News
October 7, 2025 • 1 min read • Hackernews
Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware
Microsoft on Monday attributed a threat actor it tracks as Storm-1175 to the exploitation of a critical security flaw in Fortra GoAnywhere software to facilitate the deployment of Medusa ransomware. The vulnerability is CVE-2025-10035 (CVSS score 10.0), a critical deserialization bug that could result in command injection without authentication. It was
October 7, 2025 • 1 min read • Hackernews
Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks
CrowdStrike on Monday said its attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a threat actor it tracks as Graceful Spider (aka Cl0p), and that the first known exploitation occurred on August 9, 2025. The malicious activity involves the exploitation of CVE-2025-61882
October 6, 2025 • 2 min read • theVerge
Microsoft is plugging more holes that let you use Windows 11 without an online account
October 6, 2025 • 1 min read • theVerge
Carbon removal projects that Big Tech poured money into are in Trump8217s crosshairs
October 6, 2025 • 3 min read • theVerge
SwitchBots new safety tracker can discreetly trigger a fake phone call
October 6, 2025 • 1 min read • Hackernews
New Report Links Research Firms BIETA and CIII to Chinas MSS Cyber Operations
A Chinese company named the Beijing Institute of Electronics Technology and Application (BIETA) has been assessed to be likely led by the Ministry of State Security (MSS). The assessment comes from evidence that at least four BIETA personnel have clear or possible links to MSS officers and their relationship with the
October 6, 2025 • 1 min read • Hackernews
5 Critical Questions For Adopting an AI Security Solution
In the era of rapidly advancing artificial intelligence (AI) and cloud technologies, organizations are increasingly implementing security measures to protect sensitive data and ensure regulatory compliance. Among these measures, AI-SPM (AI Security Posture Management) solutions have gained traction to secure AI pipelines, sensitive data assets, and the overall AI ecosystem.
October 6, 2025 • 1 min read • Hackernews
Weekly Recap Oracle 0-Day BitLocker Bypass VMScape WhatsApp Worm More
The cyber world never hits pause, and staying alert matters more than ever. Every week brings new tricks, smarter attacks, and fresh lessons from the field. This recap cuts through the noise to share what really matters—key trends, warning signs, and stories shaping today’s security landscape. Whether you’re defending systems or
October 6, 2025 • 1 min read • Hackernews
Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks
Oracle has released an emergency update to address a critical security flaw in its E-Business Suite software that it said has been exploited in the recent wave of Cl0p data theft attacks. The vulnerability, tracked as CVE-2025-61882 (CVSS score 9.8), concerns an unspecified bug that could allow an unauthenticated attacker with
October 6, 2025 • 1 min read • Hackernews
Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers
Cybersecurity researchers have shed light on a Chinese-speaking cybercrime group codenamed UAT-8099 that has been attributed to search engine optimization (SEO) fraud and theft of high-value credentials, configuration files, and certificate data. The attacks are designed to target Microsoft Internet Information Services (IIS) servers, with most of the infections reported in