Aggregator
CVE-2025-14819 | cURL up to 8.17.0 OpenSSL access control (cd046f6c93b39d673a58c1864)
CVE-2025-14524 | cURL up to 8.17.0 Bearer Token redirect (1a822275d333dc6da6043497160fd)
UK announces plan to strengthen public sector cyber defenses
CVE-2025-14017 | cURL up to 8.17.0 Threaded LDAPS certificate validation (39d1976b7f709a516e324333)
CVE-2025-13034 | cURL up to 8.17.0 QUIC Certificate certificate validation (3d91ca8cdb3b434226e743946)
Major Data Breach Hits Company Operating 150 Gas Stations in the US
Когда BSOD – это не баг, а фича. Злоумышленники научились профессионально притворяться сломанной «виндой»
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2009-0556 Microsoft Office PowerPoint Code Injection Vulnerability
- CVE-2025-37164 HPE OneView Code Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem
Why cybersecurity cannot hire its way through the AI era
AI can close the speed and scale gap in security, but only if organizations prioritize the risks that matter most.
The post Why cybersecurity cannot hire its way through the AI era appeared first on CyberScoop.
Microsoft to Cancel Plans Imposing Daily Limit For Exchange Online Bulk E-mails
Microsoft has announced the indefinite cancellation of its Mailbox External Recipient Rate Limit in Exchange Online, reversing a previously planned restriction on bulk email sending. The decision comes after significant customer feedback highlighting operational disruptions caused by the proposed limitation. The tech giant’s Exchange Online Transport Team confirmed on January 6, 2026, that the external […]
The post Microsoft to Cancel Plans Imposing Daily Limit For Exchange Online Bulk E-mails appeared first on Cyber Security News.
Debian seeks volunteers to rebuild its data protection team
The Debian Project is asking for volunteers to step in after its Data Protection Team became inactive. All three members of the team stepped down at the same time, leaving no dedicated group to handle privacy and data protection work. The announcement was posted to the Debian development announcements mailing list. Until new volunteers join, the responsibilities of the team sit with the Debian Project Leader, Andreas Tille. The request is aimed at members of … More →
The post Debian seeks volunteers to rebuild its data protection team appeared first on Help Net Security.
Veeam resolves CVSS 9.0 RCE flaw and other security issues
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability
ToddyCat, a sophisticated cyber espionage group, has emerged as a persistent threat targeting high-profile organizations across multiple continents. The group began operations in December 2020 by compromising Microsoft Exchange servers in Taiwan and Vietnam using an unidentified vulnerability. However, their capabilities expanded significantly in February 2021 when they began exploiting the ProxyLogon vulnerability to target […]
The post ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability appeared first on Cyber Security News.
Ваш роутер D-Link работает уже 10 лет? У нас для вас (и его безопасности) очень плохие новости
TOTOLINK EX200 Extender Vulnerability Allow Attacker to Gain Full System Access
A severe vulnerability in the TOTOLINK EX200 Wi-Fi extender could allow attackers to gain full system access via an unauthenticated telnet root service, researchers warned. The flaw, tracked as CVE-2025-65606 and assigned CERT Vulnerability Note VU#295169, affects the firmware upload error-handling logic in the End-of-Life TOTOLINK EX200 extender. When processing malformed firmware files, the device inadvertently enables […]
The post TOTOLINK EX200 Extender Vulnerability Allow Attacker to Gain Full System Access appeared first on Cyber Security News.
LockBit 5.0 Emerges with New Sophisticated Encryption and Anti-Analysis Tactics
LockBit 5.0 has surfaced as the latest iteration of one of the world’s most active ransomware-as-a-service operations, continuing a legacy of sophisticated attacks since the group’s emergence in September 2019. This new version represents a significant evolution in the threat landscape, introducing enhanced encryption mechanisms and advanced anti-analysis capabilities that make detection and recovery exponentially […]
The post LockBit 5.0 Emerges with New Sophisticated Encryption and Anti-Analysis Tactics appeared first on Cyber Security News.