344 stories
·
0 followers

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks

1 Share
CrowdStrike on Monday said it's attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a threat actor it tracks as Graceful Spider (aka Cl0p), and that the first known exploitation occurred on August 9, 2025. The malicious activity involves the exploitation of CVE-2025-61882 (CVSS score: 9.8), a critical vulnerability that

Read the whole story
felixatter
8 days ago
reply
Share this story
Delete

EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations

1 Share
Threat actors have been observed using seemingly legitimate artificial intelligence (AI) tools and software to sneakily slip malware for future attacks on organizations worldwide. According to Trend Micro, the campaign is using productivity or AI-enhanced tools to deliver malware targeting various regions, including Europe, the Americas, and the Asia, Middle East, and Africa (AMEA) region.

Read the whole story
felixatter
15 days ago
reply
Share this story
Delete

CISA Sounds Alarm on Critical Sudo Flaw Actively Exploited in Linux and Unix Systems

1 Share
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting the Sudo command-line utility for Linux and Unix-like operating systems to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability in question is CVE-2025-32463 (CVSS score: 9.3), which affects Sudo versions prior to

Read the whole story
felixatter
15 days ago
reply
Share this story
Delete

New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events

1 Share
Cybersecurity researchers have flagged a previously undocumented Android banking trojan called Datzbro that can conduct device takeover (DTO) attacks and perform fraudulent transactions by preying on the elderly. Dutch mobile security company ThreatFabric said it discovered the campaign in August 2025 after users in Australia reported scammers managing Facebook groups promoting "active senior

Read the whole story
felixatter
15 days ago
reply
Share this story
Delete

Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

1 Share
A newly patched security flaw impacting Broadcom VMware Tools and VMware Aria Operations has been exploited in the wild as a zero-day since mid-October 2024 by a threat actor called UNC5174, according to NVISO Labs. The vulnerability in question is CVE-2025-41244 (CVSS score: 7.8), a local privilege escalation bug affecting the following versions - VMware Cloud Foundation 4.x and 5.x VMware

Read the whole story
felixatter
15 days ago
reply
Share this story
Delete

Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits

1 Share
Cybersecurity researchers have disclosed three now-patched security vulnerabilities impacting Google's Gemini artificial intelligence (AI) assistant that, if successfully exploited, could have exposed users to major privacy risks and data theft. "They made Gemini vulnerable to search-injection attacks on its Search Personalization Model; log-to-prompt injection attacks against Gemini Cloud

Read the whole story
felixatter
15 days ago
reply
Share this story
Delete
Next Page of Stories