• Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems

    Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems

    Trend Micro has released mitigations to address critical security flaws in on-premise versions of Apex One Management Console that it said have been exploited in the wild. The vulnerabilities (CVE-2025-54948 and CVE-2025-54987), both rated 9.4 on the CVSS scoring system, have been described as management console command injection and remote code execution flaws. “A vulnerability…

    Read More

  • CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures

    CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures

    The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks carried out by a threat actor called UAC-0099 targeting government agencies, the defense forces, and enterprises of the defense-industrial complex in the country. The attacks, which leverage phishing emails as an initial compromise vector, are used to deliver malware families like MATCHBOIL,…

    Read More

  • AI Is Transforming Cybersecurity Adversarial Testing – Pentera Founder’s Vision

    AI Is Transforming Cybersecurity Adversarial Testing – Pentera Founder’s Vision

    When Technology Resets the Playing Field In 2015 I founded a cybersecurity testing software company with the belief that automated penetration testing was not only possible, but necessary. At the time, the idea was often met with skepticism, but today, with 1200+ of enterprise customers and thousands of users, that vision has proven itself. But…

    Read More

  • ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections

    ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections

    A combination of propagation methods, narrative sophistication, and evasion techniques enabled the social engineering tactic known as ClickFix to take off the way it did over the past year, according to new findings from Guardio Labs. “Like a real-world virus variant, this new ‘ClickFix’ strain quickly outpaced and ultimately wiped out the infamous fake browser…

    Read More

  • Cascade Locks: Measure to fund EMS could be ‘uphill battle’

    Cascade Locks: Measure to fund EMS could be ‘uphill battle’

    CASCADE LOCKS — The Cascade Locks City Council met on July 28 to discuss a recently awarded grant, the Inter-Governmental Agreement with Mid-Columbia Economic Development District (MCEDD), audit delays, worker schedules, and the city’s upcoming ballot funding measure.

    Read More

  • Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild

    Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild

    Google has released security updates to address multiple security flaws in Android, including fixes for two Qualcomm bugs that were flagged as actively exploited in the wild. The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6), by the chipmaker back in June…

    Read More

  • Misconfigurations Are Not Vulnerabilities: The Costly Confusion Behind Security Risks

    Misconfigurations Are Not Vulnerabilities: The Costly Confusion Behind Security Risks

    In SaaS security conversations, “misconfiguration” and “vulnerability” are often used interchangeably. But they’re not the same thing. And misunderstanding that distinction can quietly create real exposure. This confusion isn’t just semantics. It reflects a deeper misunderstanding of the shared responsibility model, particularly in SaaS environments where the line between vendor and customer

    Read More

  • How Top CISOs Save Their SOCs from Alert Chaos to Never Miss Real Incidents

    How Top CISOs Save Their SOCs from Alert Chaos to Never Miss Real Incidents

    Why do SOC teams still drown in alerts even after spending big on security tools? False positives pile up, stealthy threats slip through, and critical incidents get buried in the noise. Top CISOs have realized the solution isn’t adding more and more tools to SOC workflows but giving analysts the speed and visibility they need…

    Read More

  • 15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign

    15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign

    Cybersecurity researchers have lifted the veil on a widespread malicious campaign that’s targeting TikTok Shop users globally with an aim to steal credentials and distribute trojanized apps. “Threat actors are exploiting the official in-app e-commerce platform through a dual attack strategy that combines phishing and malware to target users,” CTM360 said. “The core tactic involves…

    Read More

  • SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported

    SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported

    SonicWall said it’s actively investigating reports to determine if there is a new zero-day vulnerability following reports of a spike in Akira ransomware actors in late July 2025. “Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is…

    Read More