CURATED
Dec 09, 2025
Detectum Security Team
Zero-day vulnerabilities represent one of the most significant threats in cybersecurity. Learn how they work, why they're dangerous, and how organizations can protect themselves against these unknown ...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
Detectum Team
The Apache Software Foundation's earlier fix for a critical Tika flaw missed the full scope of the vulnerability, prompting an updated advisory and CVE.
Read Full Article
Cybersecurity
Security
Dec 08, 2025
Detectum Team
Attacks against CVE-2025-55182, which began almost immediately after public disclosure last week, have increased as more threat actors take advantage of the flaw.
Read Full Article
Cybersecurity
Security
Dec 08, 2025
Detectum Team
The US Treasury's Financial Crimes Enforcement Network shared data showing how dramatically ransomware attacks have changed over time.
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
Cybersecurity researchers are calling attention to a new campaign dubbed JS#SMUGGLER that has been observed leveraging compromised websites as a distribution vector for a remote access trojan named Ne...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
It’s been a week of chaos in code and calm in headlines. A bug that broke the internet’s favorite framework, hackers chasing AI tools, fake apps stealing cash, and record-breaking cyberattacks —...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
The holiday season compresses risk into a short, high-stakes window. Systems run hot, teams run lean, and attackers time automated campaigns to get maximum return. Multiple industry threat reports sho...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
Detectum Team
"Broadside" is targeting a critical flaw in DVR systems to conduct command injection attacks, which can hijack devices to achieve persistence and move laterally.
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
Cybersecurity researchers have disclosed details of two new Android malware families dubbed FvncBot and SeedSnatcher, as another upgraded version of ClayRat has been spotted in the wild.
The findings ...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
A critical security flaw in the Sneeit Framework plugin for WordPress is being actively exploited in the wild, per data from Wordfence.
The remote code execution vulnerability in question is CVE-2025-...
Read Full Article
Cybersecurity
Security
Dec 08, 2025
info@thehackernews.com (The Hacker News)
The Iranian hacking group known as MuddyWater has been observed leveraging a new backdoor dubbed UDPGangster that uses the User Datagram Protocol (UDP) for command-and-control (C2) purposes.
The cyber...
Read Full Article
Cybersecurity
Security
CURATED
Dec 08, 2025
Detectum Security Team
Ransomware attacks continue to evolve. Discover the latest protection strategies, backup solutions, and incident response plans to safeguard your organization against ransomware threats.
Read Full Article
Cybersecurity
Security
CURATED
Dec 07, 2025
Detectum Security Team
MFA has become essential in modern cybersecurity. Understand different MFA methods, implementation strategies, and why single-factor authentication is no longer sufficient.
Read Full Article
Cybersecurity
Security
Dec 06, 2025
info@thehackernews.com (The Hacker News)
Over 30 security vulnerabilities have been disclosed in various artificial intelligence (AI)-powered Integrated Development Environments (IDEs) that combine prompt injection primitives with legitimate...
Read Full Article
Cybersecurity
Security
Dec 06, 2025
Detectum Team
A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious connections to a Kremlin-connected oligarch whose Russian university build...
Read Full Article
Cybersecurity
Security
Dec 06, 2025
info@thehackernews.com (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday formally added a critical security flaw impacting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) ...
Read Full Article
Cybersecurity
Security
CURATED
Dec 06, 2025
Detectum Security Team
Navigate the complexities of cloud security with our comprehensive guide to the shared responsibility model. Learn what cloud providers handle and what remains your responsibility.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
Detectum Team
Software teams at Google and other Rust adopters see safer code when using the memory-safe language, and also fewer rollbacks and less code review.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
Detectum Team
Remember when Apple put that U2 album in everyone's music libraries? India wanted to do that to all of its citizens, but with a cybersecurity app. It wasn't a good idea.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
A new agentic browser attack targeting Perplexity's Comet browser that's capable of turning a seemingly innocuous email into a destructive action that wipes a user's entire Google Drive contents, find...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
A critical security flaw has been disclosed in Apache Tika that could result in an XML external entity (XXE) injection attack.
The vulnerability, tracked as CVE-2025-66516, is rated 10.0 on the CVSS s...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
Detectum Team
Manufacturers are the top target for cyberattacks in 2025 because of their still-plentiful cybersecurity gaps and a lack of expertise.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
Detectum Team
A maximum-severity vulnerability affecting the React JavaScript library has been exploited in the wild, further stressing the need to patch now.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
Detectum Team
As quantum quietly moves beyond lab experiment and into production workflows, here's what enterprise security leaders should be focused on, according to Lineswala.
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge.
The vulnerability ...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
A human rights lawyer from Pakistan's Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a civil society member in the country was targeted by I...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
Most MSPs and MSSPs know how to deliver effective security. The challenge is helping prospects understand why it matters in business terms. Too often, sales conversations stall because prospects are o...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor named BRICKSTORM that has been put to use by state-sponsored threat actors from the People's...
Read Full Article
Cybersecurity
Security
Dec 05, 2025
info@thehackernews.com (The Hacker News)
A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, according to an alert issued by JPCERT/CC this week.
The vulnerab...
Read Full Article
Cybersecurity
Security
CURATED
Dec 05, 2025
Detectum Security Team
Phishing attacks have become increasingly sophisticated. Explore modern phishing techniques, social engineering tactics, and comprehensive defense strategies to protect your organization.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
Transurban head of cyber defense Muhammad Ali Paracha shares how his team is automating the triaging and scoring of security threats as part of the Black Hat Middle East conference.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishi...
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
When hiring a CISO, understand the key difference between engineering and holistic security leaders.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
State-sponsored actors tied to China continue to target VMware vSphere environments at government and technology organizations.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
Global cybersecurity agencies published guidance regarding AI deployments in operational technology, a backbone of critical infrastructure.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
info@thehackernews.com (The Hacker News)
The threat actor known as Silver Fox has been spotted orchestrating a false flag operation to mimic a Russian threat group in attacks targeting organizations in China.
The search engine optimization (...
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
The deal, believed to be valued at $1 billion, will bring nonhuman identity access control of agents and machines to ServiceNow's offerings, including its new AI Control Tower.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
It's the best deal going in cybercrime: fully compromised websites belonging to high-value organizations, for just a couple hundred bucks each.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
info@thehackernews.com (The Hacker News)
Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locked in a nonstop race to outsmart each othe...
Read Full Article
Cybersecurity
Security
Dec 04, 2025
info@thehackernews.com (The Hacker News)
As 2025 draws to a close, security professionals face a sobering realization: the traditional playbook for web security has become dangerously obsolete. AI-powered attacks, evolving injection techniqu...
Read Full Article
Cybersecurity
Security
Dec 04, 2025
info@thehackernews.com (The Hacker News)
Cybercriminals associated with a financially motivated group known as GoldFactory have been observed staging a fresh round of attacks targeting mobile users in Indonesia, Thailand, and Vietnam by impe...
Read Full Article
Cybersecurity
Security
Dec 04, 2025
Detectum Team
Iran's top state-sponsored APT is usually rather crass. But in a recent spate of attacks, it tried out some interesting evasion tactics, including delving into Snake, an old-school mobile game.
Read Full Article
Cybersecurity
Security
Dec 04, 2025
info@thehackernews.com (The Hacker News)
Cloudflare on Wednesday said it detected and mitigated the largest ever distributed denial-of-service (DDoS) attack that measured at 29.7 terabits per second (Tbps).
The activity, the web infrastructu...
Read Full Article
Cybersecurity
Security
CURATED
Dec 04, 2025
Detectum Security Team
Proper firewall configuration is critical for network security. Learn about firewall types, rule management, and best practices for securing your network perimeter.
Read Full Article
Cybersecurity
Security
Dec 03, 2025
Detectum Team
The China-based cyber-threat group has been quietly using malicious extensions on the Google Chrome and Microsoft Edge marketplaces to spy on millions of users.
Read Full Article
Cybersecurity
Security
Dec 03, 2025
Detectum Team
The vulnerability, which was assigned two CVEs with maximum CVSS scores of 10, may affect more than a third of cloud service providers.
Read Full Article
Cybersecurity
Security
Dec 03, 2025
Detectum Team
The suit alleges the Chinese retailer's app secretly accesses and harvests users' sensitive information without their knowledge or consent.
Read Full Article
Cybersecurity
Security
Dec 03, 2025
info@thehackernews.com (The Hacker News)
A maximum-severity security flaw has been disclosed in React Server Components (RSC) that, if successfully exploited, could result in remote code execution.
The vulnerability, tracked as CVE-2025-5518...
Read Full Article
Cybersecurity
Security
Dec 03, 2025
info@thehackernews.com (The Hacker News)
Remember when phishing emails were easy to spot? Bad grammar, weird formatting, and requests from a "Prince" in a distant country?
Those days are over.
Today, a 16-year-old with zero coding skills and...
Read Full Article
Cybersecurity
Security
Dec 03, 2025
info@thehackernews.com (The Hacker News)
Microsoft has silently plugged a security flaw that has been exploited by several threat actors since 2017 as part of the company's November 2025 Patch Tuesday updates, according to ACROS Security's 0...
Read Full Article
Cybersecurity
Security