Aggregator
Chrome теперь скрывает IP-адреса через прокси Google. Добро пожаловать в эпоху корпоративных посредников
Czech cyber agency warns against using services and products that send data to China
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-38352 Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
- CVE-2025-48543 Android Runtime Unspecified Vulnerability
- CVE-2025-53690 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA Releases Five Industrial Control Systems Advisories
CISA released five Industrial Control Systems (ICS) advisories on September 4, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-247-01 Honeywell OneWireless Wireless Device Manager (WDM)
- ICSA-25-217-01 Mitsubishi Electric Iconics Digital Solutions Multiple Products (Update A)
- ICSA-25-105-07 Delta Electronics COMMGR (Update A)
- ICSA-25-205-03 Honeywell Experion PKS (Update A)
- ICSA-25-191-10 End-of-Train and Head-of-Train Remote Linking Protocol (Update B)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
Microsoft says recent Windows updates cause app install issues
Virtualizing your infrastructure (ITSAP.70.011)
Singapore Personal Data Protection Act (PDPA)
What is the Personal Data Protection Act (PDPA)? The Singapore Personal Data Protection Act (PDPA), enacted in 2012 and enforced by the Personal Data Protection Commission (PDPC), is the nation’s comprehensive data protection law. It governs the collection, use, and disclosure of personal data by organizations while balancing individuals’ right to privacy with the need […]
The post Singapore Personal Data Protection Act (PDPA) appeared first on Centraleyes.
The post Singapore Personal Data Protection Act (PDPA) appeared first on Security Boulevard.
Philippines Data Privacy Act of 2012
What is the Data Privacy Act (DPA)? The Philippines Data Privacy Act of 2012 (Republic Act No. 10173), commonly referred to as the DPA, is the country’s primary data protection law. Enacted in August 2012, the Act was designed to safeguard the fundamental right to privacy of every Filipino while ensuring the free flow of […]
The post Philippines Data Privacy Act of 2012 appeared first on Centraleyes.
The post Philippines Data Privacy Act of 2012 appeared first on Security Boulevard.
Scattered Lapsus$ Hunters Demand Google Fire Security Experts or Face Data Leak
Scattered Spider-Linked Group Claims JLR Cyber-Attack
Sitecore zero-day vulnerability exploited by attackers (CVE-2025-53690)
A threat actor is leveraging a zero-day vulnerability (CVE-2025-53690) and an exposed sample ASP.NET machine key to breach internet-facing, on-premises deployments of several Sitecore solutions, Mandiant has revealed. About CVE-2025-53690 CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud. Deployed instances are affected by this vulnerability if they have been deployed by using a sample machine key that has been … More →
The post Sitecore zero-day vulnerability exploited by attackers (CVE-2025-53690) appeared first on Help Net Security.