Vulnerabilities Fresh Windows NTLM Vulnerability Exploited in Attacks A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions. Ionut Arghire7 hours ago
Vulnerabilities SonicWall Flags Old Vulnerability as Actively Exploited A SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild. Eduard Kovacs1 day ago
Malware & Threats Apple Quashes Two Zero-Days With iOS, MacOS Patches The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms. Ryan Naraine2 days ago
Government MITRE CVE Program Gets Last-Hour Funding Reprieve The US government's cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational. Ryan Naraine2 days ago
Nation-State China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games China accuses three alleged U.S. NSA operatives of cyberattacks targeting critical infrastructure and the Asian Games in Harbin. Associated Press3 days ago
Data Breaches Hertz Discloses Data Breach Linked to Cleo Hack Customers of the Hertz, Thrifty, and Dollar brands had their personal information stolen as a result of the Cleo hack last year. Ionut Arghire3 days ago
CISO Conversations CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe Van Horenbeeck's career spans some of the biggest companies in tech: Verizon, Microsoft, Google, Amazon, Zendesk, and now SVP and CSO at Adobe. Kevin Townsend3 days ago
Malware & Threats Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit A threat actor claims to offer a zero-day exploit for an unauthenticated remote code execution vulnerability in Fortinet firewalls. Ionut Arghire4 days ago
Supply Chain Security AI Hallucinations Create a New Software Supply Chain Threat Researchers uncover new software supply chain threat from LLM-generated package hallucinations. Ionut Arghire4 days ago
Nation-State China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report In a secret meeting between Chinese and US officials, the former confirmed conducting cyberattacks on US infrastructure. Eduard KovacsApril 11, 2025
Government Trump Revokes Security Clearance for Ex-CISA Director Chris Krebs Trump orders a termination of any active security clearances held by Krebs and a suspension of clearances held by individuals at SentinelOne. Ryan NaraineApril 10, 2025
IoT Security Nissan Leaf Hacked for Remote Spying, Physical Takeover Researchers find vulnerabilities that can be exploited to remotely take control of a Nissan Leaf’s functions, including physical controls. Eduard KovacsApril 10, 2025