.html
https://securityaffairs.com/184488/malware/fantasy-hub-russian-sold-android-rat-boasts-full-device-espionage-as-maas.html
Security Affairs
Fantasy Hub: Russian-sold Android RAT boasts full device espionage as MaaS
Researchers found Fantasy Hub, a Russian MaaS Android RAT that lets attackers spy, steal data, and control devices via Telegram.
βSeeing Inside the Vortex: Detecting Living off the Land Techniques
https://blogs.cisco.com/security/seeing-inside-the-vortex-detecting-living-off-the-land-techniques/
https://blogs.cisco.com/security/seeing-inside-the-vortex-detecting-living-off-the-land-techniques/
Cisco Blogs
Seeing Inside the Vortex: Detecting Living off the Land Techniques
Networking infrastructure is an often-overlooked threat surface being targeted by sophisticated threat actors. Learn more about this topic.