Cyber Security
Cybersecurity
RediShell Zero-Day in Redis Permits Remote Code Execution on Exposed Instances
Gabby Lee
October 7, 2025
Critical RediShell zero-day (CVE-2025-49844) enables Lua-based remote code execution on Redis; administrators must patch, disable Lua where possible and secure exposed instances immediately.
Cybersecurity
Oracle E-Business Suite Zero-Day Exploited, Authorities Urge Immediate Patching
Mitchell Langley
October 7, 2025
Oracle E-Business Suite zero-day CVE-2025-61882 is under active exploitation; emergency patches are available and organizations must patch and investigate potential compromise immediately.
Cybersecurity
NIST Flags DeepSeek Adoption Over Security, Censorship and Cost Concerns
Andrew Doyle
October 7, 2025
NIST analysis finds DeepSeek models lag U.S. counterparts, cost more, are easier to hijack, and exhibit CCP-aligned censorship, prompting security and policy warnings for adopters.
Cybersecurity
Unity Engine Flaw Permits Code Execution on Android and Escalation on Windows
Andrew Doyle
October 7, 2025
A Unity runtime flaw (CVE-2025-59489) allows malicious apps or inputs to load attacker libraries, enabling code execution on Android and privilege escalation on Windows; developers ...
Cybersecurity
Salesforce Faces Extortion Threat After Salesloft OAuth Token Exploits
Mitchell Langley
October 6, 2025
A hacking consortium claims Salesloft OAuth tokens were abused to extract CRM records from 700+ companies; Salesforce says claims relate to past or unverified incidents ...
Cybersecurity
Discord Discloses Support Ticket Breach After Unauthorized Access to Third-Party System
Gabby Lee
October 6, 2025
Discord confirmed attackers accessed a third-party support system, stealing support tickets, IDs, IPs, messages and partial billing data; investigation and user notifications are ongoing.
Cybersecurity
VMware Virtual Machines Targeted in Zero-Day Exploitation by China-Linked Hackers
Andrew Doyle
October 6, 2025
Broadcom warns of zero-day flaws in VMware software exploited by China-linked hackers, allowing privilege escalation for months, raising concerns over virtualization security and global enterprise ...
Cybersecurity
Boeing Supplier Dimensional Control Systems Targeted in Ransomware Attack
Andrew Doyle
October 6, 2025
J Group ransomware gang claims to have stolen 11GB of sensitive internal documents from Boeing supplier Dimensional Control Systems, raising cybersecurity concerns across global manufacturing ...
Cybersecurity
Lynx Claims Ransomware Intrusion at TriMed Subsidiary of Henry Schein
Gabby Lee
October 6, 2025
Lynx claims a ransomware intrusion at TriMed, posting alleged executive, legal, employee and proprietary files; Henry Schein is investigating with law enforcement and forensic partners.
Cybersecurity
Red Hat Confirms Breach of Consulting GitLab Instance After Claim of 570.2 GB Leak
Gabby Lee
October 5, 2025
Red Hat confirmed unauthorized access to a consulting GitLab instance; an extortion group claims to have exfiltrated 570.2 GB from 28,000 repositories, including ~800 CERs.
Cybersecurity
DrayTek Vigor RCE Vulnerability Prompts Urgent Firmware Updates
Gabby Lee
October 5, 2025
DrayTek patched CVE-2025-10547, an uninitialized-variable flaw in Vigor routers that can lead to memory corruption and potential remote code execution; administrators must update firmware and ...
Cybersecurity
WestJet Data Breach Exposes Passports and IDs for 1.2 Million Customers
Andrew Doyle
October 2, 2025
WestJet confirmed a June cyberattack exposed passports, IDs, and travel records of 1.2 million customers. The airline is notifying victims and offering two years of ...
Cybersecurity
Sendit Sued by FTC for Alleged Illegal Collection of Children’s Data
Mitchell Langley
October 2, 2025
The FTC referred a complaint alleging Sendit collected children’s personal data without parental consent and used deceptive subscription practices, prompting a DoJ referral and potential ...
Cybersecurity
China Tightens Cyber Rules, Forcing One-Hour Reporting for Major Incidents
Syed Arslan
October 2, 2025
China’s Cyberspace Administration will require operators to report major cyber incidents within 60 minutes, or 30 minutes for severe events, with penalties for concealment or ...
Cybersecurity
Klopatra Android RAT Masquerades as IPTV and VPN App, Drains Banking Devices across Europe
Gabby Lee
October 2, 2025
Klopatra, disguised as an IPTV/VPN app, uses Accessibility abuse and a black-screen VNC to capture credentials and remotely drain over 3,000 Android devices across Europe.
Cybersecurity
Allianz Life Confirms July Breach Exposed SSNs for Nearly 1.5 Million People
Andrew Doyle
October 2, 2025
Allianz Life confirmed a July CRM compromise exposed names, addresses, dates of birth and Social Security numbers for 1,497,036 people and offered two years of ...
Identity and Access Management
Axonius Identities Review 2025: Unified IAM, Governance & Security
Mitchell Langley
October 1, 2025
Axonius Identities delivers unified identity governance, lifecycle automation, and identity security posture for both human and non-human identities across complex enterprise environments, with actionable policy ...
Blog
11 Types of Social Engineering Attacks and How to Prevent Them
Andrew Doyle
October 1, 2025
This detailed guide explores eleven prevalent social engineering attack types, explaining their mechanisms and offering practical preventative measures for individuals and organizations. Understand the psychology ...
Application Security
How to Use Cain and Abel for Penetration Testing: Step-by-Step Tutorial 2026
Andrew Doyle
October 1, 2025
Cain and Abel is a powerful password recovery and penetration testing tool. Learn its features, uses, risks, and best practices for ethical cybersecurity operations.
Cybersecurity
UK Government Backs Jaguar Land Rover With £1.5 Billion Loan Guarantee After Cyberattack
Andrew Doyle
October 1, 2025
The UK guaranteed £1.5bn to stabilise JLR after a major cyberattack; phased restart underway as forensic work, supplier relief and insurance clarity continue.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Gabby Lee
August 12, 2026
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
Gabby Lee
August 12, 2026
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Gabby Lee
August 12, 2026
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Mitchell Langley
August 12, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
Andrew Doyle
August 11, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Capita Hit with £14M Fine for Data Breach Impacting 6.6M Individuals
October 16, 2025
Capita has been fined £14 million by the UK ICO for failing to prevent a 2023 cyberattack that exposed data from over 6.6 million people. ...
U.S. Seizes $15 Billion in Bitcoin Linked to Major Pig Butchering Crypto Scam
October 15, 2025
U.S. authorities seized $15 billion in bitcoin linked to a major “pig butchering” scam run by Chen Zhi and Prince Holding Group, combining fraud and ...
Pixnapping Attack Steals MFA Codes Pixel by Pixel on Android Devices
October 15, 2025
Pixnapping is a new Android attack that steals 2FA codes and on-screen data by reading pixel rendering side-channels—no permissions needed, and effective in under 30 ...
Vietnam Airlines Confirms Customer Data Breach Linked to Third-Party Support Platform
October 15, 2025
Vietnam Airlines says a third-party customer-service platform was breached, possibly exposing customer contact data; payments, passwords and passports were not affected, investigation and notifications are ...
Oracle Quietly Patches Zero-Day Vulnerability Revealed by ShinyHunters Leak
October 15, 2025
Oracle quietly patched a zero-day exploit leaked by ShinyHunters, enabling remote command execution in enterprise applications. Customers are urged to deploy updates immediately and audit ...
CoinbaseCartel Threatens to Publish SK Telecom Source Code unless Ransom Talks Start
October 15, 2025
Ransom group CoinbaseCartel claims to have stolen SK Telecom source code, build files and cloud keys via a repository compromise and threatens public disclosure this ...
Russia Suspected in Jaguar Land Rover Cyberattack That Halted Production for Weeks
October 14, 2025
UK investigators probe Russian involvement after a September cyberattack at Jaguar Land Rover disabled 800 systems and halted production; government underwrites a £1.5bn loan guarantee.
Northern Rivers Resilient Homes Program Breach Exposes Personal Data of 2,031 Residents
October 14, 2025
An internal AI upload exposed the personal and health data of 2,031 Northern Rivers Resilient Homes participants. The NSW Reconstruction Authority opened investigations and issued ...
Qantas Customer Data Leaked on Dark Web After July Cyberattack
October 14, 2025
Hackers have leaked data of nearly six million Qantas customers on the dark web after a Salesforce-linked breach, exposing names, contact details, and frequent flyer ...
Discord Breach Exposes 70,000 ID Photos and Raises Questions about Third-Party Age Verification
October 14, 2025
Discord has confirmed that government-issued identification photos belonging to roughly 70,000 users may have been exposed in a third-party breach that impacted a vendor used ...
SimonMed Confirms Data Breach Exposed 1.2 Million Patients in January
October 14, 2025
SimonMed Imaging says a January 2025 breach exposed data for 1.2 million patients. Medusa claimed theft of 212 GB including scanned IDs, medical records, and ...
The “Shotgun” Botnet: How RondoDox Hijacks Routers, Cameras, and Servers Worldwide
October 13, 2025
A new and fast-growing botnet dubbed RondoDox is shaking up the global cybersecurity landscape with its “shotgun” exploitation strategy, targeting over 50 known and unknown ...
“Inflation Refund” Scam: How Fraudsters Are Stealing Identities Through Texts
October 13, 2025
A widespread smishing campaign is sweeping across New York, luring residents with fraudulent text messages about an “Inflation Refund” from the Department of Taxation and ...
Juniper Networks Patches 220 Vulnerabilities in Massive October Security Update
October 13, 2025
In one of the year’s most extensive patch cycles, Juniper Networks has released its October 2025 security advisories, addressing a staggering 220 vulnerabilities across its ...
Linked Exploitation Campaigns Target Cisco, Fortinet, and Palo Alto Networks Devices
October 13, 2025
Cyber intelligence firm GreyNoise has uncovered what appears to be a coordinated exploitation effort targeting network edge appliances from three major security vendors: Cisco, Fortinet, ...
Salesforce Refuses Ransom as Scattered LAPSUS$ Hunters Leak Millions of Records
October 13, 2025
A new wave of cyber extortion has rocked the enterprise world as the Scattered LAPSUS$ Hunters—a coalition formed from the notorious Lapsus$, Scattered Spider, and ...
Fake “Inflation Refund” Texts Target New Yorkers in Sophisticated Phishing Scam
October 13, 2025
Fraudulent “inflation refund” texts are scamming New Yorkers into surrendering personal data. Attackers steal IDs and financial information through fake government portals posing as refund ...
Zero-Day in Gladinet CentreStack and Triofox Actively Exploited
October 13, 2025
CVE-2025-11371, an unauthenticated LFI in Gladinet CentreStack and Triofox, is being exploited to retrieve machine keys and enable remote code execution; admins must apply Web.config ...
Spain Dismantles “GXC Team” Crime-as-a-Service Network and Arrests 25-Year-Old Leader
October 13, 2025
Spanish authorities dismantled GXC Team, arresting “GoogleXcoder.” The CaaS network supplied phishing kits, Android malware, and voice-scam tools across countries; tools seized, funds recovered.
LockBit, Qilin, DragonForce Form Ransomware Cartel to Coordinate Attacks
October 13, 2025
A fresh ransomware cartel reportedly unites LockBit, Qilin and DragonForce to share infrastructure, coordinate attacks and pool revenue, raising defense complexity for incident responders.





































