Every day, billions of people place their trust in websites they know little about. Behind each one is a hosting provider, but not all of them play by the same rules. Traditionally, privacy policies let web visitors understand how their data would be handled, and SSL (Secure Sockets Layer) certificates ensured their connection was encrypted. … Read More “Why the web-hosting industry needs a trust seal – CyberScoop” »
Author: Greg Otto
ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More – The Hacker News
The online world is changing fast. Every week, new scams, hacks, and tricks show how easy it’s become to turn everyday technology into a weapon. Tools made to help us work, connect, and stay safe are now being used to steal, spy, and deceive. Hackers don’t always break systems anymore — they use them. They … Read More “ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More – The Hacker News” »
Data from the Identity Theft Resource Center reveals 23 million individuals victimized by breaches in Q3 2025 – Read More –
F5 has admitted a nation state actor has stolen source code and information on undisclosed vulnerabilities – Read More –
With the increase in digital ecosystems, cyber threats are growing in complexity and magnitude. Instead of just planning against… The post Quantum-Agile Architectures: The Future of Cybersecurity appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Adobe Experience Manager to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2025-54253 (CVSS score: 10.0), a maximum-severity misconfiguration bug that could result in arbitrary code execution. – Read More … Read More “CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack – The Hacker News” »
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS) – Full Disclosure
Posted by Gynvael Coldwind on Oct 15 Vendor Response Pattern Hi Christopher, Vendor is correct with this one. The problem isn’t the vendor’s site – it’s that the browser is already pwned with the malicious browser extension (this is site-agnostic). You’ve mentioned “No user interaction required beyond normal application usage.”, but having “Malicious browser … Read More “Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS) – Full Disclosure” »
The Power of Vector Databases in the New Era of AI Search – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
In my 15 years as a software engineer, I’ve seen one truth hold constant: traditional databases are brilliant… – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
A Massachusetts man who previously pleaded guilty to a cyberattack on PowerSchool, exposing data on tens of millions of students and teachers, was sentenced to four years in prison Tuesday — half the amount federal prosecutors sought in sentencing recommendations submitted to the court. Matthew Lane, 20, stole data from PowerSchool belonging to nearly 70 … Read More “PowerSchool hacker sentenced to 4 years in prison – CyberScoop” »
Federal cyber authorities issued an emergency directive Wednesday requiring federal agencies to identify and apply security updates to F5 devices after the cybersecurity vendor said a nation-state attacker had long-term, persistent access to its systems. The order, which mandates federal civilian executive branch agencies take action by Oct. 22, marked the second emergency directive issued … Read More “CISA warns of imminent risk posed by thousands of F5 products in federal agencies – CyberScoop” »
Microsoft Patch Tuesday Oct 2025 Fixs 175 Vulnerabilities including 3 Zero-Days – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
October’s Microsoft Patch Tuesday fixes 170+ flaws, including 3 actively exploited zero-days and critical WSUS RCE (CVSS 9.8). Immediate patching is mandatory. Final free updates for Windows 10. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
F5 Confirms Nation-State Breach, Source Code and Vulnerability Data Stolen – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
F5 has confirmed it was the victim of a state-sponsored cyberattack that allowed hackers to access its internal… – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
A threat actor with ties to China has been attributed to a five-month-long intrusion targeting a Russian IT service provider, marking the hacking group’s expansion to the country beyond Southeast Asia and South America. The activity, which took place from January to May 2025, has been attributed by Broadcom-owned Symantec to a threat actor it … Read More “Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months – The Hacker News” »
BreachLock Named Representative Provider for Penetration Testing as a Service (PTaaS) in New Gartner® Report – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
New York, United States, 15th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion – The Hacker News
U.S. cybersecurity company F5 on Wednesday disclosed that unidentified threat actors broke into its systems and stole files containing some of BIG-IP’s source code and information related to undisclosed vulnerabilities in the product. It attributed the activity to a “highly sophisticated nation-state threat actor,” adding the adversary maintained long-term, persistent access to its network. The … Read More “F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion – The Hacker News” »
A flaw in the Slider Revolution plugin has exposed millions of WordPress sites to unauthorized file access – Read More –
New research has uncovered that publishers of over 100 Visual Studio Code (VS Code) extensions leaked access tokens that could be exploited by bad actors to update the extensions, posing a critical software supply chain risk. “A leaked VSCode Marketplace or Open VSX PAT [personal access token] allows an attacker to directly distribute a malicious … Read More “Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks – The Hacker News” »
Whisper 2FA is now one of the most active PhaaS tools alongside Tycoon and EvilProxy, responsible for one million attacks since July 2025 – Read More –
F5, a company that specializes in application security and delivery technology, disclosed Wednesday that it had been the target of what it’s calling a “highly sophisticated” cyberattack, which it attributes to a nation-state actor. The announcement follows authorization from the U.S. Department of Justice, which allowed F5 to delay public disclosure of the breach under … Read More “F5 disclosures breach tied to nation-state threat actor – CyberScoop” »
Fake Google Job Offer Email Scam Targets Workspace and Microsoft 365 Users – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Cybersecurity firm Sublime Security details a new credential phishing scam impersonating Google Careers to steal login details from Google Workspace and Microsoft 365 users. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
MCPTotal Launches to Power Secure Enterprise MCP Workflows – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
New York, USA, New York, 15th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Elasticsearch Leak Exposes 6 Billion Records from Scraping, Old and New Breaches – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
An Elasticsearch leak exposed 6 billion records from global data breaches and scraping sources, including banking and personal details tied to multiple regions. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
MCPTotal Launches to Power Secure Enterprise MCP Workflows – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
New York, USA, New York, 15th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
TLDR Even if you take nothing else away from this piece, if your organization is evaluating passkey deployments, it is insecure to deploy synced passkeys. Synced passkeys inherit the risk of the cloud accounts and recovery processes that protect them, which creates material enterprise exposure. Adversary-in-the-middle (AiTM) kits can force authentication fallbacks that circumvent strong … Read More “How Attackers Bypass Synced Passkeys – The Hacker News” »
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped – The Hacker News
Microsoft on Tuesday released fixes for a whopping 183 security flaws spanning its products, including three vulnerabilities that have come under active exploitation in the wild, as the tech giant officially ended support for its Windows 10 operating system unless the PCs are enrolled in the Extended Security Updates (ESU) program. Of the 183 vulnerabilities, … Read More “Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped – The Hacker News” »
Microsoft has fixed over 170 CVEs in October’s Patch Tuesday, including six zero-day vulnerabilities – Read More –
Capita fined £14m for data protection failings in 2023 cyber-attack – Data and computer security | The Guardian
Hackers stole personal information of 6.6m people but outsourcing firm did not shut device targeted for 58 hours The outsourcing company Capita has been fined £14m for data protection failings after hackers stole the personal information of 6.6 million people, including staff details and those of its clients’ customers. John Edwards, the UK information commissioner … Read More “Capita fined £14m for data protection failings in 2023 cyber-attack – Data and computer security | The Guardian” »
Outsourcing giant Capita has been fined £14m by the ICO after a major data breach in 2023 – Read More –
Investigations found that the network operates scam centers in Cambodia, Myanmar and across Southeast Asia – Read More –
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access – The Hacker News
Cybersecurity researchers have disclosed that a critical security flaw impacting ICTBroadcast, an autodialer software from ICT Innovations, has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2025-2611 (CVSS score: 9.3), relates to improper input validation that can result in unauthenticated remote code execution due to the fact that the call … Read More “Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access – The Hacker News” »
Cybersecurity researchers have disclosed two critical security flaws impacting Red Lion Sixnet remote terminal unit (RTU) products that, if successfully exploited, could result in code execution with the highest privileges. The shortcomings, tracked as CVE-2023-40151 and CVE-2023-42770, are both rated 10.0 on the CVSS scoring system. “The vulnerabilities affect Red Lion SixTRAK and VersaTRAK – … Read More “Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control – The Hacker News” »
The Digital Personal Data Protection (DPDP) Act 2025 represents a necessary change in the data privacy of India, which… The post DPDP Act 2025: Key Compliance Challenges and How CryptoBind Solves Them appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
SAP has rolled out security fixes for 13 new security issues, including additional hardening for a maximum-severity bug in SAP NetWeaver AS Java that could result in arbitrary command execution. The vulnerability, tracked as CVE-2025-42944, carries a CVSS score of 10.0. It has been described as a case of insecure deserialization. “Due to a deserialization … Read More “New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login – The Hacker News” »
Microsoft today released software updates to plug a whopping 172 security holes in its Windows operating systems, including at least two vulnerabilities that are already being actively exploited. October’s Patch Tuesday also marks the final month that Microsoft will ship security updates for Windows 10 systems. If you’re running a Windows 10 PC and you’re … Read More “Patch Tuesday, October 2025 ‘End of 10’ Edition – Krebs on Security” »
Rep. Eric Swalwell, D-Calif., sent a letter Tuesday to acting CISA Director Madhu Gottumukkala raising concerns about staffing levels and the direction of the nation’s primary cybersecurity agency, writing that the “Trump Administration has undertaken multiple efforts to decimate CISA’s workforce, undermining our nation’s cybersecurity.” Swalwell, the ranking member on the House Homeland Security Subcommittee … Read More “Swalwell seeks answers from CISA on workforce cuts – CyberScoop” »
How much private and sensitive data can you get by pointing $600 worth of satellite equipment at the sky? Quite a bit, it turns out. Researchers from the University of Maryland and the University of California, San Diego say they were able to intercept sensitive data from the U.S. military, telecommunications firms, major businesses and … Read More “Researchers find a startlingly cheap way to steal your secrets from space – CyberScoop” »
Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days – CyberScoop
Microsoft addressed 175 vulnerabilities affecting its core products and underlying systems, including two actively exploited zero-days, the company said in its latest security update. It’s the largest assortment of defects disclosed by the tech giant this year. The zero-day vulnerabilities — CVE-2025-24990 affecting Agere Windows Modem Driver and CVE-2025-59230 affecting Windows Remote Access Connection Manager … Read More “Microsoft’s Patch Tuesday fixes 175 vulnerabilities, including two actively exploited zero-days – CyberScoop” »
I’m currently in Cork, Ireland as we prepare for Pwn2Own Ireland, but that doesn’t stop patch Tuesday from coming. Take a break from your scheduled activities and let’s take a look at the latest security offerings from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check … Read More “The October 2025 Security Update Review – Zero Day Initiative – Blog” »
Federal authorities seized 127,271 Bitcoin, valued at approximately $15 billion, from Chen Zhi, the alleged leader of a sprawling cybercrime network based in Cambodia, the Justice Department said Tuesday. Officials said it’s the largest financial seizure on record. “Today’s action represents one of the most significant strikes ever against the global scourge of human trafficking … Read More “Officials crack down on Southeast Asia cybercrime networks, seize $15B – CyberScoop” »
Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity, per ReliaQuest, is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and RedJuliett. According … Read More “Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year – The Hacker News” »
LevelBlue announced Tuesday it has signed a definitive agreement to acquire Cybereason, a Boston-based cybersecurity firm specializing in extended detection and response platforms and digital forensics. Dallas-based LevelBlue, a managed security services provider formerly known as AT&T Cybersecurity, will fold Cyberreason’s extended detection and response (XDR) platform, threat intelligence team, and digital forensics and incident … Read More “LevelBlue to acquire Cybereason in latest cybersecurity industry consolidation – CyberScoop” »
Legacy Windows protocols are still exposing organizations to credential theft, Resecurity found – Read More –
A newly identified cybercrime group TA585 is running an advanced cyber operation distributing MonsterV2 malware – Read More –
In a joint warning letter, UK ministers urged FTSE 350 CEOs to bolster cyber defenses – Read More –
From Prompts to Protocols: How Agentic Systems, MCP, Vibe Coding, and Schema-Aware Tools Are Rewiring Software Engineering – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Modern software engineering faces growing complexity across codebases, environments, and workflows. Traditional tools, although effective, rely heavily on… – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Sweet Security Named Cloud Security Leader and CADR Leader in Latio Cloud Security Report – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Tel Aviv, Israel, 14th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Torrance, United States, 14th October 2025, CyberNewsWire – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Microsoft Limits IE Mode in Edge After Chakra Zero-Day Activity Detected – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Microsoft restricted access to Edge’s IE Mode in August 2025 after hackers used a Chakra zero-day flaw to bypass security and take over user devices. Check out the new steps for enabling IE Mode. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Police Bust GXC Team, One of the Most Active Cybercrime Networks – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Spanish Guardia Civil and Group-IB arrest ‘GoogleXcoder,’ the 25-year-old Brazilian mastermind of the GXC Team, for selling AI-powered phishing kits and malware used to steal millions from banks across the US, UK, Spain, and Brazil. – Read More – Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Before an attacker ever sends a payload, they’ve already done the work of understanding how your environment is built. They look at your login flows, your JavaScript files, your error messages, your API documentation, your GitHub repos. These are all clues that help them understand how your systems behave. AI is significantly accelerating reconnaissance and … Read More “What AI Reveals About Web Applications— and Why It Matters – The Hacker News” »