ποΈ β‘ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Every week, the cyber world reminds us that silence doesnt mean safety. Attacks often begin quietly one unpatched flaw, one overlooked credential, one backup left unencrypted. By the time alarms sound, the damage is done. This weeks edition looks at how attackers are changing the game linking different flaws, working together across borders, and even turning trusted tools into weapons.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Think your WAF has you covered? Think again. This holiday season, unmonitored JavaScript is a critical oversight allowing attackers to steal payment data while your WAF and intrusion detection systems see nothing. With the 2025 shopping season weeks away, visibility gaps must close now. Get the complete Holiday Season Security Playbook here. Bottom Line Up Front The 2024 holiday season saw major.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors. The activity, described as akin to an "exploit shotgun" approach, has singled out a wide range of internetexposed infrastructure, including routers, digital video recorders DVRs, network video recorders NVRs, CCTV systems, web servers, and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Microsoft said it has revamped the Internet Explorer IE mode in its Edge browser after receiving "credible reports" in August 2025 that unknown threat actors were abusing the backward compatibility feature to gain unauthorized access to users' devices. "Threat actors were leveraging basic social engineering techniques alongside unpatched 0day exploits in Internet Explorer's JavaScript.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π New Stealit Malware Campaign Spreads via VPN and Game Installer Apps π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A new campaign distributing the Stealit infostealer employs previously unknown malware delivery techniques and infrastructure.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
New Stealit Malware Campaign Spreads via VPN and Game Installer Apps
A new campaign distributing the Stealit infostealer employs previously unknown malware delivery techniques and infrastructure
β€1
π Apple Bug Bounty Payouts Can Now Top $5m π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Apple has doubled its top bug bounty reward to 2m but with bonuses it could reach 5m.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Apple Bug Bounty Payouts Can Now Top $5m
Apple has doubled its top bug bounty reward to $2m but with bonuses it could reach $5m
π Exabeam vs. Anvilogic: The 2025 AI SOC Face-Off π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
This Exabeam vs. Anvilogic comparison is by someone whos spent too many late nights wrestling with broken detections and watching vendors pitch SOCless futures from AIpowered podiums. Key Takeaways Exabeam The post Exabeam vs. Anvilogic The 2025 AI SOC FaceOff appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Exabeam vs. Anvilogic: 2025 AI SOC Comparison
Compare Exabeam vs. Anvilogic in the 2025 AI SOC landscape. Discover strengths, blind spots, and cost dynamics.
π Spain Arrests Alleged Leader of GXC Team Cybercrime Network π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Spanish authorities have arrested a 25yearold Brazilian accused of leading the GXC Team and selling malware and AI tools to cybercriminals.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Spain Arrests Alleged Leader of GXC Team Cybercrime Network
Spanish authorities have arrested a 25-year-old Brazilian accused of leading the GXC Team and selling malware and AI tools to cybercriminals
π€1
π Hackers Target ScreenConnect Features For Network Intrusions π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A rise in attacks exploiting RMM tools like ScreenConnect enables system control via phishing tactics.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Hackers Target ScreenConnect Features For Network Intrusions
A rise in attacks exploiting RMM tools like ScreenConnect enables system control via phishing tactics
π¦Ώ Critical Oracle EBS Flaw Could Expose Sensitive Data π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Oracle patches a highseverity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data. The post Critical Oracle EBS Flaw Could Expose Sensitive Data appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Critical Oracle EBS Flaw Could Expose Sensitive Data
Oracle patches a high-severity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data.
π¦Ώ Critical Oracle EBS Flaw Could Expose Sensitive Data π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Oracle patches a highseverity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data. The post Critical Oracle EBS Flaw Could Expose Sensitive Data appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Critical Oracle EBS Flaw Could Expose Sensitive Data
Oracle patches a high-severity EBS flaw that could let attackers bypass authentication and access sensitive enterprise data.
π¨ UK experiencing four 'nationally significant' cyber attacks every week π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
Latest Annual Review reveals that the cyber threats facing the UK continue to escalate.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
UK experiencing four 'nationally significant' cyber attacks every week
Latest Annual Review reveals that the cyber threats facing the UK continue to escalate.
π¨ Small businesses to receive cyber security boost with new toolkit from experts π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
NCSC CEO unveils a new Cyber Action Toolkit at the NCSCs Annual Review launch with clear message to small businesses that it is time to act.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
www.ncsc.gov.uk
Small businesses to receive cyber security boost with new toolkit from experts
NCSC CEO unveils a new Cyber Action Toolkit at the NCSCβs Annual Review launch with clear message to small businesses that βit is time to actβ.
π New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Trend Micro have reported a campaign exploiting a flaw in Cisco SNMP to install Linux rootkits on devices.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence
Trend Micro have reported a campaign exploiting a flaw in Cisco SNMP to install Linux rootkits on devices
π New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Trend Micro have reported a campaign exploiting a flaw in Cisco SNMP to install Linux rootkits on devices.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
New Rootkit Campaign Exploits Cisco SNMP Flaw to Gain Persistence
Trend Micro have reported a campaign exploiting a flaw in Cisco SNMP to install Linux rootkits on devices
β€1
π¦Ώ F5 Hit by βNation-Stateβ Cyberattack π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The intrusion affected F5s BIGIP product development environment and engineering knowledge management platforms. The post F5 Hit by NationState Cyberattack appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
F5 Hit by βNation-Stateβ Cyberattack
The intrusion affected F5βs BIG-IP product development environment and engineering knowledge management platforms.
π¨ UK experiencing four 'nationally significant' cyber attacks every week π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
Latest Annual Review reveals that the cyber threats facing the UK continue to escalate.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
UK experiencing four 'nationally significant' cyber attacks every week
Latest Annual Review reveals that the cyber threats facing the UK continue to escalate.
π¦Ώ F5 Hit by βNation-Stateβ Cyberattack π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The intrusion affected F5s BIGIP product development environment and engineering knowledge management platforms. The post F5 Hit by NationState Cyberattack appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
F5 Hit by βNation-Stateβ Cyberattack
The intrusion affected F5βs BIG-IP product development environment and engineering knowledge management platforms.
π AI Attacks Surge as Microsoft Process 100 Trillion Signals Daily π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Microsoft systems analyze over 100 trillion daily signals, suggesting dramatically increasing AIdriven cyberthreats.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
AI Attacks Surge as Microsoft Process 100 Trillion Signals Daily
Microsoft systems analyze over 100 trillion daily signals, suggesting dramatically increasing AI-driven cyber-threats
π AI Attacks Surge as Microsoft Process 100 Trillion Signals Daily π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Microsoft systems analyze over 100 trillion daily signals, suggesting dramatically increasing AIdriven cyberthreats.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
AI Attacks Surge as Microsoft Process 100 Trillion Signals Daily
Microsoft systems analyze over 100 trillion daily signals, suggesting dramatically increasing AI-driven cyber-threats
π¦Ώ F5 Hit by βNation-Stateβ Cyberattack π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
The intrusion affected F5s BIGIP product development environment and engineering knowledge management platforms. The post F5 Hit by NationState Cyberattack appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
F5 Hit by βNation-Stateβ Cyberattack
The intrusion affected F5βs BIG-IP product development environment and engineering knowledge management platforms.