New Tetra Radio Encryption Flaws Expose Law Enforcement Communications

August 11, 2025Ravi LakshmananEncryption/Network Security Cybersecurity researchers have discovered new security issues with the Terrestrial Trunk Radio (TETRA) communications protocol, including a unique end-to-end encryption (E2EE) mechanism that exposes the system to regenerate and brute-force attacks, and even decrypt encrypted traffic. Vulnerability Details – 2tetra: Called 2burst – Last week, Midnight Blue researchers Carlo Meijer, […]

Researchers find surges in exploits on Erlang/OTP SSH RCE and 70% target OT firewall

August 11, 2025Ravi LakshmananVulnerability/Network Security Malicious actors were taking advantage of the current patched critical security flaws that are already affecting Ellan/Open Telecom Platform (OTP) SSH by the beginning of May 2025, with around 70% of detections protecting operational technology (OT) networks that protect firewalls. The vulnerability in question is CVE-2025-32433 (CVSS score: 10.0). This […]

BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & More

Aug 11, 2025Ravie Lakshmanan This week, cyber attackers are moving quickly, and businesses need to stay alert. They’re finding new weaknesses in popular software and coming up with clever ways to get around security. Even one unpatched flaw could let attackers in, leading to data theft or even taking control of your systems. The clock […]

Focus on security where business value is alive

Evolution of exposure management Most security teams understand the important things in their environment. What’s hard to pin is to be critical of business. These are assets that support processes that your business cannot function. They are not always the loudest or most exposed. They are linked to revenue, operations and delivery. If it goes […]

Winrar Zero Day under Active Exploitation – Latest Version Update

August 11, 2025Ravi LakshmananZero Day/Vulnerability The Winrar File Archive Utility maintainer has released an update to address the actively exploited zero-day vulnerability. Tracked as CVE-2025-8088 (CVSS score: 8.8), this issue is described as a case of past traversal affecting the Windows version of tools that can be exploited to create malicious archive files and obtain […]

New WIN-DDOS flaws allow attackers to turn public domain controllers into DDOS botnets via RPC, LDAP

August 10, 2025Ravi LakshmananVulnerability/Network Security Weaponize new attack technologies to rope thousands of public domain controllers (DCs) around the world to create malicious botnets that use them to carry out power distributed denial of service (DDOS) attacks. This approach is codenamed Win-Ddos by Safebreach Researchers or Yair and Shahak Morag. “When investigating the complexity of […]

Researcher Details Window EPM Addiction Exploit Chain Domain Privileges

August 10, 2025Ravi LakshmananVulnerability/Endpoint Security Cybersecurity researchers have presented new findings related to security issues related to communication protocols that can be abused by attackers and misused by attackers by known servers. The vulnerability tracked as CVE-2025-49760 (CVSS score: 3.5) has been described by the Tech giant as a spoofing bug in Windows storage. Corrected […]

Flaws in Linux-based Lenovo webcams can be exploited remotely due to BADUSB attacks

August 9, 2025Ravi LakshmananVulnerability/Hardware Security Cybersecurity researchers have revealed vulnerabilities in Lenovo’s selected model webcams and can turn them into BADUSB attack devices. “This allows remote attackers to secretly inject keystrokes and launch attacks independently of the host operating system,” Eclipsium researchers Paul Assadrian, Mickey Schkatov and Jesse Michael said in a report they shared […]

Researchers reveal Revault Attack targeting Dell ControlVault3 firmware on over 100 laptop models

August 9, 2025Ravi LakshmananVulnerability/Hardware Security Cybersecurity researchers have discovered multiple security flaws in Dell’s ControlVault3 firmware and related Windows APIs that may have been abused by attackers, maintain access even after installing a fresh operating system bypassing Windows logins, extracting encryption keys, and deploying malicious implants that are not detected in the firmware. The vulnerability […]

Researchers reveal GPT-5 jailbreak and zero-click AI agents to attack cloud and IoT systems exposure

Cybersecurity researchers have discovered jailbreak techniques to bypass the ethical guardrail built by OpenaI on the latest leading language model (LLM) GPT-5, creating illegal instructions. Generic Artificial Intelligence (AI) security platform Neural Trust said it combined a known technique called Echo Chamber with narrative-driven steering to trick the model into generating unwanted responses. “We use […]