Author: Robert Timlick

  • Juniper Session Smart Routers Vulnerability Could Let Attackers Bypass Authentication

    Juniper Session Smart Routers Vulnerability Could Let Attackers Bypass Authentication

    Juniper Networks has released security updates to address a critical security flaw impacting Session Smart Router, Session Smart Conductor, and WAN Assurance Router products that could be exploited to hijack control of susceptible devices.
    Tracked as CVE-2025-21589, the vulnerability carries a CVSS v3.1 score of 9.8 and a CVS v4 score of 9.3.
    “An Authentication Bypass Using an Alternate Path or
  • Debunking the AI Hype: Inside Real Hacker Tactics

    Debunking the AI Hype: Inside Real Hacker Tactics

    Is AI really reshaping the cyber threat landscape, or is the constant drumbeat of hype drowning out actual, more tangible, real-world dangers? According to Picus Labs’ Red Report 2025 which analyzed over one million malware samples, there’s been no significant surge, so far, in AI-driven attacks. Yes, adversaries are definitely continuing to innovate, and while AI will certainly start playing a
  • New Xerox Printer Flaws Could Let Attackers Capture Windows Active Directory Credentials

    New Xerox Printer Flaws Could Let Attackers Capture Windows Active Directory Credentials

    Security vulnerabilities have been disclosed in Xerox VersaLink C7025 Multifunction printers (MFPs) that could allow attackers to capture authentication credentials via pass-back attacks via Lightweight Directory Access Protocol (LDAP) and SMB/FTP services.
    “This pass-back style attack leverages a vulnerability that allows a malicious actor to alter the MFP’s configuration and cause the MFP
  • Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers

    Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers

    Cybersecurity researchers have flagged a credit card stealing malware campaign that has been observed targeting e-commerce sites running Magento by disguising the malicious content within image tags in HTML code in order to stay under the radar.
    MageCart is the name given to a malware that’s capable of stealing sensitive payment information from online shopping sites. The attacks are known to
  • Hundreds rally on President’s Day

    Hundreds rally on President’s Day

    HOOD RIVER — On Feb. 17 — President’s Day — hundreds of Gorge residents made their way to downtown Hood River to protest the Trump administration and rally behind vulnerable populations. The Columbia Gorge Women’s Action Network organized the rally.
  • Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics

    Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics

    Microsoft said it has discovered a new variant of a known Apple macOS malware called XCSSET as part of limited attacks in the wild.
    “Its first known variant since 2022, this latest XCSSET malware features enhanced obfuscation methods, updated persistence mechanisms, and new infection strategies,” the Microsoft Threat Intelligence team said in a post shared on X.
    “These enhanced features add to
  • South Korea Suspends DeepSeek AI Downloads Over Privacy Violations

    South Korea Suspends DeepSeek AI Downloads Over Privacy Violations

    South Korea has formally suspended new downloads of Chinese artificial intelligence (AI) chatbot DeepSeek in the country until the service makes changes to its mobile apps to comply with data protection regulations.
    Downloads have been paused as of February 15, 2025, 6:00 p.m. local time, the Personal Information Protection Commission (PIPC) said in a statement. The web service remains
  • CISO’s Expert Guide To CTEM And Why It Matters

    CISO’s Expert Guide To CTEM And Why It Matters

    Cyber threats evolve—has your defense strategy kept up? A new free guide available here explains why Continuous Threat Exposure Management (CTEM) is the smart approach for proactive cybersecurity.
    This concise report makes a clear business case for why CTEM’s comprehensive approach is the best overall strategy for shoring up a business’s cyber defenses in the face of evolving attacks. It also
  • ⚡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More

    ⚡ THN Weekly Recap: Google Secrets Stolen, Windows Hack, New Crypto Scams and More

    Welcome to this week’s Cybersecurity News Recap. Discover how cyber attackers are using clever tricks like fake codes and sneaky emails to gain access to sensitive data. We cover everything from device code phishing to cloud exploits, breaking down the technical details into simple, easy-to-follow insights.
    ⚡ Threat of the Week
    Russian Threat Actors Leverage Device Code Phishing to Hack