Aggregator
Cyber security hygiene best practices for your organization - ITSAP.10.102
2 египтянина + 80 доменов + 6 лет = весь мировой спорт в заложниках
F-35’s gealarmeerd vanwege mogelijke dreiging NAVO-grondgebied
48 лет тайны — и точка: Microsoft наконец открыла тот самый BASIC, с которого стартовала империя Гейтса
macOS vulnerability allowed Keychain and iOS app decryption without a password
Today at Nullcon Berlin, a researcher disclosed a macOS vulnerability (CVE-2025-24204) that allowed attackers to read the memory of any process, even with System Integrity Protection (SIP) enabled. The issue stems from Apple mistakenly granting the /usr/bin/gcore utility the com.apple.system-task-ports.read entitlement in macOS 15.0 (Sequoia). Apple removed the entitlement in macOS 15.3. Koh M. Nakagawa speaking at Nullcon Berlin 2025 This entitlement gave gcore the ability to read the memory of any process on the … More →
The post macOS vulnerability allowed Keychain and iOS app decryption without a password appeared first on Help Net Security.
Sendmarc appoints Rob Bowker as North American Region Lead
CMS Provider Sitecore Patches Exploited Critical Zero Day
GhostRedirector Hackers Compromise Windows Servers With Malicious IIS Module To Manipulate Search Results
A newly identified hacking group, dubbed “GhostRedirector” by cybersecurity researchers, has compromised at least 65 Windows servers across the globe, deploying custom malware designed to manipulate search engine results for financial gain. According to a new report from ESET, the threat actor utilizes a malicious module for Microsoft’s Internet Information Services (IIS) to conduct a […]
The post GhostRedirector Hackers Compromise Windows Servers With Malicious IIS Module To Manipulate Search Results appeared first on Cyber Security News.
推免报名 | 欢迎报名华东师范大学密码学院!
Chrome теперь скрывает IP-адреса через прокси Google. Добро пожаловать в эпоху корпоративных посредников
Czech cyber agency warns against using services and products that send data to China
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-38352 Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
- CVE-2025-48543 Android Runtime Unspecified Vulnerability
- CVE-2025-53690 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA Releases Five Industrial Control Systems Advisories
CISA released five Industrial Control Systems (ICS) advisories on September 4, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-247-01 Honeywell OneWireless Wireless Device Manager (WDM)
- ICSA-25-217-01 Mitsubishi Electric Iconics Digital Solutions Multiple Products (Update A)
- ICSA-25-105-07 Delta Electronics COMMGR (Update A)
- ICSA-25-205-03 Honeywell Experion PKS (Update A)
- ICSA-25-191-10 End-of-Train and Head-of-Train Remote Linking Protocol (Update B)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
Microsoft says recent Windows updates cause app install issues
Virtualizing your infrastructure (ITSAP.70.011)
Singapore Personal Data Protection Act (PDPA)
What is the Personal Data Protection Act (PDPA)? The Singapore Personal Data Protection Act (PDPA), enacted in 2012 and enforced by the Personal Data Protection Commission (PDPC), is the nation’s comprehensive data protection law. It governs the collection, use, and disclosure of personal data by organizations while balancing individuals’ right to privacy with the need […]
The post Singapore Personal Data Protection Act (PDPA) appeared first on Centraleyes.
The post Singapore Personal Data Protection Act (PDPA) appeared first on Security Boulevard.
Philippines Data Privacy Act of 2012
What is the Data Privacy Act (DPA)? The Philippines Data Privacy Act of 2012 (Republic Act No. 10173), commonly referred to as the DPA, is the country’s primary data protection law. Enacted in August 2012, the Act was designed to safeguard the fundamental right to privacy of every Filipino while ensuring the free flow of […]
The post Philippines Data Privacy Act of 2012 appeared first on Centraleyes.
The post Philippines Data Privacy Act of 2012 appeared first on Security Boulevard.