Aggregator
CVE-2025-54782 | nestjs nest up to 0.2.0 API Endpoint command injection (GHSA-85cg-cmq5-qjm7 / EUVD-2025-23413)
CVE-2025-54424 | 1Panel up to 2.0.5 HTTPS Protocol certificate validation (GHSA-8j63-96wh-wh3j / EUVD-2025-23409)
CVE-2025-54781 | himmelblau up to 1.0.x himmelblaud_tasks Service log file (GHSA-78qg-vmrw-574w / EUVD-2025-23414)
STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats
Security teams can no longer afford to wait for alerts — not when cyberattacks unfold in milliseconds.
That’s the core warning from Fortinet’s Derek Manky in a new Last Watchdog Strategic Reel recorded at RSAC 2025. As adversaries adopt AI-driven … (more…)
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats first appeared on The Last Watchdog.
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats appeared first on Security Boulevard.
Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers
A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages across npm and PyPI ecosystems. Between January and July 2025, this state-sponsored operation exposed over 36,000 potential victims to advanced malware designed for long-term surveillance […]
The post Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers appeared first on Cyber Security News.
SafePay Ransomware Infected 260+ Victims Across Multiple Countries
A new ransomware threat has emerged as one of the most aggressive cybercriminal operations of 2025, with SafePay ransomware claiming responsibility for over 265 successful attacks spanning multiple continents. The group, which first appeared in September 2024 with limited activity targeting just over 20 victims, has dramatically escalated its operations since early 2025, establishing itself […]
The post SafePay Ransomware Infected 260+ Victims Across Multiple Countries appeared first on Cyber Security News.
Transitioning from Software Engineering to Cybersecurity — Advice?
Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS
The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse of RansomHub, previously the most prolific ransomware-as-a-service operation. This transition has reshaped the cybercriminal ecosystem, with Qilin capitalizing on the vacuum left by RansomHub’s abrupt cessation of operations in early […]
The post Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS appeared first on Cyber Security News.
CVE-2025-43267 | Apple macOS up to 15.5 App information disclosure (Nessus ID 243030)
CVE-2025-43266 | Apple macOS up to 13.6/14.6/15.5 App sandbox (EUVD-2025-23079 / Nessus ID 243030)
游戏之外,芯片巨头不小心露出了第三增长曲线
关注 | 我国2025年IPv6呈现良好发展势头
美国对中国实施网络攻击 外交部:中方将采取必要措施
吴世忠院士:大模型安全治理的现状与展望
Виртуальный AK47 уже в руках Storm-2603. Кто следующий?
Noma Raised $100M to Expand Agentic AI Security Platform
With agentic AI deployments accelerating, Noma Security’s $100 million Series B will fuel development of risk management and runtime protection features. CEO Niv Braun said demand for securing agentic AI has surged among Fortune 500 firms and healthcare and financial institutions.
Genomics Gear Firm Pays $9.8M to Settle False Cyber Claims
Genomics sequencing firm Illumina Inc. has agreed to pay $9.8 million to resolve False Claims Act whistleblower allegations that it sold software and systems containing cybersecurity vulnerabilities over more than seven years to government agencies.
Safe Raises $70M Series C to Scale Cyber Risk Management
Safe's $70 million Series C will fund expanded capabilities across its cyber risk quantification, exposure management and third-party oversight tools. The company says its agentic AI vision – cyber AGI – will transform how enterprises manage and mitigate cyberthreats.
ISMG Editors: ToolShell Exploit Blurs Crime and Espionage
In this week's update, four ISMG editors discussed the latest on the ToolShell exploit and the rise of Warlock ransomware, why IT-OT integration may not be the best answer for industrial security and what to expect next week from ISMG Studio at Black Hat Conference 2025.