ποΈ Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Oracle has released an emergency update to address a critical security flaw in its EBusiness Suite software that it said has been exploited in the recent wave of Cl0p data theft attacks. The vulnerability, tracked as CVE202561882 CVSS score 9.8, concerns an unspecified bug that could allow an unauthenticated attacker with network access via HTTP to compromise and take control of the Oracle.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have shed light on a Chinesespeaking cybercrime group codenamed UAT8099 that has been attributed to search engine optimization SEO fraud and theft of highvalue credentials, configuration files, and certificate data. The attacks are designed to target Microsoft Internet Information Services IIS servers, with most of the infections reported in India, Thailand.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π NCSC: Patch Critical Oracle EBS Bug Now π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A critical Oracle EBusiness Suite vulnerability is being actively exploited by the Clop ransomware group.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NCSC: Patch Critical Oracle EBS Bug Now
A critical Oracle E-Business Suite vulnerability is being actively exploited by the Clop ransomware group
π Microsoft: Critical GoAnywhere Bug Exploited in Medusa Ransomware Campaign π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A critical GoAnywhere vulnerability is being exploited by the Medusa ransomware group, says Microsoft.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Microsoft: Critical GoAnywhere Bug Exploited in Medusa Ransomware Campaign
A critical GoAnywhere vulnerability is being exploited by the Medusa ransomware group, Microsoft warns
π Europol Calls for Stronger Data Laws to Combat Cybercrime π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Europols Cybercrime Conference has warned that cybercriminals are exploiting new technologies faster than law enforcement can adapt.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Europol Calls for Stronger Data Laws to Combat Cybercrime
Europolβs Cybercrime Conference has warned that cybercriminals are exploiting new technologies faster than law enforcement can adapt
π Ransomware Group βTrinity of Chaosβ Launches Data Leak Site π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A new TOR data leak site published by the Trinity of Chaos ransomware group unveils 39 firms data and threatens Salesforce litigation.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Ransomware Group βTrinity of Chaosβ Launches Data Leak Site
A new TOR data leak site published by the Trinity of Chaos ransomware group unveils 39 firmsβ data and threatens Salesforce litigation
π Scanning of Palo Alto Portals Surges 500% π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Experts warn that threat actors may be gearing up for compromise after large uptick in scans of Palo Alto Network portals.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Scanning of Palo Alto Portals Surges 500%
Experts warn that threat actors may be gearing up for compromise after large uptick in scans of Palo Alto Network portals
π Asahi Confirms Ransomware Attack, Data Stolen from Servers π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Asahi confirmed it has fallen victim to a ransomware attack, and revealed it has started manual order processing amid ongoing operational disruption.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Asahi Confirms Ransomware Attack, Data Stolen from Servers
Asahi confirmed it has fallen victim to a ransomware attack, and revealed it has started manual order processing amid ongoing operational disruption
π Renault Informs Customers of Supply Chain Data Breach π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Renault and Dacia have become the latest bigname brands to suffer a supply chain breach.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Renault Informs Customers of Supply Chain Data Breach
Renault and Dacia have become the latest big-name brands to suffer a supply chain breach
π Cybersecurity Technical Debt: Risks, Impacts, and Strategies Explained π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Starting the journey to a secure organisation is like fixing a broken lock on your front door you can ignore it and save time today, but every day you wait The post Cybersecurity Technical Debt Risks, Impacts, and Strategies Explained appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Cybersecurity Technical Debt: Risks, Impacts, and Management
Learn what cybersecurity technical debt is, how it accumulates, why it matters for the business, and practical steps executives can use to measure and pay it down.
π From $67M in Losses to Zero Ransom Paid: A Ransomware Rescue Case π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
How ransomware removal experts recovered critical systems and prevented longterm damage to business. The post From 67M in Losses to Zero Ransom Paid A Ransomware Rescue Case appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
How ransomware removal saved $67M and stopped hackers.
Learn how ransomware removal experts recovered critical systems and prevented long-term damage to business.
π¦
Cybersecurity Awareness Month 2025: Donβt Just Be Aware, Be Ahead π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cybersecurity Awareness Month 2025 " dataimagecaption"" datamediumfile"httpscyble.comwpcontentuploads202510CybersecurityAwarenessMonth2025300x150.webp" datalargefile"httpscyble.comwpcontentuploads202510CybersecurityAwarenessMonth2025.webp" title"Cybersecurity Awareness Month 2025 Don't Just Be Aware, Be Ahead 1" Every October, the cybersecurity world comes together to mark Cybersecurity Awareness Month. Organizations send out reminders. Security teams run training sessions. Everyone emphasizes the importance of creating strong passwords and recognizing phishing emails. And yet, here's the uncomfortable truth despite all this awareness, we're still losing ground. Too many incident response calls start with someone saying, "We knew this could happen." That's the problem right there....π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
ποΈ New Research: AI Is Already the #1 Data Exfiltration Channel in the Enterprise ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
For years, security leaders have treated artificial intelligence as an emerging technology, something to keep an eye on but not yet missioncritical. A new Enterprise AI and SaaS Data Security Report by AI Browser Security company LayerX proves just how outdated that mindset has become. Far from a future concern, AI is already the single largest uncontrolled channel for corporate data.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ XWorm 6.0 Returns with 35+ Plugins and Enhanced Data Theft Capabilities ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have charted the evolution of XWorm malware, turning it into a versatile tool for supporting a wide range of malicious actions on compromised hosts. "XWorm's modular design is built around a core client and an array of specialized components known as plugins," Trellix researchers Niranjan Hegde and Sijo Jacob said in an analysis published last week. "These plugins are.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Discord Reveals Data Breach Following Third-Party Compromise π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Discord said a thirdparty customer services provider was compromised to access user data, with the attackers aiming to extort a financial ransom.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Discord Reveals Data Breach Following Third-Party Compromise
Discord said a third-party customer services provider was compromised to access user data, with the attackers aiming to extort a financial ransom
π Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A critical Redis flaw, dubbed RediShell, has exposed 60,000 unprotected servers to exploitation.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation
A critical Redis flaw, dubbed βRediShell,β has exposed 60,000 unprotected servers to exploitation
π Qilin Claims Ransomware Attack on Mecklenburg Schools π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The Qilin ransomware gang has claimed attacks at Mecklenburg County Public Schools, stealing financial records and childrens medical files.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Qilin Claims Ransomware Attack on Mecklenburg Schools
The Qilin ransomware gang has claimed attacks at Mecklenburg County Public Schools, stealing financial records and childrensβ medical files
ποΈ Google's New AI Doesn't Just Find Vulnerabilities β It Rewrites Code to Patch Them ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Google's DeepMind division on Monday announced an artificial intelligence AIpowered agent called CodeMender that automatically detects, patches, and rewrites vulnerable code to prevent future exploits. The efforts add to the company's ongoing efforts to improve AIpowered vulnerability discovery, such as Big Sleep and OSSFuzz. DeepMind said the AI agent is designed to be both reactive and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€2π₯1
π NCSC: Observability and Threat Hunting Must Improve π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The UKs National Cyber Security Centre has released new guidance to help firms improve observability and threat hunting.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NCSC: Observability and Threat Hunting Must Improve
The UKβs National Cyber Security Centre has released new guidance to help firms improve observability and threat hunting
ποΈ Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Threat actors are actively exploiting a critical security flaw impacting the Service Finder WordPress theme that makes it possible to gain unauthorized access to any account, including administrators, and take control of susceptible sites. The authentication bypass vulnerability, tracked as CVE20255947 CVSS score 9.8, affects the Service Finder Bookings, a WordPress plugin bundled with the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π ICOβs Β£7.5m Clearview AI Fine a Step Closer After Legal Victory π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The ICO has won an Upper Tribunal appeal against Clearview AI over its ability to fine the company.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
ICOβs Β£7.5m Clearview AI Fine a Step Closer After Legal Victory
The ICO has won an Upper Tribunal appeal against Clearview AI over its intention to fine the company