CISOs are facing unprecedented challenges to their mental health due to today’s rapidly evolving threat landscape. They are often held accountable if a breach or disruption occurs, and the average tenure for a CISO tends to decrease significantly after such incidents. This constant pressure makes it difficult for them to find peace, let alone get … Read More “The realities of CISO burnout and exhaustion – CyberScoop” »
Entrust says AI is helping fraudsters open new accounts and bypass biometric checks – Read More –
Socura finds 460,000 compromised credentials belonging to FTSE 100 company employees – Read More –
Microsoft Azure Blocks 15.72 Tbps Aisuru Botnet DDoS Attack – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Microsoft Azure halted a record 15.72 Tbps DDoS attack from the Aisuru botnet exposing risks created by exposed home devices exploited in large-scale cyber attacks. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Microsoft on Monday disclosed that it automatically detected and neutralized a distributed denial-of-service (DDoS) attack targeting a single endpoint in Australia that measured 5.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps). The tech giant said it was the largest DDoS attack ever observed in the cloud, and that it originated … Read More “Microsoft Mitigates Record 5.72 Tbps DDoS Attack Driven by AISURU Botnet – The Hacker News” »
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability – The Hacker News
Google on Monday released security updates for its Chrome browser to address two security flaws, including one that has come under active exploitation in the wild. The vulnerability in question is CVE-2025-13223 (CVSS score: 8.8), a type confusion vulnerability in the V8 JavaScript and WebAssembly engine that could be exploited to achieve arbitrary code execution … Read More “Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability – The Hacker News” »
Alice Blue Partners with AccuKnox for Regulatory Compliance – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Menlo Park, CA, November 17th, 2025, CyberNewsWire. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Bitsgap vs HaasOnline: Advanced Features vs Smart Simplicity – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Power vs Practicality in Crypto Automation – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Federal authorities and researchers alerted organizations Friday to a massively exploited vulnerability in Fortinet’s web application firewall. While the actively exploited critical defect poses significant risk to Fortinet’s customers, researchers are particularly agitated about the vendor’s delayed communications and, ultimately, post-exploitation warnings about the vulnerability. Fortinet addressed CVE-2025-64446 in a software update pushed Oct. 28, … Read More “Fortinet’s delayed alert on actively exploited defect put defenders at a disadvantage – CyberScoop” »
On Monday, more than 60 digital commerce and trade groups called on governments around the globe to reject efforts or requests to weaken or bypass encryption, saying strong encrypted communications provides critical protections for user privacy, secure data protection and trust that underpin some of society’s most important interactions. “Encryption is a vital tool for … Read More “Dozens of groups call for governments to protect encryption – CyberScoop” »
Everest Ransomware Says It Stole Data of Millions of Under Armour Users – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Everest ransomware claims to have breached Under Armour, stealing 343GB of data, including customer info, product records, and internal company files. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Cybersecurity researchers have discovered malware campaigns using the now-prevalent ClickFix social engineering tactic to deploy Amatera Stealer and NetSupport RAT. The activity, observed this month, is being tracked by eSentire under the moniker EVALUSION. First spotted in June 2025, Amatera is assessed to be an evolution of ACR (short for “AcridRain”) Stealer, which was available … Read More “New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT – The Hacker News” »
Cisco Talos has observed overlaps between Kraken and the earlier HelloKitty cartel through attack tactics using SMB flaws for big-game hunting and double extortion – Read More –
Europol’s Referral Action Day removed extremist links across gaming and gaming-adjacent platforms, targeting radical content – Read More –
EchoGram Flaw Bypasses Guardrails in Major LLMs – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
HiddenLayer reveals the EchoGram vulnerability, which bypasses safety guardrails on GPT-5.1 and other major LLMs, giving security teams just a 3-month head start. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Frentree Partners with AccuKnox to Expand Zero Trust CNAPP Security in South Korea – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Menlo Park, California, USA, 17th November 2025, CyberNewsWire – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
New Immersive report finds cyber resilience and decision making are flatlining – Read More –
Phishing attacks are no longer confined to the email inbox, with 1 in 3 phishing attacks now taking place over non-email channels like social media, search engines, and messaging apps. LinkedIn in particular has become a hotbed for phishing attacks, and for good reason. Attackers are running sophisticated spear-phishing attacks against company executives, with recent … Read More “5 Reasons Why Attackers Are Phishing Over LinkedIn – The Hacker News” »
This week showed just how fast things can go wrong when no one’s watching. Some attacks were silent and sneaky. Others used tools we trust every day — like AI, VPNs, or app stores — to cause damage without setting off alarms. It’s not just about hacking anymore. Criminals are building systems to make money, … Read More “⚡ Weekly Recap: Fortinet Exploited, China’s AI Hacks, PhaaS Empire Falls & More – The Hacker News” »
The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT. The campaign, which is primarily aimed at Chinese-speaking users, employs trojanized NSIS installers masquerading as legitimate like Google Chrome and Microsoft Teams, according to … Read More “Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT – The Hacker News” »
The five defendants allegedly assisted North Korean hackers with obtaining remote IT employment with US companies – Read More –
Carmaker JLR has posted $639m Q2 losses and a one-off $258m hit after a major ransomware attack – Read More –
Google has disclosed that the company’s continued adoption of the Rust programming language in Android has resulted in the number of memory safety vulnerabilities falling below 20% for the first time. “We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code. … Read More “Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time – The Hacker News” »
AIPAC Discloses Data Breach, Says Hundreds Affected – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
AIPAC reports data breach after external system access, hundreds affected, investigation ongoing with added security steps. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice … Read More “Microsoft Patch Tuesday, November 2025 Edition – Krebs on Security” »
DoorDash hit by data breach after an employee falls for social engineering scam – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Food delivery giant DoorDash confirms a data breach on Oct 25, 2025, where an employee fell for a social engineering scam. User names, emails, and home addresses were stolen. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
A vulnerability has been discovered FortiWeb, which could allow for remote code execution. FortiWeb is a web application firewall (WAF) developed by Fortinet. It’s designed to protect web applications and APIs from a wide range of attacks, including those targeting known vulnerabilities and zero-day exploits. Successful exploitation of this vulnerability could allow an attacker to execute … Read More “A Vulnerability in FortiWeb Could Allow for Remote Code Execution – Cyber Security Advisories – MS-ISAC” »
The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request … Read More “RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet – The Hacker News” »
Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies – The Hacker News
The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28, … Read More “Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies – The Hacker News” »
The Justice Department notched a few more wins in the fight against North Korean cryptocurrency heists and the regime’s expansive scheme to get remote IT workers hired at U.S. businesses. Officials’ countermeasures to these schemes, which ultimately launder ill-gotten money to North Korea’s government, involve the targeting of U.S.-based facilitators who provide forged or stolen … Read More “DOJ lauds series of gains against North Korean IT worker scheme, crypto thefts – CyberScoop” »
Anthropic made headlines Thursday when it released research claiming that a previously unknown Chinese state-sponsored hacking group used the company’s Claude AI generative AI product to breach at least 30 different organizations. According to Anthropic’s report, the threat actor was able to bypass Claude’s security guardrails using two methods: breaking up the work into discrete … Read More “China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work – CyberScoop” »
CISA Warns of Active Attacks on Cisco ASA and Firepower Flaws – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
CISA issues an urgent directive for all organizations to patch Cisco ASA and Firepower devices against CVE-2025-20362 and CVE-2025-20333, exploited in the ArcaneDoor campaign. Verify the correct version now! – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage malicious payloads. “The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware from trojanized code projects, with the lure,” NVISO … Read More “North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels – The Hacker News” »
Personal details of Tate galleries job applicants leaked online – Data and computer security | The Guardian
Sensitive information relates to more than 100 individuals and their referees Personal details submitted by applicants for a job at Tate art galleries have been leaked online, exposing their addresses, salaries and the phone numbers of their referees, the Guardian has learned. The records, running to hundreds of pages, appeared on a website unrelated to … Read More “Personal details of Tate galleries job applicants leaked online – Data and computer security | The Guardian” »
Chinese State Hackers Jailbroke Claude AI Code for Automated Breaches – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Anthropic, the developer behind Claude AI, says a Chinese state sponsored group used its model to automate most of a cyber espionage operation against about 30 companies with Claude handling up to 90% of the technical work. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
The phishing kit Lighthouse, which has aided text scams like those soliciting victims to pay unpaid road tolls, appears to have been hampered shortly after Google filed a lawsuit aimed at its creators. Google said on Thursday that Lighthouse had been shut down. Two other organizations that have tracked the suspected Chinese operators of Lighthouse … Read More “Google, researchers see signs that Lighthouse text scammers disrupted after lawsuit – CyberScoop” »
Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets – The Hacker News
The Iranian state-sponsored threat actor known as APT42 has been observed targeting individuals and organizations that are of interest to the Islamic Revolutionary Guard Corps (IRGC) as part of a new espionage-focused campaign. The activity, detected in early September 2025 and assessed to be ongoing, has been codenamed SpearSpecter by the Israel National Digital Agency (INDA). … Read More “Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets – The Hacker News” »
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks – The Hacker News
Cybersecurity researchers have uncovered critical remote code execution vulnerabilities impacting major artificial intelligence (AI) inference engines, including those from Meta, Nvidia, Microsoft, and open-source PyTorch projects such as vLLM and SGLang. “These vulnerabilities all traced back to the same root cause: the overlooked unsafe use of ZeroMQ (ZMQ) and Python’s pickle deserialization,” – Read More … Read More “Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks – The Hacker News” »
Chinese Tech Firm Leak Reportedly Exposes State Linked Hacking – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
A massive data leak reportedly at Chinese firm Knownsec (Chuangyu) exposed 12,000 files detailing state-backed ‘cyber weapons’ and spying on over 20 countries. See the details, including 95GB of stolen Indian immigration data. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Anthropic’s Claude Code AI assistant performed 80% to 90% of the tasks involved in a recent cyber-attack campaign, said Anthropic researchers – Read More –
Key Takeaways: 85 active ransomware and extortion groups observed in Q3 2025, reflecting the most decentralized ransomware ecosystem to date. 1,590 victims disclosed across 85 leak sites, showing high, sustained activity despite law-enforcement pressure. 14 new ransomware brands launched this quarter, proving how quickly affiliates reconstitute after takedowns. LockBit’s reappearance with – Read More – … Read More “Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns – The Hacker News” »
Akira ransomware has extorted $244M since September 2025, with some attacks exfiltrating data in just two hours, a joint cybersecurity advisory warns – Read More –
Retail giants have a target on their backs. Hackers are picking them apart at a rate rarely seen in other industries. Louis Vuitton and Dior are part of a growing number of household names affected. Their breaches alone may have cost them upwards of $25 million. Moreover, Google has warned that the hacker group that … Read More “The retail sector needs a cybersecurity talent incubator – CyberScoop” »
State-sponsored threat actors from China used artificial intelligence (AI) technology developed by Anthropic to orchestrate automated cyber attacks as part of a “highly sophisticated espionage campaign” in mid-September 2025. “The attackers used AI’s ‘agentic’ capabilities to an unprecedented degree – using AI not just as an advisor, but to execute the cyber attacks themselves,” the … Read More “Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign – The Hacker News” »
Google filed a civil lawsuit against 25 individuals accused of ties to a Chinese cyber collective known as the ‘Smishing Triad’ – Read More –
Fortinet FortiWeb Flaw Actively Exploited in the Wild Before Company’s Silent Patch – The Hacker News
Cybersecurity researchers are sounding the alert about an authentication bypass vulnerability in Fortinet Fortiweb WAF that could allow an attacker to take over admin accounts and completely compromise a device. “The watchTowr team is seeing active, indiscriminate in-the-wild exploitation of what appears to be a silently patched vulnerability in Fortinet’s FortiWeb product,” Benjamin Harris, – … Read More “Fortinet FortiWeb Flaw Actively Exploited in the Wild Before Company’s Silent Patch – The Hacker News” »
Every November, International Fraud Awareness Week serves as a global reminder that fraud prevention is not merely a compliance… The post Fraud Awareness: The Untapped Power of HSM appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
Posted by Pierre Kim on Nov 13 No message preview for long message of 668188 bytes. – Read More – Full Disclosure
Posted by Apple Product Security via Fulldisclosure on Nov 13 APPLE-SA-11-13-2025-1 Compressor 4.11.1 Compressor 4.11.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/125693. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Compressor Available for: macOS Sequoia 15.6 and later Impact: … Read More “APPLE-SA-11-13-2025-1 Compressor 4.11.1 – Full Disclosure” »
Re: [FD] : “Glass Cage” – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885) – Full Disclosure
Posted by Patrick via Fulldisclosure on Nov 13 Hello Jan, You are completely right and it’s something I warned about early, which is abuse of AI-generated sensationalized headline and fake PoC-s, for fame. I urge the Full Disclosure staff to look into it. Discussions with the individual responsible seem to be fruitless, and this … Read More “Re: [FD] : “Glass Cage” – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885) – Full Disclosure” »





