The FBI warns UNC6040 and UNC6395 targeting Salesforce platforms in data theft attacks

The US Federal Bureau of Investigation (FBI) has issued a flash alert to release Compromise Indicators (IOCs) related to two cybercrime groups tracked as UNC6040 and UNC6395 due to a series of data theft and tor attacks. “It has been observed that both groups have recently been targeting their organization’s Salesforce platform through various early […]
Samsung fixes critical zero-day CVE-2025-21043 utilized in Android attacks

September 12, 2025Ravi LakshmananVulnerability/Mobile Security Samsung has released monthly security updates for Android. This includes fixing a security vulnerability that it said was exploited in a zero-day attack. The vulnerability, CVE-2025-21043 (CVSS score: 8.8) concerns out-of-bounds writes that can result in arbitrary code execution. “Bunds of bounds write so in libimagecodec.quram.s allows remote attackers to […]
Apple warns Frent users of the fourth spyware campaign in 2025, CERT-FR confirms

September 12, 2025Ravi Lakshmanan According to the French Computer Emergency Response Team (CERT-FR), Apple has notified French users of spyware campaigns targeting devices. The agency said an alert was sent on September 3, 2025, when Apple notified county citizens that at least one of the devices linked to their iCloud accounts may have been compromised […]
New Hybrid Petia Ransomware Bypass Eufi Secure Boot CVE-2024-7344 Exploit

Cybersecurity researchers have discovered a new ransomware stock called Hybridpetya, similar to the infamous Petya/notpetya malware, but it also incorporates the ability to bypass the secure boot mechanism of a unified extended firmware interface (UEFI) system using the vulnerability disclosure possibilities disclosed earlier this year. Slovakian Cybersecurity Company ESET said the sample was uploaded to […]
Critical CVE-2025-5086 Delmia apriso’s active use of CISA warning

September 12, 2025Ravi LakshmananVulnerability/Cyberspy The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw affecting Dassault Systèmes Delmia Apriso Manufacturing Operations Management (MOM) software, based on evidence of active exploitation in its known Exploitation Vulnerabilities (KEV) catalog. The vulnerability tracked as CVE-2025-5086 has a CVSS score of 9.0 out of […]
Why Runtime Visibility Needs to Step Center Stage

The security landscape for cloud-native applications is undergoing major transformation. Containers, Kubernetes, and serverless technologies are the defaults in modern companies and accelerate delivery, but expand the attack surface in ways that traditional security models cannot keep up. As adoption grows, so does complexity. Security teams are asked to monitor vast hybrid environments, sift through […]
Cursor AI Code Editor Flaw Enables silent code execution via malicious repository

The weaknesses of security are revealed in an AI-powered code editor cursor that can trigger code execution when a maliciously created repository is opened using a program. This issue is due to the fact that immediate access security settings are disabled by default, opening the door for attackers to execute arbitrary code on the user’s […]
Add Google Pixel 10 C2PA support to verify the reliability of AI-generated media

September 11, 2025Ravi LakshmananArtificial Intelligence/Mobile Security On Tuesday, Google announced that it is taking out the box a new Google Pixel 10 phone with a standard coalition of content origins and reliability (C2PA) to examine the origins and history of digital content. Therefore, C2PA content credential support has been added to the Pixel Camera and […]
Senator Wyden urges the FTC to investigate Microsoft for ransom-related cybersecurity negligence

US Sen. Ron Wyden asked the Federal Trade Commission to investigate Microsoft and hold it accountable for what is called “gross cybersecurity negligence” that allowed ransomware attacks on critical U.S. infrastructure, including healthcare networks. “Without timely action, Microsoft’s culture of negligence cybersecurity, coupled with the virtual monopoly of the enterprise operating systems market, poses a […]
Help CISOs to speak business language

September 11, 2025Hacker NewsContinuous threat exposure management Sissos knows their field. They understand the threat landscape. They know how to build a powerful and cost-effective security stack. They know how to make their organization a staff member. They understand the complexity of compliance. They understand what they need to do to reduce the risk. However, […]