• Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

    Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

    The U.K. National Cyber Security Centre (NCSC) has revealed that threat actors have exploited the recently disclosed security flaws impacting Cisco firewalls as part of zero-day attacks to deliver previously undocumented malware families like RayInitiator and LINE VIPER. “The RayInitiator and LINE VIPER malware represent a significant evolution on that used in the previous campaign,…

    Read More

  • Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

    Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

    Cisco is urging customers to patch two security flaws impacting the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, which it said have been exploited in the wild. The zero-day vulnerabilities in question are listed below – CVE-2025-20333 (CVSS score: 9.9) – An…

    Read More

  • Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

    Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

    Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect prompt injection. The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security,

    Read More

  • North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

    North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

    The North Korea-linked threat actors associated with the Contagious Interview campaign have been attributed to a previously undocumented backdoor called AkdoorTea, along with tools like TsunamiKit and Tropidoor. Slovak cybersecurity firm ESET, which is tracking the activity under the name DeceptiveDevelopment, said the campaign targets software developers across all operating systems, Windows,

    Read More

  • CTEM’s Core: Prioritization and Validation

    CTEM’s Core: Prioritization and Validation

    Despite a coordinated investment of time, effort, planning, and resources, even the most up-to-date cybersecurity systems continue to fail. Every day. Why?  It’s not because security teams can’t see enough. Quite the contrary. Every security tool spits out thousands of findings. Patch this. Block that. Investigate this. It’s a tsunami of red dots that not…

    Read More

  • Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

    Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

    The latest Gcore Radar report analyzing attack data from Q1–Q2 2025, reveals a 41% year-on-year increase in total attack volume. The largest attack peaked at 2.2 Tbps, surpassing the 2 Tbps record in late 2024. Attacks are growing not only in scale but in sophistication, with longer durations, multi-layered strategies, and a shift in target…

    Read More

  • Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

    Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed

    Cybersecurity researchers have discovered two malicious Rust crates impersonating a legitimate library called fast_log to steal Solana and Ethereum wallet keys from source code. The crates, named faster_log and async_println, were published by the threat actor under the alias rustguruman and dumbnbased on May 25, 2025, amassing 8,424 downloads in total, according to software supply…

    Read More

  • Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software

    Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software

    Cisco has warned of a high-severity security flaw in IOS Software and IOS XE Software that could allow a remote attacker to execute arbitrary code or trigger a denial-of-service (DoS) condition under specific circumstances. The company said the vulnerability, CVE-2025-20352 (CVSS score: 7.7), has been exploited in the wild, adding it became aware of it…

    Read More

  • Oregon’s Early Child Care Crisis Impacts All but Two of the State’s 36 Counties

    Oregon’s Early Child Care Crisis Impacts All but Two of the State’s 36 Counties

    OREGON — When Courtney Eggleston gave birth to her son, she knew she would have to rely on friends and family to help care for him when she went back to work. That’s because Hines, the Eastern Oregon town in…

    Read More

  • Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike

    Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike

    A suspected cyber espionage activity cluster that was previously found targeting global government and private sector organizations spanning Africa, Asia, North America, South America, and Oceania has been assessed to be a Chinese state-sponsored threat actor. Recorded Future, which was tracking the activity under the moniker TAG-100, has now graduated it to a hacking group…

    Read More